−Removed: UNRESOLVED STAFF COMMENTS
+Added: 1B UNRESOLVED STAFF COMMENTS
As a Smaller Reporting Company
1 unchanged sentence
and therefore are not required to provide the information requested by this Item 1B.
−Removed: CYBERSECURITY
+Added: 1C CYBERSECURITY
Cybersecurity Risk Management and Strategy
6 unchanged sentences
● the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls, including, third-party network security reviews, scans, and audits, on at least an annual basis;
−Removed: regular cybersecurity awareness training for employees
−Removed: with access to our information systems, incident response personnel, and senior management;
−Removed: a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
−Removed: a disaster recovery plan and controls designed to protect against business interruption, including by backing up our critical systems;
−Removed: use of end-to-end encryption and tokenization technology, a public key infrastructure, designed to ensure that only trusted devices can access our enterprise information technology network, and Intrusion Prevention System (IPS) that scans data in transit to help prevent the execution of harmful code;
−Removed: a third-party risk management process for service
−Removed: providers, suppliers, and vendors who have access to our information systems.
−Removed: There can be no assurance that
−Removed: our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied
−Removed: with or are effective in protecting our systems and information.
−Removed: We are not currently aware of risks from known cybersecurity threats,
−Removed: including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect
−Removed: us, including our operations, business strategy, results of operations, or financial condition.
+Added: cybersecurity awareness training for employees with access to our information systems, incident
+Added: response personnel, and senior management;
+Added: cybersecurity incident response plan that includes procedures for responding to cybersecurity
+Added: disaster recovery plan and controls designed to protect against business interruption, including
+Added: by backing up our critical systems;
+Added: of end-to-end encryption and tokenization technology, a public key infrastructure, designed
+Added: to ensure that only trusted devices can access our enterprise information technology network,
+Added: and Intrusion Prevention System (IPS) that scans data in transit to help prevent the execution
+Added: of harmful code;
+Added: third-party risk management process for service providers, suppliers, and vendors who have
+Added: access to our information systems.
+Added: There can be no assurance
+Added: that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented,
+Added: complied with or are effective in protecting our systems and information.
+Added: We are not currently aware of risks from known cybersecurity
+Added: threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially
+Added: affect us, including our operations, business strategy, results of operations, or financial condition.
Cybersecurity Governance
−Removed: Our Board of Directors has oversight
−Removed: responsibility for the Company’s cybersecurity risk management, including technology and cybersecurity risks facing the Company.
−Removed: Management updates the Board, as necessary, regarding cybersecurity risk management matters, including reporting any material cybersecurity
+Added: Our Board of Directors has
+Added: oversight responsibility for the Company’s cybersecurity risk management, including technology and cybersecurity risks facing the
+Added: Management updates the Board, as necessary, regarding cybersecurity risk management matters, including reporting any material
+Added: cybersecurity incidents.
Our management team, including
−Removed: the CEO, CFO, COO, Director of Information Technology, and Director of Accounting, as appropriate, supervises efforts to prevent, detect,
−Removed: mitigate and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel;
−Removed: threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged
−Removed: and alerts and reports produced by security tools deployed in the information technology environment.
+Added: the CEO, CFO, COO, Senior Director of Information Technology, Director of Information Technology, and Director of Accounting, as appropriate,
+Added: supervises efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include
+Added: briefings from internal security personnel;
+Added: threat intelligence and other information obtained from governmental, public or private sources,
+Added: including external consultants engaged by us;
+Added: and alerts and reports produced by security tools deployed in the information technology
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.