1 unchanged sentence
Cybersecurity
−Removed: The Company has no employees and is externally managed by our Manager.
−Removed: Pursuant to the terms of the Management Agreement, our Manager manages, operates and administers our day-to-day operations, business and affairs, subject to the direction and supervision of the Board.
+Added: The Company has no employees and is externally managed by our Adviser.
+Added: Pursuant to the terms of the Advisory Agreement, our Adviser manages, operates and administers our day-to-day operations, business and affairs, subject to the direction and supervision of the Board.
The Board recognizes the critical importance of maintaining the trust and confidence of our business partners.
−Removed: The Board plays an active role in overseeing management of our risks, and
−Removed: cybersecurity represents an important component of the Company’s overall approach to risk management and oversight.
−Removed: The Company and our Manager are committed to protecting the confidentiality of all nonpublic information related to the Company’s borrowers, shareholders and their personnel.
+Added: The Board plays an active role in overseeing management of our risks, and cybersecurity represents an important component of the Company’s overall approach to risk management and oversight.
+Added: The Company and our Adviser are committed to protecting the confidentiality of all nonpublic information related to the Company’s borrowers, shareholders and their personnel.
Risk Management and Strategy
−Removed: As an externally managed company, the Company relies on our Manager’s corporate information technology, accounting and financial reporting platforms, enterprise applications and related systems (the “Information Systems”) in connection with the Company’s day-to-day operations.
−Removed: Our Manager has adopted a written information security program (the “Written Information Security Policy”), which is designed to address applicable requirements under Regulation S-P and the FTC Safeguards Rule.
−Removed: Consequently, the Company also relies on the processes for assessing, identifying, and managing material risks from cybersecurity threats under the Manager’s Written Information Security Policy.
+Added: As an externally managed company, the Company relies on our Adviser’s corporate information technology, accounting and financial reporting platforms, enterprise applications and related systems (the “Information Systems”) in connection with the Company’s day-to-day operations.
+Added: Our Adviser has adopted a written information security program (the “Written Information Security Policy”), which is designed to address applicable requirements under Regulation S-P and the FTC Safeguards Rule.
+Added: Consequently, the Company also relies on the processes for assessing, identifying, and managing material risks from cybersecurity threats under the Adviser’s Written Information Security Policy.
The processes include, among other things, maintaining secure digital or physical access to information assets, using manual and automated detection methods for malicious code, due diligence of third-party vendors, and engaging a leading provider of cybersecurity services to assess and manage cybersecurity risk.
For third-party service vendors that perform a variety of important functions for our business, we seek to engage reliable, reputable service vendors that maintain cybersecurity programs.
−Removed: All of the Company’s personnel are employees of the Manager or one of its affiliates and are subject to the Manager’s policies and procedures.
−Removed: Our Manager utilizes a third-party managed & cybersecurity services provider (the “MSSP”) for cybersecurity services, including threat detection and response, vulnerability assessment and monitoring, security incident response and recovery and general cybersecurity education and awareness.
−Removed: Our Manager and the MSSP engage in periodic assessment and training regarding the policies, standards and practices designed to address cybersecurity threats and incidents.
+Added: All of the Company’s personnel are employees of the Adviser or one of its affiliates and are subject to the Adviser’s policies and procedures.
+Added: Our Adviser utilizes a third-party managed & cybersecurity services provider (the “MSSP”) for cybersecurity services, including threat detection and response, vulnerability assessment and monitoring, security incident response and recovery and general cybersecurity education and awareness.
+Added: Our Adviser and the MSSP engage in periodic assessment and training regarding the policies, standards and practices designed to address cybersecurity threats and incidents.
Our cybersecurity risk management is integrated into our overall enterprise risk management and shares common methodologies, reporting channels and governance processes that apply across our enterprise risk management.
7 unchanged sentences
The Company relies on the MSSP’s processes for assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: The Company’s Chief Financial Officer and Treasurer, Chief Legal Officer and Secretary, and Head of IT work collaboratively with other employees of our Manager or its affiliates and the MSSP to ensure the MSSP’s services protect the Company’s Information Systems from cybersecurity threats and to promptly respond to any cybersecurity incidents.
+Added: The Company’s Chief Financial Officer and Treasurer, Chief Legal Officer and Secretary, and Head of IT work collaboratively with other employees of our Adviser or its affiliates and the MSSP to ensure the MSSP’s services protect the Company’s Information Systems from cybersecurity threats and to promptly respond to any cybersecurity incidents.
These members of the Company’s management team, together with the MSSP, monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and report such threats and incidents to the Audit and Valuation Committee when appropriate.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.