Unresolved Staff Comments
−Removed: Ta b l e of Contents
Cybersecurity
8 unchanged sentences
Additionally, we require third-party service providers to implement and maintain appropriate security measures and promptly report any suspected breaches that may impact the Company.
−Removed: We also maintain a cybersecurity insurance policy.
+Added: We also maintain a cybersecurity insurance policy that is intended to address certain costs that we may incur in the event that we experience a cybersecurity incident.
We have invested in relevant tools and technologies to protect our data and business partners.
−Removed: Our Security Operations Team continuously monitors risks specific to our industry.
+Added: Our Security Operations Team continuously monitors risks specific to us and our industry.
We also leverage third-party assessors, consultants, and advisors to enhance our cybersecurity risk assessment and mitigation efforts.
2 unchanged sentences
Additionally, employees in specialized IT roles receive targeted training, including tabletop exercises, among other training.
+Added: Following our acquisition of Alimera, we prioritized the integration and adoption of consistent policies and procedures related to information security, data privacy, and cybersecurity practices, with a strong focus on aligning security and privacy standards across our organization.
We continuously update and improve our cybersecurity program through independent assessments, penetration testing, and system vulnerability scanning.
2 unchanged sentences
Additionally, we periodically engage external advisors to assess our program's effectiveness, strengthen policies, and identify potential vulnerabilities.
−Removed: Our Security Operations Team led by VP of Technology, collaborates regularly with IT network teams and other management stakeholders to review and address cybersecurity risks and opportunities.
+Added: Our Security Operations Team led by a VP of Technology, collaborates regularly with IT network teams and other management stakeholders to review and address cybersecurity risks and opportunities.
We have a global incident response plan with defined incident management protocols, escalation timelines, and responsibilities among other policies to manage data and its risks.
−Removed: As of the date of this Annual Report on Form 10-K, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company.
+Added: As of the date of this Annual Report on Form 10-K, we have not identified any cybersecurity incidents that have materially affected affect our business strategy, results of operations or financial condition, or are reasonably likely to materially affect the Company, including any cybersecurity incidents involving our vendors' facilities or systems.
+Added: Please refer to “ We rely significantly on information technology and any failure, inadequacy, interruption, or security lapse of that technology, including any cybersecurity incidents, could harm our ability to operate the business effectively.
+Added: ” in Item 1A of this Annual Report on Form 10-K.
Our Board of Directors, with delegation to the Audit Committee, as appropriate, retains oversight of the Company’s cybersecurity risks.
−Removed: The senior leadership team provides periodic reports to our board of directors, as well as the Chief Executive Officer and audit committee as necessary .
+Added: The senior leadership team led by our VP of Technology provides periodic reports to our Board of Directors, as well as the Chief Executive Officer and Audit Committee as necessary .
+Added: The current VP of Technology has more than 20 years of experience in cybersecurity, while possessing the required subject matter expertise, skills, experience, and industry certifications expected of an individual assigned to these duties.
In addition, we have contracted with certified security experts that act as an extension of the internal information technology team for all security related items.
These communications include potential risks facing the Company, assessments and evaluations of our cybersecurity environment, results of internal controls testing, and reports on our on-going initiatives to strengthen our cybersecurity framework.
−Removed: Ta b l e of Contents
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.