1 unchanged sentence
Cybersecurity
−Removed: We recognize the critical importance of maintaining the safety and security of our systems and data and have a holistic process for overseeing and managing cybersecurity and related risks.
+Added: We recognize the critical importance of maintaining the safety and security of our systems and data and we believe we have a holistic process for assessing, identifying and managing cybersecurity and related risks.
In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach.
Our board of directors is actively involved in oversight of our risk management program, and cybersecurity represents an important component of our overall approach to enterprise risk management.
−Removed: Senior management also devotes significant resources to cybersecurity and risk management processes as well as to adapt to the changing cybersecurity landscape and respond to emerging threats in a timely and effective manner.
+Added: Senior management also devotes significant resources to cybersecurity and risk management processes as well as to adapting to the changing cybersecurity landscape and responding to emerging threats in a timely and effective manner.
Risk Management and Strategy
−Removed: We devote significant resources and designate high-level personnel, including our Chief Technology Officer who reports to our President of Amprius Lab, to manage the risk assessment and mitigation process.
+Added: We devote significant resources and designate high-level personnel, including our Chief Technology Officer (“CTO”), to manage the risk assessment and mitigation process.
We conduct periodic risk assessments to identify cybersecurity threats, as well as assessments in the event of a material change in our business practices that may affect information systems that are vulnerable to such cybersecurity threats.
3 unchanged sentences
and regularly monitor the effectiveness of our safeguards.
+Added: Index to Consolidated Financial Statements
As part of our overall risk management system, we monitor and test our safeguards and train our employees on these safeguards, in collaboration with human resources, IT, and management.
Personnel at all levels and departments are made aware of our cybersecurity policies through trainings and related documentation.
−Removed: Index to Consolidated Financial Statements
We engage third parties in connection with our risk assessment processes .
−Removed: These service providers assist us to design and implement our cybersecurity policies and procedures, as well as to monitor and test our safeguards.
−Removed: We require each third-party service provider to certify that it has the ability to implement and maintain appropriate security measures, consistent with all applicable laws, to implement and maintain reasonable security measures in connection with their work with us, and to promptly report any suspected breach of its security measures that may affect our company.
+Added: These service providers assist us in designing and implementing our cybersecurity policies and procedures, as well as in monitoring and testing our safeguards.
+Added: We also engage third-party service providers in connection with our business.
+Added: We require each such third-party service provider to certify that it has the ability to implement and maintain appropriate security measures, consistent with all applicable laws, to implement and maintain reasonable security measures in connection with their work with us, and to promptly report any suspected breach of its security measures that may affect our company.
For additional information regarding cybersecurity threats that are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to the section titled “Risk Factors” above.
4 unchanged sentences
Dixon, is a Director for Business Executives for National Security (BENS.org), and a member of the Aspen Institute’s Cybersecurity Group, the nation’s leading cross-sector public-private cybersecurity forum and he has extensive experience leading cyber security oversight.
−Removed: The President of Amprius Lab and the Chief Technology Officer are responsible for developing and implementing our information security program and reporting on cybersecurity matters to our board of directors.
−Removed: Our Chief Technology Officer has over 20 years of experience in managing IT, software and hardware systems and leading cybersecurity oversight.
+Added: Our CTO is responsible for developing and implementing our information security program and reporting on cybersecurity matters to our board of directors.
+Added: Our CTO has over 20 years of experience in managing IT, software and hardware systems and leading cybersecurity oversight.
He works closely with our third-party managed service provider and managed security service provider to oversee cybersecurity risks, advise on employee trainings and respond to new risks and threats when they occur.
We view cybersecurity as a shared responsibility by all operations, and we engage third-party vendors to periodically perform simulations and tabletop exercises across our company and incorporate other external resources and advisors as needed.
−Removed: All newly hired employees are required to complete two cybersecurity trainings during their onboarding process.
−Removed: All employees are required to complete cybersecurity online training every other month, including topics such as spear phishing as well as other awareness training.
+Added: All employees are required to complete online cybersecurity trainings every six months containing topics about cybersecurity risks awareness and how to prevent them, such as phishing, ransomware, malware, and social engineering attacks, among others.
+Added: In addition, all newly hired employees are required to complete a one-hour online cybersecurity training during their onboarding process.
We face a number of cybersecurity risks in connection with our business.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.