18 unchanged sentences
provide regular, mandatory training for our employees and contractors regarding cybersecurity threats as a means to equip them with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices;
−Removed: conduct regular phishing email simulations for all employees and contractors with access to our email systems to enhance awareness and responsiveness to possible threats;
+Added: conduct phishing email awareness training for all employees to enhance awareness and responsiveness to possible threats;
conduct annual cybersecurity management and incident training for employees involved in our systems and processes that handle sensitive data;
12 unchanged sentences
The audit committee of our board of directors is responsible for the oversight of risks from cybersecurity threats.
−Removed: On an annual basis, our audit committee receives an update from management of our cybersecurity threat risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
−Removed: In such sessions, our audit committee generally receives materials discussing current cyber risks and threats specific to our organization and industry, progress and status updates on projects aimed at fortifying our information security infrastructure, comprehensive evaluations of our ongoing information security program's effectiveness, and analysis of the evolving cyber threat landscape and its potential implications for our operations.
−Removed: and discusses such matters with our Chief Executive Officer.
+Added: On a periodic basis, our audit committee receives an update from management of our cybersecurity threat risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
+Added: In such sessions, our audit committee generally receives materials discussing current cyber risks and threats specific to our organization and industry, progress and status updates on projects aimed at fortifying our information security infrastructure, comprehensive evaluations of our ongoing information security program's effectiveness, and analysis of the evolving cyber threat landscape and its potential implications for our operations and discusses such matters with our Chief Executive Officer.
Our audit committee also receives prompt and timely information regarding any cybersecurity incident that meets establishing reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
19 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.