4 unchanged sentences
materially adversely affect our operations, performance and results of operations.
−Removed: We maintain a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
−Removed: This program addresses cybersecurity risks to the corporate information technology (“IT”) environment including systems,
−Removed: hardware, software, data, people, and processes.
+Added: maintain a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
+Added: addresses cybersecurity risks to the corporate information technology (“IT”) environment including systems, hardware, software,
+Added: data, people, and processes.
Audit Committee of the Board of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity
−Removed: Our VP of Information Security regularly briefs senior leadership on our cybersecurity and information security posture including
−Removed: on the prevention, detection, mitigation, and remediation of cybersecurity incidents, and senior leadership will then brief the Audit
−Removed: In the event of an incident, we intend to follow our incident response playbook, which outlines our planned response from
−Removed: incident detection to mitigation, recovery and notification, including notifying functional areas (e.g.
−Removed: legal), as well as senior leadership
−Removed: and the Board, as appropriate.
+Added: Our Head of Information Security has primary responsibility for our entity-wide information security program.
+Added: Our current Head
+Added: of Information Security has held that position since 2019 and has broad information technology and cybersecurity experience as a result
+Added: of that role and past work experience which includes cybersecurity consulting.
+Added: Our Head of Information Security regularly briefs senior
+Added: leadership on our cybersecurity and information security posture including on the prevention, detection, mitigation, and remediation
+Added: of cybersecurity incidents, and senior leadership will then brief the Audit Committee.
+Added: In the event of an incident, we intend to follow
+Added: our incident response playbook, which outlines our planned response from incident detection to mitigation, recovery and notification,
+Added: including notifying functional areas (e.g.
+Added: legal), as well as senior leadership and the Board, as appropriate.
security team is responsible for our overall information security strategy, including policy, security engineering, operations and cyber
2 unchanged sentences
initiatives, and processes.
−Removed: Employees outside of our security team also have a role in our cybersecurity defenses, and they are given
−Removed: training which we believe improves our cybersecurity.
−Removed: parties also play a role in our cybersecurity risk management strategy.
−Removed: We engage third parties to conduct risk assessments and
−Removed: evaluations of our security controls.
+Added: Employees outside of our security team and third parties also have a role in our cybersecurity defenses.
+Added: Such employees are given training which we believe improves our cybersecurity.
+Added: We engage third parties to conduct risk assessments and evaluations
+Added: of our security controls.
Such risk assessment and evaluations identify, quantify, and categorize any cyber risks.
−Removed: addition, we, along with third party cyber risk management specialists, develops a risk mitigation plan to address such risks, and
−Removed: where necessary, remediate potential vulnerabilities identified through the assessment and evaluation process.
−Removed: cybersecurity risk management engagement also includes activities such as penetration testing, independent audits or consulting on
−Removed: best practices to address new challenges.
+Added: In addition, we, along
+Added: with third party cyber risk management specialists, develops a risk mitigation plan to address such risks, and where necessary, remediate
+Added: potential vulnerabilities identified through the assessment and evaluation process.
+Added: have processes to oversee and identify cybersecurity risks associated with the use of third party service providers in our organization’s
+Added: Third party cybersecurity risk management engagement also includes activities such as penetration testing, independent audits
+Added: or consulting on best practices to address new challenges.
We include security and privacy addendums to our contracts where applicable.
−Removed: commenced third party risk management assessments to help manage the risks associated with reliance on vendors, critical service providers,
−Removed: and other third-parties that may lead to a service disruption or an adverse cybersecurity incident.
−Removed: VP of Information Security and cybersecurity stakeholders regularly brief the senior leadership team on cyber vulnerabilities identified
−Removed: through the risk management process, the effectiveness of our cyber risk management program, the emerging threat landscape,
−Removed: and new cyber risks on at least an annual basis.
−Removed: This includes updates on our processes to prevent, detect, and mitigate
−Removed: cybersecurity incidents.
+Added: We also perform third party risk management assessments to help manage the risks associated with reliance on vendors, critical
+Added: service providers, and other third-parties that may lead to a service disruption or an adverse cybersecurity incident.
+Added: Head of Information Security and cybersecurity stakeholders regularly brief the senior leadership team on cyber vulnerabilities identified
+Added: through the risk management process, the effectiveness of our cyber risk management program, the emerging threat landscape, and new cyber
+Added: risks on at least an annual basis.
+Added: This includes updates on our processes to prevent, detect, and mitigate cybersecurity incidents.
Notwithstanding
1 unchanged sentence
a material adverse effect on us.
−Removed: While we maintain cybersecurity insurance, the costs related to cybersecurity threats or
−Removed: disruptions may not be fully insured.
−Removed: We have not identified any risks from known cybersecurity threats, including as a result of
−Removed: any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect our operations,
−Removed: business strategy, regulatory compliance, results of operations, or financial condition.
−Removed: proactively seeks to detect and investigate unauthorized attempts and attacks against Company IT assets, data, and services, and to
−Removed: prevent their occurrence and recurrence where practicable through changes or updates to internal processes and tools and changes or
−Removed: updates to Company service delivery;
−Removed: however, potential vulnerabilities to known or unknown threats will still remain.
+Added: While we maintain cybersecurity insurance, the costs related to cybersecurity threats or disruptions
+Added: may not be fully insured.
+Added: We have not identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity
+Added: incidents, that have materially affected or are reasonably likely to materially affect our operations, business strategy, regulatory
+Added: compliance, results of operations, or financial condition.
+Added: The Company proactively seeks to detect and investigate unauthorized attempts
+Added: and attacks against Company IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through changes
+Added: or updates to internal processes and tools and changes or updates to Company service delivery;
+Added: however, potential vulnerabilities to
+Added: known or unknown threats will still remain.
“Risk Factors” for a discussion of cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.