Unresolved Staff Comments
−Removed: Tab le o f co ntents
Cybersecurity
Risk management and strategy
−Removed: Our information security function is led by our Executive Director of Global IT Operations ( “ Head of IT ” ), whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
+Added: Our information security function is led by our Chief Information Officer, whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
The information security function identifies and assesses risks from cybersecurity threats by monitoring and evaluating our threat environment and our risk profile using various methods including, for example, manual tools and automated tools, conducting scans of the threat environment, evaluating our and our industry’s risk profile, evaluating threats reported to us, internal and external audits, leveraging third party threat assessments, and conducting vulnerabilities assessments.
In addition, our employees and contractors receive periodic training under our IT security policies, including simulated intrusion attempts, and are required to certify compliance with our cybersecurity practices.
+Added: In February 2025, we obtained ISO 27001 certification for our information security management systems.
Depending on the environment or system, we implement and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including, for example:
9 unchanged sentences
For a description of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Part 1.
−Removed: Risk Factors in this Annual Report, including “If our information technology systems or data, or those of third parties upon which we rely, are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
+Added: Risk Factors in this Annual Report, including “If our information technology systems or data, or those of third parties with whom we work, are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
fines and penalties;
6 unchanged sentences
Management regularly updates the board of directors on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies and provides regular cybersecurity updates.
−Removed: Our board of directors has overall oversight responsibility for our risk management and is charged with oversight of our cybersecurity risk management program.
−Removed: The board is responsible for ensuring that management has policies and processes in place designed to identify, monitor, assess and respond to cybersecurity, data privacy and other information technology risks to which the Company is exposed and implement processes and programs to manage cybersecurity risks and mitigate cybersecurity threats and incidents.
−Removed: Tab le o f co ntents
+Added: Our board of directors has overall oversight responsibility for our risk management and has charged our Audit Committee with oversight of our cybersecurity risk management program.
+Added: The board and Audit Committee are responsible for ensuring that management has policies and processes in place designed to identify, monitor, assess and respond to cybersecurity, data privacy and other information technology risks to which the Company is exposed and implement processes and programs to manage cybersecurity risks and mitigate cybersecurity threats and incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.