1 unchanged sentence
CYBERSECURITY
−Removed: We, together with our third-party vendors, employ information technology including networks, systems, and applications to support our business processes and decision-making across the Company.
−Removed: Our information technology is connected to support the flow of information across our business processes.
−Removed: As such, our information technology infrastructure is susceptible to cybersecurity threats.
−Removed: We monitor our information security procedures and risk management systems and implement initiatives aimed at improving our cybersecurity measures.
−Removed: Our process for assessing, identifying, and managing information security risks include:
+Added: We, together with our third-party vendors, employ information technology including networks, systems, and applications to support our business and decision-making across the Company, including supporting the flow of information across our business processes.
+Added: Our information technology infrastructure is susceptible to cybersecurity threats.
+Added: We monitor our information technology systems, including through the use of information security procedures and risk management systems, and implement initiatives aimed at improving our cybersecurity measures.
+Added: Our process for assessing, identifying, managing and addressing information security risks include:
• Internalization of Information Security Management .
1 unchanged sentence
He also possesses relevant experience in improving a company's cybersecurity posture and data privacy policies.
−Removed: He holds a Bachelor of Science degree in Information Systems and oversees all of our information security initiatives, assesses cybersecurity risks, provides cybersecurity solution plans, identifies opportunities for the implementation of additional cybersecurity procedures and provides cybersecurity training to our employees and executives.
+Added: He holds a Bachelor of Science degree in Information Systems and oversees all of our information security initiatives, assesses cybersecurity risks, provides cybersecurity plans, identifies opportunities for the implementation of additional cybersecurity measures and provides cybersecurity training to our employees and executives.
• Third-Party Consultant.
1 unchanged sentence
This consultant conducts periodic tests and analyses of our defensive and detective information security controls, including annual penetration tests and risk assessments as well as regular vulnerability scans and assessments.
−Removed: The consultant also provides live, interactive annual information security training to our employees and monitors the effectiveness of such training through quarterly phishing campaigns.
−Removed: The consultant also assists us in managing cybersecurity risks associated with third-party service providers by administering a due diligence questionnaire for the Company's third-party service providers that is inclusive of a cybersecurity risk assessment and provides guidance for remediation of security gaps.
+Added: The consultant also provides live, interactive annual information security training to our employees and executive officers and monitors the effectiveness of such training through quarterly phishing campaigns.
+Added: The consultant also assists us in managing cybersecurity risks associated with third-party service providers by administering a due diligence questionnaire for the Company's third-party service providers that includes a cybersecurity risk assessment and provides guidance for remediation of security gaps.
• Current Plans and Procedures .
−Removed: The Company has implemented an incident response plan (“IRP”) and a Business Continuity Plan ("BCP").
+Added: The Company has implemented and maintains an incident response plan (“IRP”) and a Business Continuity Plan (“BCP”).
The IRP establishes the organization, actions and procedures for recognizing and responding to information security incidents;
7 unchanged sentences
• Risk Identification and Mitigation.
−Removed: The Company aims to identify and mitigate information security risks using the National Institute of Standards and Technology Cybersecurity Framework (the “NIST Framework”).
−Removed: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST Framework as a guide to help us identify and mitigate information security risks relevant to our business.
+Added: The Company aims to identify and mitigate information security risks by using the National Institute of Standards and Technology Cybersecurity Framework (the “NIST Framework”) as a guide to help us identify and mitigate information security risks relevant to our business.
The Company seeks to identify potential risks through various software programs which perform asset and patch management;
3 unchanged sentences
The Company aims to protect itself from potential risks through the implementation of software programs which provide protective measures such as single sign-on, multi-factor identification, content filtering, disk encryption, regular patches and inside threat protection.
−Removed: The Company has implemented a suite of software programs to detect information security events, plans to respond to information security events in accordance with the IRP and BCP, and aims to take proactive steps to recover from information security events through its Disaster Recovery Plan.
+Added: The Company has implemented a suite of software programs to detect information security events, plans to respond to information security events in accordance with the IRP and BCP, and aims to take proactive steps to recover from information security events through its Disaster Recovery Plan (“DRP”).
+Added: The DRP prioritizes the swift recovery of information technology systems, data, and infrastructure and the efficient restoration of servers and applications to their normal operational state in the event of a significant disaster.
• Insurance .
−Removed: We maintain an information security risk insurance policy.
+Added: We maintain a breach response insurance policy.
• Enterprise Risk Assessment .
8 unchanged sentences
Our Board of Directors exercises oversight of information security risk primarily through the Audit Committee.
−Removed: The Head of Information Technology regularly provides information security updates to named executive officers and briefs our Board of Directors or Audit Committee on relevant information security issues at least twice a year.
−Removed: We also provide periodic cybersecurity training for members of our Board of Directors.
−Removed: As of the date of this Report, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company.
+Added: T he Head of Information Technology provides information security updates to named executive officers and briefs our Board of Directors and Audit Committee on relevant information security issues on a quarterly basis.
+Added: We also make available periodic cybersecurity training for members of our Board of Directors.
+Added: As of the date of this Report, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
However, we acknowledge that cybersecurity threats are continually evolving and the possibility of future cybersecurity incidents remains.
−Removed: Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cyberattack will not occur.
+Added: Despite the implementation of our security measures, we cannot guarantee that a significant cyberattack will not occur.
A successful attack on our information technology systems could have significant consequences for our business.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.