5 unchanged sentences
Our cybersecurity risk assessment program includes a number of components, including information security program assessments, audits and maturity assessments, that are conducted periodically by both internal and external resources.
−Removed: Our internal audit function also conducts regular assessments of different systems to provide the audit committee with information on our cybersecurity risk management processes.
+Added: Additionally, we partner with multiple third-party managed security service providers for enhanced monitoring of our
+Added: information technology and data security environment and to perform proactive detection and investigation of malicious activity within our network.
+Added: Our internal audit function also conducts regular assessments of different systems to provide the audit committee with information on our cybersecurity risk management processes, which processes are integrated into our overall enterprise risk management program.
As part of our cybersecurity risk management program, we take a risk-based approach to the evaluation of third-party vendors, and apply mitigations and processes based on our evaluation of the sensitivity of the data accessed by the vendor and the maturity of the vendor’s programs.
Our vendor evaluation procedures include, as appropriate, the completion of a vendor security questionnaire and our implementation of vendor monitoring programs.
−Removed: We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business
−Removed: strategy, results of operations, or financial condition.
+Added: We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
However, like other companies in our industry, we and our third-party vendors have from time-to-time experienced threats and security incidents that could affect our information or systems.
+Added: See “Item 1A.
+Added: Risk Factors” for additional information on the Company’s cybersecurity-related risks.
Governance Related to Cybersecurity Risks
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.