3 unchanged sentences
Cybersecurity
−Removed: The Trust, through the Sponsor, has established
−Removed: procedures to manage significant cybersecurity risks.
−Removed: The Trust’s operations depend on the systems of the Sponsor and other third-party
−Removed: The Sponsor manages the Trust’s day-to-day operations and has implemented a cybersecurity program that applies to the
−Removed: Trust and its operations.
+Added: The Trust, through the Sponsor,
+Added: has established procedures to manage significant cybersecurity risks.
+Added: The Trust’s operations depend on the systems of the Sponsor
+Added: and other third-party providers.
+Added: The Sponsor manages the Trust’s day-to-day operations and has implemented a cybersecurity program
+Added: that applies to the Trust and its operations.
Cybersecurity Program Overview
−Removed: The Sponsor has developed a cybersecurity program
−Removed: to manage cyber risks relevant to the Trust.
−Removed: This program includes risk assessments, security measures, and continuous monitoring of systems
−Removed: and networks.
+Added: The Sponsor has developed
+Added: a cybersecurity program to manage cyber risks relevant to the Trust.
+Added: This program includes risk assessments, security measures, and continuous
+Added: monitoring of systems and networks.
The Sponsor proactively identifies significant risks from new and evolving cybersecurity threats.
−Removed: The Trust relies on the Sponsor to engage external
−Removed: experts, such as cybersecurity assessors, consultants, and compliance professionals, to review the cybersecurity measures and risk management
−Removed: These third parties are engaged on an as-needed basis, with some hired on an ongoing basis as managed service providers.
−Removed: The Trust relies on the Sponsor’s risk management
−Removed: program, which includes cyber risk assessments.
−Removed: These processes have been integrated into the Sponsor’s overall risk management
−Removed: The Trust engages various third parties to support
−Removed: its operations.
−Removed: The Trust relies on the Sponsor’s expertise in risk management, legal, information technology, and compliance when managing
−Removed: risks from cybersecurity threats associated with these entities.
−Removed: Prior to engaging a key service provider, the Sponsor conducts a due
−Removed: diligence process.
−Removed: The Sponsor has adopted a cybersecurity strategy
−Removed: focused around a Zero Trust Network model throughout the entire operational environment, operating on the premise that no entity, system
−Removed: or service provider within the Sponsor’s IT security perimeter can be inherently trusted.
−Removed: The Sponsor actively monitors its cybersecurity
−Removed: risks and has appointed an internal Cybersecurity Lead and partners with an outside service provider responsible for system monitoring
−Removed: and alerting.
−Removed: In addition, the Sponsor enforces stringent security
−Removed: requirements for storage devices and applications, including encryption at rest, full user activity tracking, and secure sharing of client
−Removed: The Sponsor’s email environment is further fortified with dual factor authentication and other security measures.
−Removed: requires both two-factor and at rest encryption on all systems.
−Removed: The Sponsor requires through its compliance and cyber-security policy
−Removed: that all system breaches detected by an employee are immediately escalated to the Chief Compliance Officer and Head of Legal.
−Removed: The Sponsor also has several archival systems
−Removed: in place to monitor compliance.
−Removed: The Sponsor relies on a trusted firewall to manage and safeguard the Sponsor’s network.
−Removed: the Sponsor conducts regular reviews on third parties to ensure they have policies in place that are designed to prevent information security
−Removed: lapses or breaches.
+Added: The Trust relies on the Sponsor
+Added: to engage external experts, such as cybersecurity assessors, consultants, and compliance professionals, to review the cybersecurity measures
+Added: and risk management processes.
+Added: These third parties are engaged on an as-needed basis, with some hired on an ongoing basis as managed service
+Added: The Trust relies on the Sponsor’s
+Added: risk management program, which includes cyber risk assessments.
+Added: These processes have been integrated into the Sponsor’s overall
+Added: risk management system.
+Added: The Trust engages various
+Added: third parties to support its operations.
+Added: The Trust relies on the Sponsor’s expertise in risk management, legal, information technology,
+Added: and compliance when managing risks from cybersecurity threats associated with these entities.
+Added: Prior to engaging a key service provider,
+Added: the Sponsor conducts a due diligence process.
+Added: The Sponsor has adopted a
+Added: cybersecurity strategy focused around a Zero Trust Network model throughout the entire operational environment, operating on the premise
+Added: that no entity, system or service provider within the Sponsor’s IT security perimeter can be inherently trusted.
+Added: The Sponsor actively
+Added: monitors its cybersecurity risks and has appointed an internal Cybersecurity Lead and partners with an outside service provider responsible
+Added: for system monitoring and alerting.
+Added: In addition, the Sponsor enforces
+Added: stringent security requirements for storage devices and applications, including encryption at rest, full user activity tracking, and secure
+Added: sharing of client data.
+Added: The Sponsor’s email environment is further fortified with dual factor authentication and other security
+Added: The Sponsor requires both two-factor and at rest encryption on all systems.
+Added: The Sponsor requires through its compliance and
+Added: cybersecurity policy that all system breaches detected by an employee are immediately escalated to the Chief Compliance Officer and Head
+Added: The Sponsor also has several
+Added: archival systems in place to monitor compliance.
+Added: The Sponsor relies on a trusted firewall to manage and safeguard the Sponsor’s
+Added: Furthermore, the Sponsor conducts regular reviews on third parties to ensure they have policies in place that are designed to
+Added: prevent information security lapses or breaches.
Board Oversight of Cybersecurity Risks
−Removed: The Sponsor does not have a board of directors,
−Removed: but rather, the board of directors (the “Board”) of Amun Holdings Limited (“Parent Company”) provides strategic
−Removed: oversight on cybersecurity matters, including risks associated with cybersecurity threats.
−Removed: The Board relies upon the Parent Company’s
−Removed: Risk Committee for cybersecurity risk governance.
−Removed: The Parent Company’s Risk Committee receives periodic updates regarding the overall
−Removed: state of the Sponsor’s cybersecurity program, information on the current threat landscape, and risks from cybersecurity threats
−Removed: and cybersecurity incidents impacting the Trust.
+Added: The Sponsor does not have
+Added: a board of directors, but rather, the board of directors (the “Board”) of 21co Holdings Limited (formerly known as Amun Holdings
+Added: Limited) (“Parent Company”) provides strategic oversight on cybersecurity matters, including risks associated with cybersecurity
+Added: The Board relies upon the Parent Company’s Risk Committee for cybersecurity risk governance.
+Added: The Parent Company’s
+Added: Risk Committee receives periodic updates regarding the overall state of the Sponsor’s cybersecurity program, information on the
+Added: current threat landscape, and risks from cybersecurity threats and cybersecurity incidents impacting the Trust.
Management’s Role in Assessing &
Managing Material Risks from Cybersecurity Threats
−Removed: The Sponsor’s management, including the
−Removed: Sponsor’s CCO, is responsible for assessing and managing material risks from cybersecurity threats.
−Removed: The Sponsor’s CCO approves
−Removed: all changes to the cybersecurity policy.
−Removed: The Sponsor relies on its full-service compliance partner to stay updated on all SEC rules and
−Removed: regulations and to recommend changes in the compliance policies when necessary.
−Removed: Management of the Sponsor is informed about and monitors
−Removed: the prevention, detection, mitigation, and remediation of cybersecurity incidents impacting the Trust, including through the receipt of
−Removed: notifications from service providers and reliance on communications with risk management, legal, information technology, and/or compliance
−Removed: personnel of the Sponsor.
−Removed: The Head of Legal and CCO would receive notifications of a cybersecurity incident that impacts a service provider
−Removed: of the Trust.
−Removed: The Trust has an Incident Response Plan and Business
−Removed: Continuity/Disaster Recovery Plan, which it relies on the Sponsor’s plans.
−Removed: The CCO of the Sponsor is responsible for determining
−Removed: whether a cybersecurity incident is material to the Trust.
−Removed: Pursuant to the Sponsor’s policies and procedures, an internal team at
−Removed: the Sponsor is tasked with investigating all reported and suspected security breaches.
−Removed: The Sponsor is required to provide the required
−Removed: notifications without unreasonable delay after the discovery of a breach.
+Added: The Sponsor’s management,
+Added: including the Sponsor’s CCO, is responsible for assessing and managing material risks from cybersecurity threats.
+Added: The Sponsor’s
+Added: CCO approves all changes to the cybersecurity policy.
+Added: The Sponsor relies on its full-service compliance partner to stay updated on all
+Added: SEC rules and regulations and to recommend changes in the compliance policies when necessary.
+Added: Management of the Sponsor is informed about
+Added: and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents impacting the Trust, including through
+Added: the receipt of notifications from service providers and reliance on communications with risk management, legal, information technology,
+Added: and/or compliance personnel of the Sponsor.
+Added: The Head of Legal and CCO would receive notifications of a cybersecurity incident that impacts
+Added: a service provider of the Trust.
+Added: The Trust has an Incident
+Added: Response Plan and Business Continuity/Disaster Recovery Plan, which it relies on the Sponsor’s plans.
+Added: The CCO of the Sponsor is
+Added: responsible for determining whether a cybersecurity incident is material to the Trust.
+Added: Pursuant to the Sponsor’s policies and procedures,
+Added: an internal team at the Sponsor is tasked with investigating all reported and suspected security breaches.
+Added: The Sponsor is required to
+Added: provide the required notifications without unreasonable delay after the discovery of a breach.
Assessment of Cybersecurity Risk
−Removed: The potential impact of risks from cybersecurity
−Removed: threats on the Trust is assessed on an ongoing basis, and how such risks could materially affect the Trust’s business strategy,
−Removed: operational results, and financial condition are regularly evaluated.
−Removed: During the reporting period, the Trust has not identified any risks
−Removed: from cybersecurity threats, including as a result of previous cybersecurity incidents, that the Trust believes have materially affected,
−Removed: or are reasonably likely to materially affect, the Trust, including its business strategy, operational results, and financial condition.
+Added: The potential impact of risks
+Added: from cybersecurity threats on the Trust is assessed on an ongoing basis, and how such risks could materially affect the Trust’s
+Added: business strategy, operational results, and financial condition are regularly evaluated.
+Added: During the reporting period, the Trust has not
+Added: identified any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that the Trust believes have
+Added: materially affected, or are reasonably likely to materially affect, the Trust, including its business strategy, operational results, and
+Added: financial condition.
Legal Proceedings
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.