7 unchanged sentences
• risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader enterprise IT environment;
−Removed: • an information security team who, in collaboration with the broader technology organization, manages and maintains our (1) cybersecurity risk assessment processes including our Incident Response Plan, (2) security controls, and (3) response to cybersecurity incidents;
+Added: • an information security team who, in collaboration with the broader technology organization and the management team, manages and maintains our (1) cybersecurity risk assessment processes including our Incident Response Plan, (2) security controls, and (3) response to cybersecurity incidents;
• the use of external service providers, where appropriate, to assess, test, or otherwise assist with aspects of our security controls ;
2 unchanged sentences
• a third-party risk management process for service providers, suppliers, and vendors who have access to our critical systems and information.
−Removed: There can be no assurance that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied with or effective in protecting our systems and confidential information.
+Added: There can be no assurance that our cybersecurity risk management program and processes, including our policies, controls, or procedures, will be fully implemented, complied with, or effective in protecting our systems and confidential information given the ever-evolving threat landscape.
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
5 unchanged sentences
Our management team, including our Chief Legal Officer, our Chief Security Officer, and our Chief Technology Officer, is responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: The team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal information security team and our retained external cybersecurity consultants.
+Added: The management team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal information security team and our retained external cybersecurity consultants.
Our management team has over 20 years of cybersecurity technology leadership experience.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.