8 unchanged sentences
Our Audit Committee is responsible for overseeing our cybersecurity, which represents an important component of the company’s enterprise risk management (“ERM”).
−Removed: We seek to reduce cybersecurity risks through a variety of cybersecurity risk management activities that are designed to identify, assess, manage and mitigate cybersecurity threats.
+Added: We seek to reduce cybersecurity risks through a variety of control activities that are designed to identify, assess, manage and mitigate these risks.
Risk Management Strategy
2 unchanged sentences
As more fully described in the section titled “Governance” below, the cybersecurity risk management program is led by our Chief Information Security Officer (“CISO”), with oversight from the Audit Committee of our Board of Directors and input from the Risk Management Advisory Committee (the “Risk Management Committee”).
−Removed: Our Risk Management Committee consists of our Chief Executive Officer, Chief Financial Officer, General Counsel and Chief Compliance Officer, CISO, other members of management, and other employees from selected key functions of the company.
−Removed: We use a cross-functional approach to identifying, preventing, assessing, and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that are designed to provide for the prompt escalation of cybersecurity incidents and support appropriate public disclosure and reporting of incidents as required in a timely manner.
−Removed: Our cybersecurity efforts include the use of risk-based administrative, technical, and physical controls.
−Removed: Backblaze has implemented an extensive set of policies, procedures, systems and tools designed to help safeguard our systems and data, including firewalls, endpoint protection, detection and response solutions, intrusion detection systems, access controls including multi-factor authentication, vulnerability scanning, software static analysis, dynamic analysis and software composition analysis tools, third party independent penetration testing, independent third-party control audits, a public bug bounty program, and other systems and processes.
+Added: Our Risk Management Advisory Committee is a cross-functional committee comprised of our executives and other leaders of various departments that consists of our Chief Executive Officer, Chief Financial Officer, Head of Legal and Compliance, CISO, other members of management, and other employees from selected key functions of the company.
+Added: We use a cross-functional approach to identify, assess, treat, and monitor cybersecurity risks, while also implementing controls and procedures that are designed to provide for the prompt escalation of cybersecurity incidents and support appropriate public disclosure and reporting of incidents as required in a timely manner.
+Added: Our cybersecurity program includes the selection, implementation, testing, and monitoring of a layered set of administrative (including policies and procedures), technical, and physical controls, including access controls, endpoint protection, vulnerability management, independent testing, and monitoring capabilities, designed to reduce the likelihood and impact of cybersecurity threats.
• Incident Response Planning:
4 unchanged sentences
We have implemented processes designed to identify and assess cybersecurity risks associated with our use of third-party service providers.
−Removed: conduct a security risk assessment based on the potential for harm prior to onboarding of any such new services and include security and privacy addenda to our contracts where applicable.
+Added: We generally conduct a security risk assessment based on the potential risk to the company and its customers prior to onboarding of any such new services and include security and privacy addenda to our contracts where applicable.
• Education and Awareness:
1 unchanged sentence
We regularly review and update our policies, procedures, processes and practices to address changes in the threat landscape and as a result of lessons learned from suspected, actual or simulated incidents.
−Removed: We also conduct tabletop exercises, and engage third party services to conduct evaluations of our security controls through penetration testing and independent audits.
+Added: We conduct tabletop exercises, and engage third-party services to conduct evaluations of our security controls through penetration testing and independent audits.
We also review industry best practices to assist in evaluating responses to new challenges and risks.
−Removed: These evaluations include testing both the design and operational effectiveness of security controls.
−Removed: The state of the cybersecurity program is also reported by the CISO to the Audit Committee.
−Removed: Our Board of Directors, in coordination with its committees, with input from the Risk Management Committee, a cross-functional committee comprised of our executives and other leaders of various departments, oversees our enterprise risk management process, including the risks arising from cybersecurity threats.
−Removed: Our incident response policies and procedures provide for prompt notice to key members of our management team and other company personnel of any incidents that could negatively impact the company’s systems or data.
−Removed: Our cybersecurity risk management program is managed by our CISO , whose security team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
−Removed: Our CISO also regularly provides updates to the Audit Committee on our cybersecurity program, including recent developments, key initiatives to strengthen our systems, applicable industry standards, vulnerability assessments, third-party and independent reviews, and other information security considerations.
−Removed: The Audit Committee also receives information regarding cybersecurity incidents, including prompt updates for any cybersecurity incidents that may be deemed material events impacting us and which might require public disclosure.
+Added: These evaluations include testing the design and operational effectiveness of security controls.
+Added: The state of the cybersecurity program is reported by the CISO to the Audit Committee.
+Added: Our Board of Directors, with input from the Risk Management Committee, oversees our enterprise risk management process, including the risks associated with AI and cybersecurity threats.
+Added: Our cybersecurity risk management program is managed by our CISO , whose security team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, controls, and processes.
+Added: Cybersecurity risks are evaluated alongside other enterprise risks and inform prioritization of mitigation activities and resource allocation.
+Added: Our CISO also provides updates to the Audit Committee on our cybersecurity program, including recent developments, key initiatives to strengthen our systems, applicable industry standards, vulnerability assessments, third-party vendor risk, and independent security framework alignment and compliance maturity, AI, and other information security considerations.
+Added: The Audit Committee also receives information regarding cybersecurity incidents, including prompt updates for any cybersecurity incidents that may be deemed material and which might require public disclosure.
+Added: Management is responsible for the day-to-day operation of the cybersecurity program, while the Audit Committee provides oversight.
Our CISO and other key personnel also frequently engage with key vendors, industry groups, and law enforcement communities as part of our continuing efforts to improve our cybersecurity program.
−Removed: Our CISO has 30 years of experience working in cybersecurity, IT, governance, risk management, regulatory compliance, and data protection and privacy program design and implementation.
−Removed: He previously served as the Chief Information Security Officer at multiple federal healthcare contractor organizations, and also served as the Director of IT Security at a publicly traded international satellite radio company.
−Removed: He is an IAPP Fellow of Information Privacy, holds a GIAC Law of Data Security and Investigations certification, and also holds approximately 40 security, privacy, and risk management certifications.
+Added: Our CISO has more than 30 years of experience in cybersecurity, IT, governance, risk management, regulatory compliance, and data protection and privacy program design and implementation.
+Added: He has served in CISO roles for over 15 years, including leadership positions at a publicly traded cloud services company and organizations supporting highly regulated federal healthcare programs, and previously served as Director of IT Security at a publicly traded international satellite radio company.
+Added: He is an IAPP Fellow of Information Privacy and holds recognized security, privacy, audit, and risk management certifications relevant to data protection and regulatory compliance.
Cybersecurity Risks
1 unchanged sentence
Any breach of our network security and information systems or other cybersecurity-related incidents that results in, or may result in, the loss, theft or unauthorized disclosure of data, or any delay in determining the full extent of a potential breach, could have a material adverse impact on our business, results of operations, and financial condition, including harm to our reputation and brand, reduced demand for our solutions, time-consuming and expensive litigation, fines, penalties, and other damages.
−Removed: For example, as we previously disclosed, in December 2021, an industry-wide zero-day vulnerability was discovered in the Apache Log4j logging library commonly used by many companies throughout the world that could enable attackers to take control of vulnerable servers.
−Removed: Although we did not identify any unauthorized access to our systems due to the Log4j vulnerability, out of an abundance of caution and because Log4j was leveraged widely in our environment, we decided it was in our customers’ best interest to take our systems offline for a short period of time until we could apply the security updates.
−Removed: As is common in the industry, we also experience periodic phishing and distributed denial-of-service (DDoS) attacks.
+Added: As is common in industry, we experience periodic phishing and DDoS attacks.
To date and except as otherwise may be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect the company, including its business strategy, results of operations or financial condition.
−Removed: For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “If our information technology systems, including the data of our customers stored in our systems, are breached or subject
−Removed: to cybersecurity attached, our reputation and business may be harmed” in Part I, Item 1A, and other risk factors in this 10-K.
+Added: For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “If our information technology systems, including the data of our customers stored in our systems, are breached or subject to cybersecurity attacks, our reputation and business may be harmed” in Part I, Item 1A, and other risk factors in this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.