4 unchanged sentences
This process is supported by both our management and our Board of Directors.
−Removed: Our Chief Information Officer (CIO) oversees our information systems and cybersecurity function and reports to our Chief Operating Officer (COO).
−Removed: She has over 30 years of experience in leading information systems management, strategy, and operational execution, including incident management, prevention, and response.
−Removed: Our Senior Director of Global Information Security (ISD) reports to our CIO and is responsible for the protection and defense of our networks and systems and managing cybersecurity risk.
+Added: Our Chief Digital and Information Officer (CDIO) oversees our information systems and cybersecurity function and reports to our Chief Executive Officer (CEO).
+Added: He has over 30 years of experience in leading information systems management, strategy, and operational execution, including incident management, prevention, and response.
+Added: Our Chief Information Security Officer (CISO) reports to our CDIO and is responsible for the protection and defense of our networks and systems and managing cybersecurity risk.
He has over 20 years of experience in managing cybersecurity and related risks, including threat identification, incident response, and defense strategies.
−Removed: Our CIO and ISD are supported by a direct and cross-functional team of professionals with broad experience and expertise in threat assessment and detection, mitigation technologies, training, incident response, and regulatory compliance.
+Added: Our CDIO and CISO are supported by a direct and cross-functional team of professionals with broad experience and expertise in threat assessment and detection, mitigation technologies, training, incident response, and regulatory compliance.
Our Board of Directors is responsible for overseeing our enterprise risk management activities in general, which includes our management of information and cybersecurity risk.
2 unchanged sentences
As part of its oversight, the Audit Committee receives regular reports from management on information systems and security, including metrics and controls at each meeting, and other items at least annually including risk assessments, security software, incident response plans, and key updates to the cybersecurity program and its effectiveness.
−Removed: We have also established a committee of our executive leadership team to consider cybersecurity risks and to consider mitigation strategies in managing the risk.
−Removed: Our CIO and ISD participate on this committee, which meets regularly.
−Removed: We have an established incident response plan led by our CIO and ISD to assess, respond, and report in the event of a cybersecurity incident.
−Removed: Depending on the nature and severity of the incident, the plan requires escalating notifications up to our CEO, Audit Committee and our Board.
+Added: We have also established a committee of our executive leadership team to consider cybersecurity risks and to consider mitigation strategies in managing the risks.
+Added: Our CDIO and CISO participate on this committee, which meets regularly.
+Added: We have an established incident response plan led by our CDIO and CISO to assess, respond, and report in the event of a cybersecurity incident.
+Added: Depending on the nature and severity of the incident, the plan requires escalating notifications up to our CEO, the Audit Committee and our Board.
Cybersecurity Risk Management
3 unchanged sentences
Our approach to cybersecurity risk management includes:
−Removed: • Cybersecurity awareness training, including interactive simulations and tabletop exercises for our employees, incident response personnel, senior management, and our Board;
+Added: • Cybersecurity awareness training, including interactive simulations and tabletop exercises for our employees, incident response personnel, and senior management
• Periodic risk assessments designed to help identify significant or potentially material cybersecurity risks to our critical systems, information, and our broader enterprise information technology (IT) environment;
1 unchanged sentence
• A multi-layered defense and continuous monitoring strategy employing various tools and testing, and incorporating lessons learned from our defense and monitoring efforts to help prevent future attacks;
−Removed: • Regular testing by our Internal Audit function of controls related to our financial information systems;
• Information security assessments conducted on third parties with whom we share sensitive electronic data against established cybersecurity frameworks;
−Removed: While we have experienced cybersecurity incidents in the past, to-date none have materially affected the Company or our financial position, results of operations and/or cash flows.
+Added: While the Company's information systems are exposed to cybersecurity threats and risks, we have not experienced any material cybersecurity incidents during 2025, 2024 or 2023, and any costs or operational impacts related to cybersecurity incidents were immaterial during this period.
We continue to invest in cybersecurity and the resiliency of our networks, including our controls and processes, all of which are designed in an effort to protect our IT systems and infrastructure, and the information they contain.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.