5 unchanged sentences
Our process for assessing, identifying, managing and addressing information security risks include:
−Removed: • Internalization of Information Security Management .
−Removed: We have internalized our information security oversight by hiring a full time Head of Information Technology that has over 20 years of experience in managing information technology and guiding organizations through technology strategy, cybersecurity risk mitigation, information technology process improvement initiatives and digital transformations.
+Added: • Information Security Management .
+Added: Our information security oversight is managed by a full time Head of Information Technology that has over 20 years of experience in managing information technology and guiding organizations through technology strategy, cybersecurity risk mitigation, information technology process improvement initiatives and digital transformations.
He also possesses relevant experience in improving a company's cybersecurity posture and data privacy policies.
−Removed: He holds a Bachelor of Science degree in Information Systems and oversees all of our information security initiatives, assesses cybersecurity risks, provides cybersecurity plans, identifies opportunities for the implementation of additional cybersecurity measures and provides cybersecurity training to our employees and executives.
+Added: He holds a Bachelor of Science degree in Information Systems and oversees all of our information security initiatives, assesses cybersecurity risks, provides cybersecurity plans and identifies opportunities for the implementation of additional cybersecurity measures.
+Added: Our Information Technology team also includes a Senior Cybersecurity Engineer who has over 20 years of experience in Information Technology and Cybersecurity and holds multiple cybersecurity certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP) and Certified Cloud Security Professional (CCSP).
+Added: He also holds a Bachelor of Science degree in Information Systems.
+Added: The Senior Cybersecurity Engineer provides live, interactive annual information security training to our employees and executive officers and monitors the effectiveness of such training through quarterly phishing campaigns.
+Added: The Senior Cybersecurity Engineer also assists in managing cybersecurity risks associated with third-party service providers by administering a due diligence questionnaire for the Company's third-party service providers that includes a cybersecurity risk assessment and provides guidance for remediation of security gaps.
• Third-Party Consultant.
−Removed: We engage a third-party information security consultant to assist in managing our risk posture.
+Added: We also engage a third-party information security consultant to assist in managing our risk posture.
This consultant conducts periodic tests and analyses of our defensive and detective information security controls, including annual penetration tests and risk assessments as well as regular vulnerability scans and assessments.
−Removed: The consultant also provides live, interactive annual information security training to our employees and executive officers and monitors the effectiveness of such training through quarterly phishing campaigns.
−Removed: The consultant also assists us in managing cybersecurity risks associated with third-party service providers by administering a due diligence questionnaire for the Company's third-party service providers that includes a cybersecurity risk assessment and provides guidance for remediation of security gaps.
• Current Plans and Procedures .
20 unchanged sentences
• Enterprise Risk Assessment .
−Removed: The Company completes an annual enterprise risk assessment that includes cybersecurity risks and mitigants.
−Removed: The results of the enterprise risk assessment are shared with the Board of Directors on an annual basis.
+Added: The Company completes an enterprise risk assessment on a biennial basis that includes cybersecurity risks and mitigants.
+Added: The results of each enterprise risk assessment are shared with the Board of Directors.
• Implemented Programs for a Hybrid Work Environment.
5 unchanged sentences
Our Board of Directors exercises oversight of information security risk primarily through the Audit Committee.
−Removed: T he Head of Information Technology provides information security updates to named executive officers and briefs our Board of Directors and Audit Committee on relevant information security issues on a quarterly basis.
+Added: The Head of Information Technology provides information security updates to named executive officers and briefs our Board of Directors and Audit Committee on relevant information security issues on a quarterly basis.
We also make available periodic cybersecurity training for members of our Board of Directors.
−Removed: As of the date of this Report, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
+Added: As of the date of this Annual Report on Form 10-K, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
However, we acknowledge that cybersecurity threats are continually evolving and the possibility of future cybersecurity incidents remains.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.