4 unchanged sentences
Our critical information technology resources include computer networks and hardware, third party hosted services, communications systems and software, and critical data including confidential, personal, proprietary and sensitive data (collectively, “Information Assets”).
−Removed: To operate our business, we also utilize certain third-party service providers to perform a variety of functions, such as professional services, SaaS platforms, managed services, cloud-based infrastructure, encryption and authentication technology, corporate productivity services, and other functions.
+Added: To operate our business, we also utilize certain third-party service providers to perform a variety of functions, such as professional services, SaaS platforms, managed services, cloud-based infrastructure, encryption and authentication technology, corporate productivity services, contract research organizations, application providers, supply chain resources, and other functions.
Accordingly, we have implemented and maintain certain risk assessment processes intended to identify cybersecurity threats, determine their likelihood of occurring, and assess and manage potential material impact to our business.
3 unchanged sentences
Risks from cybersecurity threats are among those that we address in our general risk management program.
−Removed: We identify, assess, and manage such threats by, among other things, monitoring the threat environment using manual and automated tools, subscribing to reports and services that identify cybersecurity threats, conducting scans of the threat environment, and conducting vulnerability assessments.
−Removed: We also engage third parties to conduct annual penetrations tests, as well as to provide threat and security risk assessments and intelligence feeds.
+Added: We identify, assess, and manage such threats by, among other things, monitoring the threat environment using manual and automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat actors, conducting scans of the threat environment, conducting vulnerability assessments, conducting audits, and conducting threat assessments for internal and external threats.
+Added: We also engage third parties to conduct annual penetration tests and tabletop incident response exercises, as well as to provide threat and security risk assessments and intelligence feeds.
Based on our assessment process and depending on the environment, we implement and maintain various technical, physical and organizational measures, processes, standards and policies designed to manage and mitigate such risks and potential material impacts.
10 unchanged sentences
asset management, tracking and disposal;
+Added: systems monitoring;
employee security training;
penetration testing;
−Removed: and cyber insurance.
+Added: cyber insurance;
+Added: and, as appropriate, inclusion of cybersecurity requirements in our contracts.
Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes.
For example, the IT department works with management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business.
−Removed: We work with third parties from time to time that assist us to identify, assess, and manage material risks from cybersecurity threats, including, for example, professional services firms (including legal counsel), threat intelligence service providers, cybersecurity software providers, managed cybersecurity service providers , forensic investigators, and penetration testing firms.
+Added: We work with third parties from time to time that assist us to identify, assess, and manage material risks from cybersecurity threats, including, for example, professional services firms (including legal counsel), threat intelligence service providers, cybersecurity consultants, cybersecurity software providers, managed cybersecurity service providers , and penetration testing firms.
For a description of the risks from cybersecurity threats that may materially affect us and how they may do so, refer to “Item 1A.
−Removed: Risk factors” in this Annual Report, including “If our information technology systems, those of third parties upon which we rely, or our data are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
+Added: Risk factors” in this Annual Report, including “If our information technology systems or data, or those of the third parties with whom we work, are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
fines and penalties;
11 unchanged sentences
Our cybersecurity incident response process involves members of management who also participate in our disclosure controls and procedures.
−Removed: Our cybersecurity incident response plan and information security incidence response procedures are designed to escalate certain cybersecurity incidents to members of finance and legal, depending on the circumstances, who report to the Chief Financial Officer and the General Counsel.
+Added: Our cybersecurity incident response plan and information security incidence response procedures are designed to escalate certain cybersecurity incidents to members of IT, finance and legal, depending on the circumstances, who report to the Chief Financial Officer and the General Counsel.
The Chief Financial Officer and the General Counsel work with our cybersecurity incident response team to help us mitigate and remediate cybersecurity incidents of which they are notified.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.