1 unchanged sentence
Cybersecurity
+Added: Risk Management and
We recognize the importance of securing our data
1 unchanged sentence
is supported by both management and our Board of Directors.
−Removed: The Chief Technology Officer (“CTO”),
−Removed: who reports to the CEO, leads our cybersecurity function and is responsible for managing our cybersecurity risk and the protection of our networks, systems, and data.
−Removed: The CTO uses both internal and external resources to execute this process including security tools that
−Removed: help prevent, identify, escalate, investigate and resolve security incidents in a timely manner and tools that help prevent unauthorized
−Removed: The majority of the Company’s employees have a background in technology and engineering and are intensely aware of cyber
−Removed: Additionally, the Company has less than 20 employees and contractors, therefore, the small size helps with rapid communication
−Removed: and response on any potential threats.
+Added: The Company’s cybersecurity function is
+Added: led by a contracted Chief Technology Officer (“Contract CTO”), who provides strategic oversight and reports directly to the
+Added: Chief Executive Officer.
+Added: The Contract CTO is responsible for managing the Company’s cybersecurity risk and overseeing the protection
+Added: of our networks, systems, and data.
+Added: To execute these responsibilities, the Company utilizes a combination of internal personnel and multiple
+Added: external technology partners , including two independent IT service firms that support system administration, infrastructure management,
+Added: and security monitoring.
+Added: These resources employ industry-standard tools and processes designed to prevent, identify, escalate, investigate,
+Added: and resolve security incidents in a timely manner.
+Added: Additionally, with fewer than 20 employees and contractors, the Company’s small
+Added: size facilitates rapid communication and coordinated response to potential cybersecurity risks.
The Company’s aggressive prevention and
response protocols consist of the following:
−Removed: · Password management – employees are encouraged to maintain strong passwords and are educated on
−Removed: the risks around passwords;
−Removed: · Network administration – the Company maintains a single, small-scale network which is configured
−Removed: to prevent external penetrations and is secured with limited administrative access and strong passwords;
+Added: Password management – employees are encouraged to maintain strong passwords and are educated on the risks around passwords;
+Added: Network administration – the Company maintains a single, small-scale network which is configured to prevent external penetrations and is secured with limited administrative access and strong passwords;
Firewall – configured to prevent unauthorized external access;
Virtual Private Networks – closely and carefully managed following industry best practices;
−Removed: · Training and communication – the Company monitors various types of threats, routinely educates employees
−Removed: on high risk threats, and communicates any potential identified threats to all employees and related third parties.
+Added: Training and communication – the Company monitors various types of threats, routinely educates employees on high risk threats, and communicates any potential identified threats to all employees and related third parties.
Our Board of Directors is responsible for overseeing
our enterprise risk management activities.
−Removed: The Board of Directors receives an update on the Company’s risk management process and the risk trends related to cybersecurity at least annually.
+Added: The Board of Directors receives an update on the Company’s risk management process and
+Added: the risk trends related to cybersecurity at least annually.
Additionally, on a quarterly basis, the Audit Committee will receive updates
2 unchanged sentences
upon identification.
−Removed: While the Company has not, as of the date of this Form 10-K, identified
−Removed: a cybersecurity threat or incident that resulted in a material adverse impact to its business, results of operations or financial condition,
−Removed: there can be no guarantee that the Company will not experience such an incident in the future.
+Added: While the Company has not, as of the date of this
+Added: Form 10-K, identified a cybersecurity threat or incident that resulted in a material adverse impact to its business, results of operations
+Added: or financial condition, there can be no guarantee that the Company will not experience such an incident in the future.
We own no properties.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.