UNRESOLVED STAFF COMMENTS
−Removed: CYBERSECURITY RISK MANAGEMENT STRAGEY
+Added: CYBERSECURITY
+Added: Risk Management Strategy
We have developed and implemented cybersecurity risk management processes intended to protect the confidentiality, integrity and availability of our critical systems and information.
8 unchanged sentences
● annual cybersecurity and privacy training of employees, including incident response personnel and senior management, and specialized training for certain teams depending on their role and/or access to certain types of information, such as consumer information;
−Removed: a third-party risk management process that includes internal vetting of certain third-party vendors and service providers with whom we may share data.
−Removed: Over the past fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: ● a third -party risk management process that includes internal vetting of certain third -party vendors and service providers with whom we may share data and processes designed to oversee, identify, and reduce the potential impact of a cybersecurity incident at a third -party vendor or service provider or otherwise implicating the third -party technology and systems used.
+Added: We have not identified risks from known cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
We will continue to monitor and assess our cybersecurity risk management program as well as invest in and seek to improve such systems and processes as appropriate.
10 unchanged sentences
Our management team, including our Chief Information Officer, is responsible for assessing and managing our material risks from cybersecurity threats and for our overall cybersecurity risk management program on a day-to-day basis, and supervises both our internal cybersecurity personnel and the relationship with our retained external cybersecurity consultants.
−Removed: Our Chief Information Officer’s experience includes years of working in the cybersecurity field in various industries, including the financial services industry.
+Added: Our Chief Information Officer’s experience includes over 10 years of working in the cybersecurity field in various industries, including the financial services industry.
Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, including briefings from internal security personnel;
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.