12 unchanged sentences
It is led by our Chief Financial Officer and its actions are reported to our Board of Directors on a quarterly basis.
−Removed: Our Chief Information Officer and Director of Information Security, along with members of their respective teams, are responsible for identifying and managing cybersecurity risk.
+Added: Our Chief Information Officer and Senior Director of Information Security, along with members of their respective teams, are responsible for identifying and managing cybersecurity risk.
The Senior Leadership Team, the Board of Directors and the Board’s Audit Committee receive regular updates and engage in regular strategic discussions relating to cybersecurity risk management as part of their overall oversight of risk management.
−Removed: Our cybersecurity framework leverages internationally recognized standards, including the CIS 20 and the NIST SP 800-171 frameworks, and is required to comply with the Department of Defense CMMC.
+Added: Our cybersecurity framework leverages internationally recognized standards, including the CIS 20 and the NIST SP 800-171 frameworks, and is required to comply with the Department of War Cybersecurity Maturity Model Certification (CMMC).
We have policies and procedures in place designed to maintain compliance with relevant cybersecurity and data privacy laws and regulations in the jurisdictions in which we operate, such as the European Union GDPR and the California Consumer Privacy Act.
6 unchanged sentences
Our incident response and crisis management plan coordinates the activities we will take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity for, escalate, contain, investigate, and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate reputational damage.
−Removed: In addition, we provide regular security awareness education and training for all employees and consultants, conduct internal “phishing” testing and training for “clickers,” require mandatory security training for all new hires and publish
−Removed: periodic cybersecurity newsletters to highlight any emerging or urgent security threats.
+Added: In addition, we provide regular security awareness education and training for all employees and consultants, conduct internal “phishing” testing and training for “clickers,” require mandatory security training for all new hires and publish periodic cybersecurity newsletters to highlight any emerging or urgent security threats.
We also carry insurance that provides protection against the potential losses arising from a cybersecurity incident.
14 unchanged sentences
As part of their oversight of cybersecurity risk, the Board and Audit Committee regularly review detailed cybersecurity reports, which include analyses of the threat landscape, recent incidents, and the efficacy of our cybersecurity strategy.
−Removed: In addition, the Chief Information Officer provides bi-annual updates to the Audit Committee and annual briefings to the full Board on our cybersecurity posture, strategy, and risk management.
+Added: In addition, the Chief Information Officer and Senior Director of Information Security provide bi-annual updates to the Audit Committee and annual briefings to the full Board on our cybersecurity posture, strategy, and risk management.
These reviews and updates are complemented by ongoing cybersecurity training for board members to enhance their decision-making and oversight effectiveness.
4 unchanged sentences
This proactive stance is essential to safeguarding digital assets and ensuring operational resilience against evolving cyber threats.
−Removed: Quarterly, the Chief Information Officer presents detailed cybersecurity reports to the Enterprise Risk Committee, focusing on strategic initiatives and evolving threats.
+Added: Quarterly, the Chief Information Officer and Senior Director of Information Security present detailed cybersecurity reports to the Enterprise Risk Committee, focusing on strategic initiatives and evolving threats.
The Enterprise Risk Committee, meeting quarterly, evaluates cybersecurity within the broader organizational risk context, ensuring consistent assessment and management.
5 unchanged sentences
This expertise is crucial in aligning our cybersecurity initiatives with business objectives, ensuring that our strategies effectively support the Company's overall goals.
−Removed: The Director of Information Security, reporting to and collaborating with the Chief Information Officer, manages our Enterprise Cybersecurity team.
+Added: The Senior Director of Information Security, reporting to and collaborating with the Chief Information Officer, manages our Enterprise Cybersecurity team.
Day-to-day responsibilities include the implementation of cybersecurity strategies, cybersecurity risk management, and enhancing defenses against evolving threats.
−Removed: Our Director of Information Security has over 30 years of IT experience, 10 of which have been spent leading the Company’s cybersecurity efforts.
+Added: Our Senior Director of Information Security has over 35 years of IT experience, 12 of which have been spent leading the Company’s cybersecurity efforts.
The Information Security plays a key role in shaping our cybersecurity strategy, ensuring alignment with industry standards and integration into our broader IT strategy.
−Removed: Regular reporting channels between the Director of Information Security, the Chief Information Officer, and the Chief Financial Officer facilitate a cohesive, well-informed approach to managing cybersecurity risks.
+Added: Regular reporting channels between the Senior Director of Information Security, the Chief Information Officer, and the Chief Financial Officer facilitate a cohesive, well-informed approach to managing cybersecurity risks.
These reports include detailed analyses of potential threats, incident response readiness, and the effectiveness of existing cybersecurity measures.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.