7 unchanged sentences
Our information technology (“IT”) cybersecurity leadership team works closely with our Security Committees and internal audit team to evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.
+Added: Using a risk-based prioritization approach, the IT cybersecurity leadership team and the Security Committees focus on securing our high value assets, updating our cybersecurity detection and prevention capabilities to identify new threats, and improving compliance processes to protect the Company’s operations and data.
+Added: During this process, the following factors, among others, are considered:
+Added: likelihood and severity of risk, impact on the Company and others if a risk materializes, feasibility and cost of controls, and impact of controls on operations.
+Added: The Company has also implemented technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality, access controls, and vulnerability and patch management.
Risk Management Personnel
1 unchanged sentence
The Company’s senior IT leadership bring over fifty years of combined IT experience to their roles.
−Removed: member of the Company’s IT cybersecurity leadership team, comprised of the AMC Sr.
−Removed: Director Cybersecurity and Network, the AMC Director Cybersecurity, the Odeon Group Head of Cyber, Risk and Operations and the AMC VP IT Operations, brings 20+ years of IT experience.
+Added: Each member of the Company’s IT cybersecurity leadership team, comprised of the AMC Director Cybersecurity, the Odeon Group Head of Cyber, Risk and Operations and the AMC SVP & Chief Information Officer, brings 20+ years of IT experience.
The Company regularly invests in training on these teams, and key leadership positions hold CISSP certifications.
−Removed: Our senior IT leadership and IT cybersecurity team, with input as appropriate from the Security Committees, oversee our governance programs, tests our compliance with standards, remediate known risks, and direct employee training.
+Added: Our senior IT leadership and IT cybersecurity team, with input as appropriate from the Security
+Added: Committees, oversee our governance programs, tests our compliance with standards, remediate known risks, and direct employee training.
Monitoring Cybersecurity Incidents
1 unchanged sentence
The Security Committees, and in particular senior IT leadership, IT cybersecurity and internal audit members serving on the Security Committees, implement and oversee processes for the regular monitoring of our information systems.
−Removed: The Company follows the NIST framework to design and implement security processes, tools and procedures, and regular system audits identify and lead to remediation of potential vulnerabilities.
+Added: The Company follows the National Institute of Standards and Technology (“NIST”) framework to design and implement security processes, tools and procedures, and regular system audits identify and lead to prompt remediation of potential vulnerabilities.
In the event of a cybersecurity incident, senior IT leadership and the Security Committees are equipped with a well-defined incident response plan.
29 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.