4 unchanged sentences
To more effectively address cybersecurity threats, we have numerous security layers within our least privilege network approach which is managed by our Information Technology ("IT") department.
−Removed: Our cybersecurity programs align with numerous standards and continues to grow and develop as new technologies emerge.
−Removed: Further, we have regular user awareness testing and trainings in place which helps keep all end users and executive leadership up-to-date on the most current threats.
+Added: Our cybersecurity programs align with numerous standards and continue to grow and develop as new technologies emerge.
+Added: Further, we have regular user awareness testing and trainings in place which help keep all end users and executive leadership up-to-date on the most current threats.
The global head of our IT department has responsibility over cybersecurity management globally and reports directly to the Chief Financial Officer.
He has degrees in both management information systems and cybersecurity - and has held a number of progressing roles, including management of global infrastructure, information security and technology operations at Balchem, in addition to managing a global team of information technology and cybersecurity experts.
−Removed: The IT department provides regular updates to senior management.
−Removed: Additionally, he provides at least an annual update, or more frequently if necessary, to both the Audit Committee and the full Board regarding the current threat landscape at Balchem, cybersecurity technologies, mitigation strategies, industry trends and best practices that we follow, major cybersecurity incidents (if any), and other areas of importance.
+Added: The IT department provides regular updates to senior management and provides at least an annual update, or more frequently if necessary, to both the Audit Committee and the full Board regarding the current threat landscape at Balchem, cybersecurity technologies, mitigation strategies, industry trends and best practices that we follow, major cybersecurity incidents (if any), and other areas of importance.
Additional activities to maintain and enhance information security are discussed below.
2 unchanged sentences
National Institute of Standards and Technology ("NIST") framework for information security, which is a set of guidelines, accepted standards, and best practices for mitigating organization cybersecurity risks published by NIST.
−Removed: We continue to make significant investments in industry-leading and advanced technologies as part of our strategy to strengthen our security
−Removed: posture, business continuity capabilities, and ability to protect and safeguard systems and stakeholder data.
−Removed: Our Information Security Program and systems are tested and assessed annually by an independent third party.
+Added: We continue to make significant investments in industry-leading and advanced technologies as part of our strategy to strengthen our security posture, business continuity capabilities, and ability to protect and safeguard systems and stakeholder data.
+Added: Our Information Security Program includes at least annual penetration testing of our systems by an independent third party.
• Automation and Artificial Intelligence
−Removed: We have implemented automated systems to proactively test attack vectors by emulating inside and outside threats resulting in the validation of our ability to detect and defend against a cyber attack.
+Added: We employ controlled security testing activities to evaluate attack vectors and validate our ability to detect and respond to cyber threats.
Artificial intelligence is used as part of early warning systems designed to detect, alert, and respond to potential cyber threats.
Recognizing that information security, stakeholder data, and privacy principles involve more than just systems and infrastructure, we provide semi-annual cybersecurity education and training to all users with access to IT systems, devices, or applications.
−Removed: Internal social engineering phishing campaigns are conducted regularly with the goal of building a culture of cybersecurity, as well as raising awareness and reinforcing best practices across the organization.
+Added: Internal social engineering phishing campaigns are conducted frequently with the goal of building a culture of cybersecurity, as well as raising awareness and reinforcing best practices across the organization.
Third parties also play a role in our cybersecurity.
2 unchanged sentences
We apply a risk-based approach to mitigate cybersecurity risks associated with our use of third-party service providers and cybersecurity considerations affect the selection and oversight of these third-party service providers.
−Removed: We perform due diligence on third parties that have access to our most critical systems, data or facilities that house such systems or data.
+Added: We perform risk-based due diligence on third parties with access to our systems, data or facilities, commensurate with the level of access and risk.
While we have experienced cybersecurity threats in the past in the normal course of business and expect to continue to experience such threats from time to time, to date, none have had a material adverse effect on our business, financial condition, results of operations or cash flows.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.