15 unchanged sentences
We maintain an incident response plan to respond to and mitigate the effects of an information security incident.
−Removed: The plan provides for the formation of a multi-functional incident response team led by the Chief Information Officer (“CIO”) and comprised of IT, legal, corporate communications, internal audit, and operational personnel.
+Added: The plan provides for the formation of a multi-functional incident response team led by the Chief Information Officer (“CIO”) and comprised of IT, legal, corporate communications, internal audit, operational personnel, and members of the Board of Directors.
● Global Recovery.
2 unchanged sentences
We have an assessment and audit process for third party vendors .
−Removed: Prior to granting vendor access to our systems or data, we conduct pre-engagement diligence to ensure that each of our third party vendors involved in processing sensitive data have reasonable cybersecurity processes and procedures in place.
+Added: Prior to granting key vendor access to our systems or data, we conduct pre-engagement diligence to ensure that each of our third party vendors involved in processing sensitive data have reasonable cybersecurity processes and procedures in place.
We also have contractual provisions with key vendors for prompt notification of material cybersecurity incidents.
5 unchanged sentences
Although we have experienced non-material information security incidents from time to time in the past, in the last three years, we have not experienced any material cybersecurity incidents , nor has any incident had a material impact on our operations or financial condition.
−Removed: For a discussion of how risks from cybersecurity threats are reasonably likely to affect us, including our business strategy, results of operations, or financial condition, please see “If our information security measures are breached or fail and a customer’s or our data is improperly obtained or unauthorized access to our information technology systems occurs, we may incur significant legal and financial exposure and liabilities.” under the heading Part I, Item 1A “Risk Factors”.
+Added: For a discussion of how risks from cybersecurity threats are reasonably likely to affect us, including our business strategy, results of operations, or financial condition, please see “If our information security measures are breached, disrupted, or fail, we may incur significant legal and financial exposure and liabilities” under the heading Part I, Item 1A “Risk Factors”.
Cybersecurity Governance
2 unchanged sentences
The Audit and Finance Committee reports to the full Board and, if warranted, coordinates with the Board to address material risks.
−Removed: In addition, the full Board receives a cybersecurity briefing from the CIO annually.
+Added: In addition, two members of the Board have been delegated authority to serve as initial points of contact for the Board in the event of a severe information security incident.
+Added: The full Board receives a cybersecurity briefing from the CIO annually.
As discussed above, our cybersecurity risk management and strategy are led by our CIO, who has extensive leadership experience with enterprise information technology in the manufacturing and telecom industries, where he has held various executive roles in which he developed and executed IT strategy, including cybersecurity programs, helped achieve and maintain Sarbanes-Oxley compliance, and brought companies into compliance with ISO 27001, among other things.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.