5 unchanged sentences
We have established policies and procedures to ensure timely and appropriate notifications to relevant parties and regulators as required for cybersecurity threats and data breaches.
−Removed: We have continued to expand investments in information security, including additional end-user training, using layered defenses, identifying and protecting critical assets, strengthening monitoring and alerting mechanisms, and engaging experts.
+Added: We have continued to expand investments in information security and resiliency, including additional end-user training, using layered defenses, identifying and protecting critical assets, enhanced monitoring and alerting, recovery capabilities and engaging experts.
Information security awareness trainings are a compliance requirement for employees.
2 unchanged sentences
The incident response team is responsible for determining whether a cybersecurity incident is material and requires current reporting pursuant to SEC Form 8-K Item 1.05 (Material Cybersecurity Incidents).
−Removed: In conducting the assessment, the team considers
−Removed: factors including, but not limited to:
+Added: In conducting the assessment, the team considers factors including, but not limited to:
the probability of an adverse outcome;
the potential significance of loss;
−Removed: the nature and extent of harm to individuals, customers, and vendors;
+Added: the nature and
+Added: extent of harm to individuals, customers, and vendors;
the nature and extent of harm to our competitive position or reputation;
3 unchanged sentences
We evaluate our physical, electronic and administrative safeguards on a continuous basis to ensure they are effectively deployed across the business.
−Removed: We also work with trusted and recognized third parties to help us assess, strengthen and monitor the operations of our information security program.
−Removed: We engage third-party services to conduct evaluations of our security controls, whether through penetration testing, independent audits or consulting on best practices to address new challenges.
−Removed: These evaluations include testing both the design and operational effectiveness of security controls.
−Removed: We also share and receive threat intelligence with information sharing and analysis centers and cybersecurity associations.
+Added: We collaborate with reputable third parties to assess, enhance and monitor our information security program.
+Added: Independent audits and advisory services conducted by experienced providers evaluate our security controls in alignment with evolving industry best practices.
+Added: These evaluations encompass both testing the design and operational effectiveness of security controls.
+Added: We maintain ongoing vulnerability and exposure assessments and actively participate in information sharing and analysis centers and cybersecurity associations.
Assessing, identifying and managing cybersecurity related risks are integrated into our overall enterprise risk management (ERM) process, which evaluates and assesses top risks to the enterprise on a periodic basis.
18 unchanged sentences
The Audit Committee assists in determining materiality for timely reporting of cybersecurity incidents and is notified immediately if the incident response team has assessed that a material event may have occurred that may require filing an SEC Current Report on Form 8-K.
−Removed: The Vice President of Information Technology, assisted by our broader IT team, is responsible for setting the strategic direction and priorities for information security, coordination of enterprise-wide compliance with information security policies and procedures, as well as day-to-day information security management.
+Added: The Vice President of Information Technology and Director of Information Security, assisted by our broader IT team, are responsible for setting the strategic direction and priorities for information security, coordination of enterprise-wide compliance with information security policies and procedures, as well as day-to-day information security management.
Our Vice President of IT has served in various roles in information technology and information security for over 20 years.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.