6 unchanged sentences
Such incidents could lead to shutdowns or disruptions of or damage to our systems and those of our customers and suppliers, and unauthorized disclosure of sensitive or confidential information, potentially including personal data and proprietary business information.
−Removed: Unauthorized disclosure of, denial of access to, or other incidents involving sensitive or confidential Company, employee, customer or supplier data, whether through systems failure, employee negligence, fraud, misappropriation, or cybersecurity, ransomware or malware attacks, or other intentional or unintentional acts, could damage our reputation and our competitive positioning in the marketplace, disrupt our or our customer’s business, cause us to lose customers and result in significant financial exposure and legal liability.
+Added: Unauthorized disclosure of, denial of access to, or other incidents involving sensitive or confidential Company, employee, customer or supplier data, whether through systems failure, employee negligence, fraud, misappropriation, or cybersecurity, ransomware or malware attacks, or other intentional or unintentional acts, could damage our reputation and our competitive positioning in the marketplace, disrupt our business or our customers' businesses, cause us to lose customers and result in significant financial exposure and legal liability.
These risks are identified, assessed and managed within the broader context of our ERM strategy, ensuring a comprehensive approach to organizational risk.
14 unchanged sentences
Our incident response and crisis management plan coordinates the activities we will take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity for, escalate, contain, investigate, and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate reputational damage.
−Removed: In addition, we provide regular security awareness education and training for all employees and consultants, conduct internal “phishing” testing and training for “clickers,” require mandatory security training for all new hires and publish periodic cybersecurity newsletters to highlight any emerging or urgent security threats.
+Added: In addition, we provide regular security awareness education and training for all employees and consultants, conduct internal “phishing” testing and training for “clickers,” require mandatory security training for all new hires and publish
+Added: periodic cybersecurity newsletters to highlight any emerging or urgent security threats.
We also carry insurance that provides protection against the potential losses arising from a cybersecurity incident.
4 unchanged sentences
Our contracts explicitly include requirements relating to cybersecurity, including adherence to certain standards, to ensure compliance with our security protocols.
−Removed: Once engaged, we regularly monitor the cybersecurity posture of these providers through surveys and reports, audits, and performance reviews.
+Added: Once engaged, we regularly monitor the cybersecurity posture of major providers through log reports and intelligent threat protection analysis.
Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previous cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks and any future material incidents.
4 unchanged sentences
The Board of Directors oversees our risk management processes, including with respect to cybersecurity risk, and the Board considers cybersecurity risk management an enterprise priority.
−Removed: The Board has delegated primary
−Removed: responsibility for reviewing and discussing with management our strategies, initiatives and policies relating to cybersecurity to the Audit Committee, which regularly reports to the full Board regarding such review and discussions.
+Added: The Board has delegated primary responsibility for reviewing and discussing with management our strategies, initiatives and policies relating to cybersecurity to the Audit Committee, which regularly reports to the full Board regarding such review and discussions.
In addition, in connection with its oversight of cybersecurity risks in relation to financial reporting and internal controls, the Audit Committee plays a crucial role in the Board’s understanding and management of the financial and operational impacts of cybersecurity risks.
15 unchanged sentences
This expertise is crucial in aligning our cybersecurity initiatives with business objectives, ensuring that our strategies effectively support the Company's overall goals.
−Removed: The Director of Information Security, reporting to and collaborating with the Vice President of Information Technology & the Chief Information Officer, manages our Enterprise Cybersecurity team.
+Added: The Director of Information Security, reporting to and collaborating with the Chief Information Officer, manages our Enterprise Cybersecurity team.
Day-to-day responsibilities include the implementation of cybersecurity strategies, cybersecurity risk management, and enhancing defenses against evolving threats.
Our Director of Information Security has over 30 years of IT experience, 10 of which have been spent leading the Company’s cybersecurity efforts.
−Removed: The Information Security Director plays a key role in shaping our cybersecurity strategy, ensuring alignment with industry standards and integration into our broader IT strategy.
+Added: The Information Security plays a key role in shaping our cybersecurity strategy, ensuring alignment with industry standards and integration into our broader IT strategy.
Regular reporting channels between the Director of Information Security, the Chief Information Officer, and the Chief Financial Officer facilitate a cohesive, well-informed approach to managing cybersecurity risks.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.