3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: To effectively prevent, detect, and respond to cybersecurity threats, the Company employs a multi-faceted cybersecurity risk management program supervised by our Senior Director of Technology Infrastructure and Operations ("Sr Director of Tech"), who reports directly to our CEO.
−Removed: The Sr Director of Tech is responsible for leading our enterprise cybersecurity strategy.
+Added: To effectively prevent, detect, and respond to cybersecurity threats, the Company employs a multi-faceted cybersecurity risk management program supervised by our Vice President, Technology, who reports directly to our CEO.
+Added: The Vice President, Technology is responsible for leading our enterprise cybersecurity strategy.
This responsibility includes establishing processes designed to prevent and monitor potential cybersecurity risks, assessing potential cybersecurity incidents, implementing mitigation measures, and maintaining the cybersecurity program itself.
11 unchanged sentences
In addition, the assessments also provide the executive leadership and the Board of Directors an understanding of the Company’s security landscape and allows it to prepare to respond to threats.
−Removed: Cybersecurity threats continue to be identified as one of the Company’s significant risks, with our Sr Director of Tech assigned as the risk owner.
−Removed: Our Sr Director of Tech has developed expertise in cybersecurity and compliance, enterprise architecture and road mapping, data analytics and customer service through his twenty years of experience in the information technology space.
+Added: Cybersecurity threats continue to be identified as one of the Company’s significant risks, with our Vice President, Technology assigned as the risk owner.
+Added: Our Vice President, Technology has developed expertise in cybersecurity and compliance, enterprise architecture and road mapping, data analytics and customer service through his twenty years of experience in the information technology space.
He holds a Bachelor's degree from the University of North Carolina, Charlotte.
1 unchanged sentence
The Audit Committee serves and functions as the Board of Directors' primary oversight body to monitor the Company’s cybersecurity and related information technology risks.
−Removed: The Audit Committee receives periodic updates from the Sr Director of Tech on the Company’s policies, processes, procedures, and any significant development related to the identification, mitigation and remediation of cybersecurity risks.
−Removed: The Audit Committee ensures that the Sr Director of Tech provides to the Board of Directors annual updates on our cybersecurity
−Removed: and information technology risk.
+Added: The Audit Committee receives periodic updates from the Vice President, Technology on the Company’s policies, processes, procedures, and any significant development related to the identification, mitigation and remediation of cybersecurity risks.
+Added: The Audit Committee ensures that the Vice President, Technology provides to the Board of Directors annual updates on our cybersecurity and information technology risk.
These annual updates include topics related to our cybersecurity programs and mitigation strategies, trends in cybersecurity, and other cybersecurity-related developments.
We may engage third-party advisors to monitor threats and to scan for vulnerabilities.
−Removed: When a cybersecurity threat or incident is identified by our third-party advisor, it is reported directly to our Sr Director of Tech .
−Removed: The Sr Director of Tech in conjunction with professionals throughout the organization, including information technology specialists, accountants, and lawyers, determine severity and response, then manage it to conclusion in accordance with our cybersecurity incident response processes.
+Added: When a cybersecurity threat or incident is identified by our third-party advisor, it is reported directly to our Vice President, Technology.
+Added: The Vice President, Technology in conjunction with professionals throughout the organization, including information technology specialists, accountants, and lawyers, determine severity and response, then manage it to conclusion in accordance with our cybersecurity incident response processes.
We may engage third party advisors as part of our incident response processes to assist with digital forensics among other efforts.
−Removed: The Sr Director of Tech, together with the cross-functional team, report material or potentially material incidents to our executive leadership and the Audit Committee.
−Removed: The Sr Director of Tech provides further updates regarding root causes and remediation efforts.
+Added: The Vice President, Technology, together with the cross-functional team, report material or potentially material incidents to our executive leadership and the Audit Committee.
+Added: The Vice President, Technology provides further updates regarding root causes and remediation efforts.
In the event the Company determines it has experienced a material cybersecurity incident, the Board of Directors is notified.
1 unchanged sentence
The Company continuously monitors the risk associated with its third-party service providers.
−Removed: The Company mandates that our key third-party service providers undergo an annual SOC 1 audit, which assist in identifying risks from cybersecurity threats.
+Added: The Company mandates that our key third-party service providers undergo an annual SOC 1 audit, which assists in identifying risks from cybersecurity threats.
In cases where a waiver is granted, the Company ensures that alternative measures are in place to maintain rigorous oversight.
2 unchanged sentences
We have not identified any cybersecurity threats during the last two fiscal years that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
−Removed: Please refer to our Risk Factors in Item 1A for more information on the risks associated with cybersecurity attacks.
+Added: P lease refer to our Risk Factors in Item 1A for more information on the risks associated with cybersecurity attacks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.