1 unchanged sentence
Cybersecurity
−Removed: Assessment, Identification and Management of Material Risks from Cybersecurity
+Added: Assessment, Identification and Management of Material Risks from Cybersecurity Threats
Our cybersecurity strategy prioritizes the detection and analysis of, and response to, known, anticipated or unexpected threats, effective management of security risks and resilience against cyber incidents.
4 unchanged sentences
Through our cybersecurity risk management process, we seek to monitor cybersecurity vulnerabilities and potential attack vectors, evaluate the potential operational and financial effects of any threat and mitigate such threats.
−Removed: The assessment of cybersecurity risks is integrated into our Enterprise Risk Management program, which is overseen by our Enterprise Risk Committee (the “ERC”), as discussed below.
+Added: The assessment of cybersecurity threats is integrated into our Enterprise Risk Management program, which is overseen by our Enterprise Risk Committee (the “ERC”), as discussed below.
In addition, we periodically engage third-party consultants and engage with key vendors to assist us in assessing, enhancing, implementing, and monitoring our cybersecurity risk management programs and responding to incidents.
6 unchanged sentences
Depending on their nature, incidents may also be reported to our audit committee of the board of directors and to our full board of directors, if appropriate.
−Removed: Material Impact of Cybersecurity Risks
−Removed: In the last three fiscal years, we have not experienced a material information security breach incident and the expenses we have incurred from information security breach incidents have been immaterial, and we are not aware of any cybersecurity risks that are reasonably likely to materially affect our business.
+Added: Material Impact of Risks from Cybersecurity Threats
+Added: We have not experienced an information security breach incident that has materially affected our business strategy, results of operations or financial condition.
+Added: The expenses we have incurred from information security breach incidents have been immaterial, and we are not aware of any cybersecurity risks that are reasonably likely to materially affect our business.
However, future incidents could have a material impact on our business strategy, results of operations or financial condition.
For additional discussion of the risks posed by cybersecurity threats, see “Item 1A.
−Removed: Risk Factors—General Risk Factors—Cybersecurity failures and data security incidents could adversely affect our business by causing a disruption to our operations, a compromise or corruption of our confidential, personal or other sensitive information and/or damage to our business relationships or reputation, any of which could negatively impact our business, financial condition and operating results.”
+Added: Risk Factors—General Risk Factors—Security incidents or cyber-attacks could adversely affect our business by causing a disruption to our operations, a compromise or corruption of our confidential, personal or other sensitive information and/or damage to our business relationships or reputation, any of which could negatively impact our business, financial condition and operating results.”
Oversight of Cybersecurity Risks
1 unchanged sentence
The team is led by our CISO who has a Master’s degree in Cybersecurity from Brown University and over 25 years of experience advising on, and managing risks from cybersecurity threats as well as developing and implementing cybersecurity policies and procedures.
−Removed: The CISO is also a member of the ERC.
−Removed: The ERC is a cross-functional committee that governs and oversees our Enterprise Risk Program, including cybersecurity.
−Removed: The ERC includes our Chief Executive Officer, Chief Financial Officer, General Counsel, Global Chief Compliance Officer, Chief Information Officer, CISO, and Head of Enterprise Risk, who acts as chairperson of the ERC.
+Added: The CISO reports cybersecurity updates to the ERC.
+Added: The ERC is a committee that governs and oversees our Enterprise Risk Program, including
+Added: cybersecurity.
+Added: The ERC includes our Chief Executive Officer, Co-Presidents, Chief Financial Officer, General Counsel, Global Chief Compliance Officer and Head of Enterprise Risk, who acts as chairperson of the ERC.
The ERC, through regular consultation with the internal cybersecurity team, assesses, discusses, and prioritizes our approach to high-level risks, mitigating controls, and ongoing cybersecurity efforts.
The audit committee has primary responsibility for oversight and review of guidelines and policies with respect to risk assessment and risk management, including cybersecurity.
−Removed: Certain members of the ERC periodically report to our audit committee as well as the full board of directors, as appropriate, on cybersecurity matters, primarily through presentations by the CISO and the Head of Enterprise Risk.
+Added: Periodically, reports are provided to our audit committee as well as the full board of directors , as appropriate, on cybersecurity matters, primarily through presentations by the CISO and the Head of Enterprise Risk.
Such reporting includes updates on our cybersecurity program, the external threat environment, and our programs to address and mitigate the risks associated with the evolving cybersecurity threat environment.
These reports also include updates on our preparedness, prevention, detection, responsiveness, and recovery with respect to cyber incidents.
+Added: Our principal executive offices are located in leased office space at 1800 Avenue of the Stars, Suite 1400, Los Angeles, California.
+Added: We also lease office space in New York, London and other cities around the world.
+Added: We do not own any real property.
+Added: We consider these facilities to be suitable and adequate for the management and operation of our businesses.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.