3 unchanged sentences
At Backblaze, we recognize the importance of developing, implementing and maintaining a cybersecurity risk management program.
−Removed: Our customers rely on our solutions to store, use and protect their files, which may include confidential or personally identifiable information, critical business information, photographs, and other meaningful content.
+Added: Our customers rely on our solutions to store, use and protect their files, which may include confidential or personally identifiable information, critical business information, and other meaningful content.
A successful cybersecurity attack could adversely affect the confidentiality, integrity, and availability of our information systems or any data residing therein.
We dedicate significant effort and resources to protect our systems and data, as well as the data of our customers from cybersecurity threats.
−Removed: We are dependent on internal and external information technology systems and
−Removed: infrastructure to securely process, transmit, and store critical information.
+Added: We are dependent on internal and external information technology systems and infrastructure to securely process, transmit, and store critical information.
Our Audit Committee is responsible for overseeing our cybersecurity, which represents an important component of the company’s enterprise risk management (“ERM”).
14 unchanged sentences
We have implemented processes designed to identify and assess cybersecurity risks associated with our use of third-party service providers.
−Removed: We generally conduct a security risk assessment based on the potential for harm prior to onboarding of any such new services and include security and privacy addenda to our contracts where applicable.
+Added: conduct a security risk assessment based on the potential for harm prior to onboarding of any such new services and include security and privacy addenda to our contracts where applicable.
• Education and Awareness:
5 unchanged sentences
The state of the cybersecurity program is also reported by the CISO to the Audit Committee.
−Removed: Our Board of Directors, in coordination with its committees, with input from the Risk Management Committee, oversees our enterprise risk management process, including the risks arising from cybersecurity threats.
+Added: Our Board of Directors, in coordination with its committees, with input from the Risk Management Committee, a cross-functional committee comprised of our executives and other leaders of various departments, oversees our enterprise risk management process, including the risks arising from cybersecurity threats.
Our incident response policies and procedures provide for prompt notice to key members of our management team and other company personnel of any incidents that could negatively impact the company’s systems or data.
5 unchanged sentences
He previously served as the Chief Information Security Officer at multiple federal healthcare contractor organizations, and also served as the Director of IT Security at a publicly traded international satellite radio company.
−Removed: He is an IAPP Fellow of Information Privacy and holds over 35 security, privacy, and risk management certifications.
+Added: He is an IAPP Fellow of Information Privacy, holds a GIAC Law of Data Security and Investigations certification, and also holds approximately 40 security, privacy, and risk management certifications.
Cybersecurity Risks
3 unchanged sentences
Although we did not identify any unauthorized access to our systems due to the Log4j vulnerability, out of an abundance of caution and because Log4j was leveraged widely in our environment, we decided it was in our customers’ best interest to take our systems offline for a short period of time until we could apply the security updates.
+Added: As is common in the industry, we also experience periodic phishing and distributed denial-of-service (DDoS) attacks.
To date and except as otherwise may be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect the company, including its business strategy, results of operations or financial condition.
−Removed: For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “If our information technology systems, including the data of our customers stored in our systems, are breached or subject to cybersecurity attached, our reputation and business may be harmed” in Part I, Item 1A, and other risk factors in this 10-K.
+Added: For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “If our information technology systems, including the data of our customers stored in our systems, are breached or subject
+Added: to cybersecurity attached, our reputation and business may be harmed” in Part I, Item 1A, and other risk factors in this 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.