1 unchanged sentence
Cybersecurity
−Removed: Given the critical importance of cybersecurity, including data privacy, we believe we have developed a comprehensive cybersecurity program, supported by robust risk management and oversight procedures.
−Removed: We are committed to implementing leading data protection standards and have a comprehensive set of written policies and standards that take into account the guidance of industry-standard cybersecurity frameworks.
+Added: Given the critical importance of cybersecurity, including data privacy, we have developed a cybersecurity program, supported by risk management and oversight procedures.
+Added: The cybersecurity program includes written policies and standards that take into account the guidance of well-recognized industry cybersecurity frameworks.
Management and Board Oversight
−Removed: We have dedicated cybersecurity resources led by our Chief Information Officer ("CIO"), who regularly provides reports to our executive officers, including the CEO and CFO.
−Removed: Our CIO has over 20 years of experience in the cybersecurity and IT fields and holds multiple degrees, including a Bachelor of Science in Information Science and a Master of Business Administration.
+Added: We have dedicated cybersecurity resources led by our Chief Information Officer ("CIO") , who regularly provides reports on cybersecurity to our executive officers, including the CEO and CFO.
+Added: Our CIO has significant experience in the cybersecurity and IT fields and holds multiple degrees, including a Bachelor of Science in Information Science and a Master of Business Administration.
Additionally, our CIO is a Certified Information Security Manager.
We have developed a cybersecurity incident response plan ("CSIRP") for cybersecurity incidents that may jeopardize the confidentiality, integrity, or availability of our IT systems.
−Removed: Our CSIRP guides the internal response to cybersecurity incidents, following a process that generally aligns with the industry-standard cybersecurity frameworks.
+Added: Our CSIRP guides the internal response to cybersecurity incidents, following a process consistent with well-recognized industry cybersecurity frameworks.
Pursuant to the CSIRP and its escalation protocols, we engage the incident response team ("IRT"), which includes designated personnel responsible for:
6 unchanged sentences
and (7) performing post-incident analysis and improvements.
−Removed: The IRT is led by an incident response coordinator, which in the event of a cybersecurity incident would generally be the CIO, and includes members of our IT resources, risk management, legal, communications, finance, and accounting teams, in addition to any other necessary personnel depending on the particular facts and circumstances of the incident.
−Removed: When a cybersecurity incident is detected, the incident response coordinator notifies relevant members of management, as appropriate and consistent with the escalation protocols of the CSIRP, such as the CEO, CFO, and General Counsel, and provides an assessment of the incident and containment strategy, if applicable.
−Removed: We consider cybersecurity as part of our broader consideration of business strategy and risk management.
−Removed: Our board of directors has delegated to the Audit Committee the responsibility of overseeing our risk management program, including risk assessment, risk management, and risk mitigation policies and programs.
−Removed: A key part of this responsibility is overseeing the cybersecurity program.
−Removed: The Audit Committee receives quarterly updates from our CIO with respect to the cybersecurity program, including current threat levels and ongoing program enhancements.
−Removed: The Audit Committee oversees our compliance with the industry-standard cybersecurity frameworks, our cybersecurity insurance coverage, cybersecurity-related internal controls, penetration testing, the CSIRP, business continuity plans, and threat assessments.
−Removed: The Audit Committee also periodically evaluates our cyber strategy to ensure its effectiveness, including benchmarking against our peers.
+Added: The IRT is led by an incident response coordinator, which in the event of a cybersecurity incident would generally be the CIO, and includes members of our IT resources, risk management, legal, communications, finance, and accounting teams, in addition to any other personnel depending on the particular facts and circumstances of the incident.
+Added: We consider cybersecurity as part of our broader consideration of business strategy and enterprise risk management.
+Added: Our board of directors has delegated to the Audit Committee the responsibility of overseeing our risk management program, including for the cybersecurity program.
+Added: The Audit Committee receives quarterly updates from our CIO with respect to the cybersecurity program.
+Added: As part of its oversight, the Audit Committee may, for example, receive updates regarding assessments of our alignment with certain industry cybersecurity frameworks, our cybersecurity insurance coverage, cybersecurity-related internal controls, results of penetration testing, revisions to the CSIRP, business continuity plans, and threat assessments.
Processes for Assessing, Identifying, and Managing Material Risks from Cybersecurity Threats
5 unchanged sentences
Preparation and Prevention
−Removed: We utilize a variety of tools, processes, software, and hardware that are managed and monitored by our IT resources and third-party vendors, as applicable, to prevent and prepare for cybersecurity threats.
+Added: We utilize a variety of tools, processes, software, and hardware that are managed and monitored by our IT resources including third-party vendors, as applicable, to prevent and prepare for cybersecurity threats.
We conduct regular internal and external security audits and vulnerability assessments to reduce the risk of a cybersecurity incident and we implement business continuity, contingency, and recovery plans to mitigate the impact of an incident.
−Removed: As part of these efforts, we engage a third party to conduct penetration testing and an external review of our vulnerabilities.
+Added: As part of these efforts, we engage a third party to conduct periodic penetration testing and an external review of our vulnerabilities.
We continue to strengthen access management mechanisms including broad adoption of multi-factor authentication, geolocation-based blocking, and network segmentation.
1 unchanged sentence
We recognize that threat actors frequently target employees to gain unauthorized access to information systems.
−Removed: Therefore, a key element of our prevention efforts is comprehensive employee training to recognize and respond to cybersecurity threats.
+Added: Therefore, a key element of our prevention efforts is training employees to recognize and respond to cybersecurity threats.
All new hires receive mandatory privacy and information security training.
−Removed: Employees must also complete mandatory ongoing annual cybersecurity and data trainings, which are supplemented throughout the year by regular phishing and other cyber-related testing.
+Added: Employees must also complete mandatory ongoing annual cybersecurity and data trainings, which are supplemented throughout the year by regular phishing and other cyber-related awareness activities.
Additionally, we conduct specialized training for our high-risk employees on an annual basis and specialized training for employees with access to certain sensitive information systems.
1 unchanged sentence
We recognize that our third-party vendors can be subject to cybersecurity incidents which may impact us.
−Removed: To mitigate third-party risk, vendor access to network resources is reviewed, authorized, and monitored by our IT resources, including requirements for our third-party vendors’ cybersecurity, estimated termination dates for network access, and regular reviews of all third-party vendor accounts and after access is granted, it is managed through various security tools.
−Removed: Third-party IT vendors are also subject to additional diligence such as questionnaires, inquiries, and relevant certifications.
+Added: To mitigate third-party risk, vendor access to our network resources is reviewed, authorized, and monitored for appropriateness.
+Added: Third-party IT vendors that are determined to present a higher risk are also subject to additional diligence such as questionnaires, inquiries, and relevant certifications.
Detection and Analysis
Cybersecurity incidents may be detected through a variety of means and indicators, which may include, but are not limited to, alerts from customers, employees, vendors, service providers, other third parties, and/or automated event-detection notifications.
−Removed: Once a potential cybersecurity incident is identified, including a third-party cybersecurity event, the incident response coordinator follows the procedures pursuant to the CSIRP to investigate the potential incident, including classifying the nature and severity of the event (e.g.
−Removed: malware, ransomware, service interruption, denial of service, distributed denial of service, personal data breach, intellectual property breach, theft, or fraud) and sensitivity of any compromised data.
+Added: Once a potential cybersecurity incident is identified, including a third-party cybersecurity event, the incident response coordinator follows the procedures pursuant to the CSIRP to investigate the potential incident, including classifying the nature and severity of the event.
Containment, Eradication, Recovery, and Reporting
−Removed: With every cybersecurity incident, the highest priority for the IRT is to contain the cybersecurity incident as quickly as possible.
−Removed: A cybersecurity incident is considered contained when the attacker’s ability to affect the network resources has been effectively controlled or stopped, the affected system(s) have been identified, and compromised data, memory image, and disks have been collected for analysis.
The IRT is responsible for deciding on a containment strategy to respond to the cybersecurity incident, coordinating resources, and communicating to management with subsequent notification to the Audit Committee, if warranted.
The IRT also directs and coordinates eradication and recovery efforts.
−Removed: Eradication and recovery activities depend on the nature of the cybersecurity incident, which may include, but are not limited to, rebuilding systems and/or hosts, replacing compromised files with clean versions, validation of files or data that may have been affected, increased network monitoring or logging to identify recurring attacks, or employee re-training.
+Added: Eradication and recovery activities depend on the nature of the cybersecurity incident, which may include, but are not limited to, rebuilding systems and/or hosts, replacing compromised files with clean versions, or validation of files or data that may have been affected.
Containment, eradication, and recovery may be aided by third-party vendors or investigators.
−Removed: The incident response coordinator, in consultation with the IRT and management, will engage all third parties involved in the incident.
−Removed: Our CSIRP provides clear communication protocols, including with respect to members of management, including the members of the IRT, CEO, CFO, CIO, General Counsel, Audit Committee, and external counsel, particularly with respect to legal obligations to report the incident to tenants, regulators, and law enforcement and, if applicable, our SEC reporting obligations.
+Added: Our CSIRP provides clear communication protocols, including with respect to members of management, which may include, depending on the incident's classification and other circumstances, members of the IRT, CEO, CFO, CIO, General Counsel, Audit Committee, and external counsel.
+Added: In addition, the CSIRP considers communications and reporting to tenants, regulators, and law enforcement.
Post-Incident Activity
−Removed: After recovery, the IRT gathers and preserves all incident-related documentation and conducts a post-incident analysis to identify and implement enhancements to the cybersecurity program that can mitigate the risk and/or severity of future incidents.
+Added: After recovery, the IRT conducts a post-incident analysis to identify potential enhancements to the cybersecurity program that can mitigate the risk and/or severity of future incidents.
The results of these reviews are shared with management and the Audit Committee.
−Removed: The incident response coordinator typically oversees the preparation of the formal incident report, its distribution, and the implementation of any enhancements identified through these reviews.
Cybersecurity Risks
−Removed: As of December 31, 2023, we have not had any material incidences involving cybersecurity attacks.
−Removed: However, we face risks associated with security breaches, whether through cyber-attacks or cyber-intrusions over the Internet,
−Removed: ransomware and other forms of malware, computer viruses, attachments to emails, phishing attempts, or other scams.
−Removed: Although we make efforts to maintain the security and integrity of our networks and systems including the proprietary, confidential, and personal information that resides on or is transmitted through them, and we have implemented various cybersecurity policies and procedures to manage the risk of a security incident or disruption.
+Added: As of December 31, 2024, we have not had any known instances of material cybersecurity incidents.
However, there can be no assurance that our cybersecurity efforts and measures will be effective or that attempted cybersecurity incidents or disruptions would not be successful or damaging.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.