Unresolved Staff Comments
+Added: Ta b l e of Contents
Cybersecurity
Risk management and strategy
−Removed: We maintain a comprehensive process for identifying, assessing and managing material risks arising from cybersecurity threats, and have integrated these into our overall risk management processes.
−Removed: Our senior leadership team, along with representatives from our information technology, legal, human resources and finance departments, are responsible for developing the Company’s overall risk management program and are also responsible for executing our cybersecurity policies.
−Removed: We are establishing a formal written information security policy and incident response policy which outlines the methods for assessing, identifying, and managing risks related to the Company.
−Removed: We’ve developed a robust cybersecurity program which includes multiple security layers.
−Removed: We understand the importance of a strong cybersecurity framework and have hired external security consultants to assess, audit, and monitor its security controls and events.
−Removed: We also ensure that third-party service providers have the ability to implement and maintain appropriate security measures in connection with their work with us, and to promptly report any suspected breach of its security measures that may affect our company.
−Removed: In addition, we maintain a cybersecurity insurance policy.
−Removed: Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats.
+Added: We rely on information technology systems and various software applications to operate our business.
+Added: To address cybersecurity risks, we have implemented a comprehensive process for identifying, assessing, and managing material threats, and integrating these measures into our overall risk management framework.
+Added: Our Security Operations Team and Security Audit/Advisory Team play a key role in this strategy.
+Added: Our senior leadership team, in collaboration with representatives from the Security Operations Team, as well as the legal, human resources, and finance departments, are responsible for developing and executing the company's overall risk management program, including cybersecurity policies.
+Added: To enhance security, we have established an Information Security Program with a formal written security and incident response policy.
+Added: This policy outlines methods for assessing, identifying, and mitigating risks.
+Added: Our cybersecurity program incorporates multiple security layers, and we engage external security consultants to assess, audit, and monitor our security controls and events.
+Added: Additionally, we require third-party service providers to implement and maintain appropriate security measures and promptly report any suspected breaches that may impact the Company.
+Added: We also maintain a cybersecurity insurance policy.
+Added: We have invested in relevant tools and technologies to protect our data and business partners.
+Added: Our Security Operations Team continuously monitors risks specific to our industry.
+Added: We also leverage third-party assessors, consultants, and advisors to enhance our cybersecurity risk assessment and mitigation efforts.
+Added: To foster a security-conscious culture, we have implemented a cybersecurity awareness program that educates employees on identifying and reporting threats.
+Added: We conduct periodic phishing campaigns and training sessions to equip employees with the necessary skills to manage and defend against prevalent cybersecurity risks.
+Added: Additionally, employees in specialized IT roles receive targeted training, including tabletop exercises, among other training.
+Added: We continuously update and improve our cybersecurity program through independent assessments, penetration testing, and system vulnerability scanning.
+Added: Our security framework follows a hybrid approach, incorporating best practices from the Center for Internet Security framework and incorporating relevant standards from the National Institute of Standards and Technology Cybersecurity framework.
+Added: We also undergo an annual third-party assessment to evaluate the maturity of our cybersecurity program.
+Added: Additionally, we periodically engage external advisors to assess our program's effectiveness, strengthen policies, and identify potential vulnerabilities.
+Added: Our Security Operations Team led by VP of Technology, collaborates regularly with IT network teams and other management stakeholders to review and address cybersecurity risks and opportunities.
+Added: We have a global incident response plan with defined incident management protocols, escalation timelines, and responsibilities among other policies to manage data and its risks.
+Added: As of the date of this Annual Report on Form 10-K, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
Our board of directors, with delegation to the audit committee, as appropriate, retains oversight of the Company’s cybersecurity risks.
2 unchanged sentences
These communications include potential risks facing the Company, assessments and evaluations of our cybersecurity environment, results of internal controls testing, and reports on our on-going initiatives to strengthen our cybersecurity framework.
+Added: Ta b l e of Contents
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.