8 unchanged sentences
We also require cybersecurity training when onboarding new employees and contractors and on an annual basis thereafter.
−Removed: Our cybersecurity program leverages industry frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Risk Assessment Framework to strengthen our program effectiveness and reduce cybersecurity risks.
+Added: Our cybersecurity program leverages industry frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework to strengthen our program effectiveness and reduce cybersecurity risks.
We use a risk-based approach with respect to our oversight of third-party service providers.
−Removed: As part of our new vendor onboarding process, we assess all new third-party service providers for technical capabilities, reputation, financial stability, pricing, and other criteria and all new third-party service providers are reviewed and approved by our Finance and Legal departments.
−Removed: Foreign vendors are evaluated separately for compliance with the Foreign Corrupt Practices Act.
−Removed: Our contracts with third-party service provides include appropriate data security and privacy terms.
−Removed: For certain key third-party service providers, we obtain a SOC type 2 audit report from the vendor’s audit firm which provides detailed information and assurance about a service organization’s security, availability, processing integrity, confidentiality and privacy controls, in accordance with Statement on Standards for Attestation Engagements No.
+Added: As part of our process for onboarding new vendors, we assess new third-party service providers for technical capabilities, reputation, financial stability, pricing, and other criteria and such third-party service providers are reviewed and approved by our Finance and Legal departments.
+Added: We have implemented processes to confirm that agreements with third-parties contain data security and privacy terms as appropriate.
+Added: For certain key third-party service providers, we obtain a SOC type 2 audit report from the vendor’s audit firm which provides detailed information and assurance about a service organization’s security, availability, processing integrity, confidentiality and privacy controls.
Process for Assessing, Identifying and Managing Material Risks from Cybersecurity Threats
8 unchanged sentences
Board Oversight
−Removed: While the Board of Directors has overall responsibility for risk oversight, our Audit Committee oversees cybersecurity risk matters.
+Added: While our Board of Directors has overall responsibility for risk oversight, our Audit Committee oversees cybersecurity risk matters.
The Audit Committee is responsible for reviewing, discussing with management, and overseeing our data privacy, information technology and security and cybersecurity risk exposures.
−Removed: On at least an annual basis, the ED, IT & IS reports to the Audit Committee on information security and cybersecurity matters, including significant information technology risks, material threats (and the potential impact of those exposures on our business, financial results, operations and reputation) and the steps implemented by management to monitor and mitigate exposures.
−Removed: He also apprises the Audit Committee promptly of any high priority cybersecurity incidents, consistent with our Incident Management and Response Policy, and provides updates to the full Board as needed.
+Added: On at least an annual basis, the ED, IT & IS reports to the Audit Committee on information security and cybersecurity matters, including significant information technology risks, significant threats (and the potential impact of those exposures on our business, financial results, operations and reputation) and the steps implemented by management to monitor and mitigate exposures.
+Added: He also apprises the Audit Committee promptly of high priority cybersecurity incidents, consistent with our Incident Management and Response Policy, and provides updates to the full Board as needed.
Cybersecurity Risks
9 unchanged sentences
We also maintain cybersecurity insurance providing coverage for certain costs related to cybersecurity-related incidents that impact our own systems, networks, and technology or the systems, networks and technology of our contractors, consultants, vendors and other business partners.
−Removed: In the last three years, we did not experience any material cybersecurity incidents or threats.
+Added: As of December 31, 2024, we have not experienced any material risks from cybersecurity threats, including as a result of any previous cybersecurity incidents or threats, that have materially affected our business strategy, results of operations or financial condition or are reasonably likely to have such a material effect.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.