1 unchanged sentence
Cybersecurity
−Removed: Our IT and related systems are
−Removed: critical to the efficient operation of our business and essential to our ability to perform day to day processes.
−Removed: We face persistent security
−Removed: threats, including threats to our IT infrastructure and unlawful attempts to gain access to our confidential or otherwise proprietary
−Removed: information, or that of our employees, via phishing/malware campaigns and other cyberattack methods.
−Removed: Our security policies and processes
−Removed: are based on industry best practices and are revisited regularly to ensure their appropriateness based on risk, threats and current technological
−Removed: capabilities.
−Removed: We regularly assess our threat landscape and monitor our systems and other technical security controls, maintain information
−Removed: security practices and ensure maintenance of backup and protective systems.
−Removed: We review System and Organization Controls 1 (SOC 1 Type II)
−Removed: certifications where relevant from key third party partners and other service providers with access to information assets at least annually.
−Removed: Our internal controls and procedures
−Removed: address cybersecurity and include processes intended to ensure that security breaches are reported to appropriate personnel and, if warranted,
−Removed: analyzed for potential disclosure.
−Removed: We also maintain insurance coverage that is intended to address certain aspects of cybersecurity risks.
+Added: IT and related systems are critical to the efficient operation of our business and essential to our ability to perform day-to-day processes.
+Added: We face persistent security threats, including threats to our IT infrastructure and unlawful attempts to gain access to our confidential
+Added: or otherwise proprietary information, or that of our employees, via phishing/malware campaigns and other cyberattack methods.
+Added: security policies and processes are based on industry best practices and are revisited regularly to ensure their appropriateness based
+Added: on risk, threats and current technological capabilities.
+Added: We regularly assess our threat landscape and monitor our systems and other technical
+Added: security controls, maintain information security practices and ensure maintenance of backup and protective systems.
+Added: We review System
+Added: and Organization Controls 1 (SOC 1 Type II) certifications where relevant from key third party partners and other service providers with
+Added: access to information assets at least annually.
+Added: internal controls and procedures address cybersecurity and include processes intended to ensure that security breaches are reported to
+Added: appropriate personnel and, if warranted, analyzed for potential disclosure.
+Added: We also maintain insurance coverage that is intended to address
+Added: certain aspects of cybersecurity risks.
To date, there have not been any cybersecurity threats that have materially affected the Company.
−Removed: Board Oversight of Cybersecurity Matters
−Removed: Assessing and managing information
−Removed: security matters is the responsibility of our Audit Committee.
−Removed: The Audit Committee meets with the senior executives, specifically the
−Removed: Chief Executive Officer and Chief Financial Officer on at least an annual basis to discuss cybersecurity posture.
−Removed: The Audit Committee
−Removed: may also periodically receive targeted briefings related to cybersecurity and reviews our incident response capabilities.
−Removed: Management of Cybersecurity Risks
+Added: Oversight of Cybersecurity Matters
+Added: and managing information security matters is the responsibility of our Audit Committee.
+Added: The Audit Committee meets with the senior executives,
+Added: specifically the Chief Executive Officer and Chief Financial Officer on at least an annual basis to discuss cybersecurity posture.
+Added: Audit Committee may also periodically receive targeted briefings related to cybersecurity and reviews our incident response capabilities.
+Added: of Cybersecurity Risks
senior executives work to protect our information systems from cybersecurity threats and to promptly assist in coordinating a response
to any cybersecurity incidents in accordance with our cybersecurity incident response and recovery plans.
−Removed: We have engaged an IT Managed Service Provider who assists in the oversight of our corporate-wide data security, including developing,
−Removed: implementing and enforcing security policies to manage our overall cybersecurity risks.
−Removed: The senior executives regularly meet with
−Removed: our IT Managed Service Provider during the course of the year to review and discuss cybersecurity issues.
−Removed: Our Security Culture
−Removed: We protect our information assets
−Removed: and manage risk by promoting a culture that communicates security risks, designs secure IT systems and operates according to approved
−Removed: processes to reduce the likelihood and impact of security incidents.
+Added: We have engaged an IT Managed
+Added: Service Provider who assists in the oversight of our corporate-wide data security, including developing, implementing and enforcing security
+Added: policies to manage our overall cybersecurity risks.
+Added: The senior executives regularly meet with our IT Managed Service Provider during
+Added: the course of the year to review and discuss cybersecurity issues.
+Added: Security Culture
+Added: protect our information assets and manage risk by promoting a culture that communicates security risks, designs secure IT systems and
+Added: operates according to approved processes to reduce the likelihood and impact of security incidents.
We achieve this objective by:
−Removed: designing, implementing and maintaining solutions with appropriate security controls;
−Removed: sustaining solutions with required patching and vulnerability remediation;
−Removed: creating and executing controls in support of policy as well as regulatory compliance;
−Removed: ensuring that our policies, processes, practices and technologies proactively protect, shield, defend and remediate cyber threats;
−Removed: delivering quality communications and annual training to stakeholders on cyber awareness and computing hygiene.
−Removed: We believe that the conduct of
−Removed: our employees is critical to the success of our information security.
−Removed: We keep our employees apprised of threats, risks and the part that
−Removed: they play in protecting both themselves and the Company.
−Removed: We assess our service providers
−Removed: prior to allowing our information to be processed, stored or transmitted by third parties, and we include standardized contractual requirements
−Removed: in each contract where appropriate.
−Removed: We validate our service providers’ security via questionnaires, open-source intelligence and,
−Removed: where appropriate, SOC 1 Type II reports on financially significant third-party service providers.
−Removed: Our process also includes regular monitoring
−Removed: of risk related to third parties on a periodic basis or when services or product purchases expand beyond their original scope or intended
+Added: designing, implementing
+Added: and maintaining solutions with appropriate security controls;
+Added: sustaining solutions with
+Added: required patching and vulnerability remediation;
+Added: creating and executing
+Added: controls in support of policy as well as regulatory compliance;
+Added: ensuring that our policies,
+Added: processes, practices and technologies proactively protect, shield, defend and remediate cyber threats;
+Added: delivering quality communications
+Added: and training to stakeholders on cyber awareness and computing hygiene.
+Added: believe that the conduct of our employees is critical to the success of our information security.
+Added: We keep our employees apprised of threats,
+Added: risks and the part that they play in protecting both themselves and the Company.
+Added: assess our service providers prior to allowing our information to be processed, stored or transmitted by third parties , and we include
+Added: standardized contractual requirements in each contract where appropriate.
+Added: We validate our service providers’ security via open-source
+Added: intelligence and, where appropriate, SOC 1 Type II reports on financially significant third-party service providers.
+Added: Our process also
+Added: includes regular monitoring of risk related to third parties on a periodic basis or when services or product purchases expand beyond
+Added: their original scope or intended use.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.