20 unchanged sentences
We track key performance indicators and cybersecurity metrics to evaluate the efficacy of our cybersecurity controls and practices.
−Removed: Further, our cybersecurity program is periodically reviewed by senior members of management and adjusted as
−Removed: needed in an effort to maintain the program’s agility and responsiveness as circumstances and technologies evolve, new cybersecurity threats emerge and regulations change.
+Added: Further, our cybersecurity program is periodically reviewed by senior members of management and adjusted as needed in an effort to maintain the program’s agility and responsiveness as circumstances and technologies evolve, new cybersecurity threats emerge and regulations change.
In addition, we operate an enterprise risk management (“ERM”) program to identify, evaluate and manage risks.
14 unchanged sentences
We use third-party service providers to support our operations and many of our technology initiatives, including third parties that house financial or sensitive information.
−Removed: Our technology acquisition policy and our internal controls framework require us to obtain and review attestation reports regarding these third-party service providers and their sub-service processors or providers and their internal controls, complementary user entity controls and contractual obligations, including those specific to cybersecurity.
+Added: Our technology acquisition
+Added: policy and our internal controls framework require us to obtain and review attestation reports regarding these third-party service providers and their sub-service processors or providers and their internal controls, complementary user entity controls and contractual obligations, including those specific to cybersecurity.
We evaluate cybersecurity risks associated with our use of third-party service providers, which may include a review of a service provider’s cybersecurity posture or a recommendation of specific mitigation controls.
3 unchanged sentences
Although we have not previously experienced cybersecurity incidents that are individually, or in the aggregate, material, we have experienced cyberattacks in the past, which we believe have thus far been deflected or mitigated by our preventative, detective and responsive measures.
−Removed: For additional discussion of our cybersecurity related risks, see “Item 1.A Risk Factors.”
+Added: For additional discussion of our cybersecurity related risks, refer to “Item 1.A Risk Factors.”
Cybersecurity Governance
Board Oversight
−Removed: The Board is responsible for overseeing management’s assessments of major risks facing the Company and for reviewing options to mitigate these risks.
+Added: The Board is responsible for overseeing management’s assessments of major risks facing us and for reviewing options to mitigate these risks.
The Board’s oversight of cybersecurity risks occurs at both the Board level and through its Audit Committee.
12 unchanged sentences
This function is led by our Senior Vice President – Information Systems and Technology, who reports to our Chief Financial Officer.
−Removed: The IT Department’s security team, a cross-functional group composed of members who all have 12 to 26 years of professional and technical information technology experience, oversees the cybersecurity program to help ensure the confidentiality, integrity and availability of the company’s systems and mitigate day-to-day threats and exposures.
+Added: The IT Department’s security team, a cross-functional group composed of members who all have 7 to 27 years of professional and technical information technology experience, oversees the cybersecurity program to help ensure the confidentiality, integrity and availability of our systems and mitigate day-to-day threats and exposures.
It is responsible for measuring and managing cybersecurity risk, including the prevention, detection, mitigation and remediation of cybersecurity incidents and also for implementing cybersecurity policies, programs, procedures and strategies.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.