25 unchanged sentences
We have an internal cybersecurity incident response plan designed to minimize the impact of cyber incidents and ensure consistent responses to any such incident.
−Removed: This plan undergoes regular reviews and updates.
+Added: This plan undergoes regular review and update by outside counsel.
The Company builds information security awareness among our employees by conducting regular training on our cybersecurity and data protection policies and executing vulnerability testing with employee simulated email threats.
4 unchanged sentences
We also have a vulnerability management program in place that is designed to protect our external and internal networks and critical assets.
−Removed: In addition, we have designed policies and procedures so that our Disclosure Committee, which is composed of members of management and is co-chaired by the Company’s CFO and General Counsel, is appropriately informed of significant cybersecurity matters to ensure compliance with applicable cybersecurity disclosure requirements for our public filings.
−Removed: The Disclosure Committee meets on a quarterly basis and more often as necessary.
+Added: In addition, we have designed policies and procedures so that our Disclosure Committee, which is composed of members of management and is co-chaired by the Company’s CFO and Chief Legal Officer, is appropriately informed of significant cybersecurity matters to ensure compliance with applicable cybersecurity disclosure requirements for our public filings.
+Added: The Disclosure Committee meets on a quarterly basis and more often as needed.
We maintain cybersecurity insurance and regularly consult with third-party cybersecurity experts during our review of existing cybersecurity controls.
6 unchanged sentences
Cybersecurity Governance
−Removed: Board’s Oversight of Risks from Cybersecurity Threats
−Removed: The Board oversees our ERM program, including the review of cybersecurity and IT risks.
−Removed: The Board is also regularly briefed by the Global CIO, with the support of the Global CISO, on our cybersecurity risk management framework and completed, ongoing and planned actions relating managing to cybersecurity risks.
−Removed: These reports also include updates on the status of projects to strengthen our information security systems, recent assessments of the information security program and the emerging threat landscape.
+Added: Audit and Ethic Committee's Oversight of Risks from Cybersecurity Threats
+Added: The Board oversees our ERM program, and has delegated responsibility for cybersecurity and IT risk oversight to the Audit and Ethics Committee.
+Added: The Committee receives regular briefings from the Global CIO, with support from the Global CISO, regarding our cybersecurity risk management framework and the actions taken, underway or planned to mitigate cybersecurity risks.
+Added: These updates include assessments of our information security program, initiatives to enhance system resilience, and developments in the evolving cybersecurity threat landscape.
Management’s Role in Assessing and Managing our Material Risks from Cybersecurity Threats
2 unchanged sentences
Sethi sets our strategic vision and roadmap to define, build and optimize our IT systems, policies and operations.
−Removed: Sethi regularly reports to the Board regarding cybersecurity risks.
James Holley, the Global CISO, oversees our information, cyber, and technology security and reports to the Company’s Global CIO.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.