3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: To effectively prevent, detect, and respond to cybersecurity threats, the Company employs a multi-faceted cybersecurity risk management program supervised by our Vice President of Technology (VP of Tech), who reports directly to our CEO.
−Removed: The VP of Tech is responsible for leading our enterprise cybersecurity strategy.
+Added: To effectively prevent, detect, and respond to cybersecurity threats, the Company employs a multi-faceted cybersecurity risk management program supervised by our Senior Director of Technology Infrastructure and Operations ("Sr Director of Tech"), who reports directly to our CEO.
+Added: The Sr Director of Tech is responsible for leading our enterprise cybersecurity strategy.
This responsibility includes establishing processes designed to prevent and monitor potential cybersecurity risks, assessing potential cybersecurity incidents, implementing mitigation measures, and maintaining the cybersecurity program itself.
11 unchanged sentences
In addition, the assessments also provide the executive leadership and the Board of Directors an understanding of the Company’s security landscape and allows it to prepare to respond to threats.
−Removed: Cybersecurity threats continue to be identified as one of the Company’s significant risks, with our VP of Tech assigned as the risk owner.
−Removed: Our VP of Tech has developed expertise in cybersecurity and compliance, enterprise architecture and road mapping, data analytics and customer service through his eighteen years of experience in the information technology space including over thirteen years in senior leadership roles.
−Removed: He is currently a Certified Information Systems Security Professional (CISSP) and he holds a Master's degree in Software from the University of St.
+Added: Cybersecurity threats continue to be identified as one of the Company’s significant risks, with our Sr Director of Tech assigned as the risk owner.
+Added: Our Sr Director of Tech has developed expertise in cybersecurity and compliance, enterprise architecture and road mapping, data analytics and customer service through his twenty years of experience in the information technology space.
+Added: He holds a Bachelor's degree from the University of North Carolina, Charlotte.
The Board of Directors has delegated primary responsibility for the oversight of cybersecurity and information technology risks, and the Company’s preparedness for these risks, to the Audit Committee.
The Audit Committee serves and functions as the Board of Directors primary oversight body to monitor the Company’s cybersecurity and related information technology risks.
−Removed: The Audit Committee receives periodic updates from the VP of Tech on the Company’s policies, processes, procedures, and any significant development related to the identification, mitigation and remediation of cybersecurity risks.The Audit Committee ensures that the VP of Tech provides to the Board of Directors annual updates on our cybersecurity and information technology risk.
+Added: The Audit Committee receives periodic updates from the Sr Director of Tech on the Company’s policies, processes, procedures, and any significant development related to the identification, mitigation and remediation of cybersecurity risks.
+Added: The Audit Committee ensures that the Sr Director of Tech provides to the Board of Directors annual updates on our cybersecurity
+Added: and information technology risk.
These annual updates include topics related to our cybersecurity programs and mitigation strategies, trends in cybersecurity, and other cybersecurity-related developments.
We may engage third-party advisors to monitor threats and to scan for vulnerabilities.
−Removed: When a cybersecurity threat or incident is identified by our third-party advisor, it is reported directly to our VP of Tech.
−Removed: The VP of Tech in conjunction with professionals throughout the organization, including information technology specialists, accountants, and lawyers, determine severity and response, then manage it to conclusion in accordance with our cybersecurity incident response processes.
+Added: When a cybersecurity threat or incident is identified by our third-party advisor, it is reported directly to our Sr Director of Tech .
+Added: The Sr Director of Tech in conjunction with professionals throughout the organization, including information technology specialists, accountants, and lawyers, determine severity and response, then manage it to conclusion in accordance with our cybersecurity incident response processes.
We may engage third party advisors as part of our incident response processes to assist with digital forensics among other efforts.
−Removed: The VP of Tech, together with the cross-functional team, report material or potentially material incidents to our executive leadership and the Audit Committee.
−Removed: The VP of Tech provides further updates regarding root causes and remediation efforts.
+Added: The Sr Director of Tech, together with the cross-functional team, report material or potentially material incidents to our executive leadership and the Audit Committee.
+Added: The Sr Director of Tech provides further updates regarding root causes and remediation efforts.
In the event the Company determines it has experienced a material cybersecurity incident the Board of Directors is notified.
5 unchanged sentences
This review process is part of our commitment to confirming that these third-party service providers are safeguarding our operations and data integrity.
−Removed: We sustained a cybersecurity attack in May 2022 involving ransomware that caused a network disruption and impacted certain of our systems.
−Removed: Upon detection, we undertook steps to address the incident, including engaging a team of third-party forensic experts and notifying law enforcement.
−Removed: We restored network systems and resumed normal operations.
−Removed: The Company did not pay any ransomware and the attack did not materially affect the Company's business strategy, results of operations, or financial condition.
−Removed: We have taken actions to improve our existing systems such as adding multi-factor authentication and to improve employee training and security competency.
−Removed: We have not identified any other cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
−Removed: Please refer to our R isk F actors in Item 1 A for more information on the risks associated with cybersecurity attacks.
+Added: We have not identified any cybersecurity threats during the last two fiscal years that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: Please refer to our Risk Factors in Item 1A for more information on the risks associated with cybersecurity attacks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.