4 unchanged sentences
Management and Board Oversight
−Removed: We have dedicated cybersecurity resources led by our Chief Information Officer ("CIO") , who regularly provides reports on cybersecurity to our executive officers, including the CEO and CFO.
−Removed: Our CIO has significant experience in the cybersecurity and IT fields and holds multiple degrees, including a Bachelor of Science in Information Science and a Master of Business Administration.
−Removed: Additionally, our CIO is a Certified Information Security Manager.
+Added: We have dedicated cybersecurity resources, including our incident response team ("IRT"), led by our Chief Information Officer ("CIO") , who regularly provides reports on cybersecurity to our executive officers, including the CEO and CFO.
+Added: Our IRT members, which are subject to change from time to time, have a diverse range of education and expertise significant experience in fields such as IT, change and incident management, public company governance, accounting, financial controls, risk management, communications, human capital, and legal matters.
We have developed a cybersecurity incident response plan ("CSIRP") for cybersecurity incidents that may jeopardize the confidentiality, integrity, or availability of our IT systems.
Our CSIRP guides the internal response to cybersecurity incidents, following a process consistent with well-recognized industry cybersecurity frameworks.
−Removed: Pursuant to the CSIRP and its escalation protocols, we engage the incident response team ("IRT"), which includes designated personnel responsible for:
+Added: Pursuant to the CSIRP and its escalation protocols, we engage the IRT, which includes designated personnel responsible for:
(1) analyzing the severity of the incident and associated threat;
5 unchanged sentences
and (7) performing post-incident analysis and improvements.
−Removed: The IRT is led by an incident response coordinator, which in the event of a cybersecurity incident would generally be the CIO, and includes members of our IT resources, risk management, legal, communications, finance, and accounting teams, in addition to any other personnel depending on the particular facts and circumstances of the incident.
+Added: The IRT is led by an incident response coordinator, which in the event of a cybersecurity incident would generally be the CIO, and includes members of our IT resources, risk management, legal, communications, finance, and accounting teams, in addition to other personnel depending on the particular facts and circumstances of the cybersecurity incident.
We consider cybersecurity as part of our broader consideration of business strategy and enterprise risk management.
12 unchanged sentences
As part of these efforts, we engage a third party to conduct periodic penetration testing and an external review of our vulnerabilities.
−Removed: We continue to strengthen access management mechanisms including broad adoption of multi-factor authentication, geolocation-based blocking, and network segmentation.
To support our preparedness, we perform tabletop exercises at least once a year to test our CSIRP.
−Removed: We recognize that threat actors frequently target employees to gain unauthorized access to information systems.
−Removed: Therefore, a key element of our prevention efforts is training employees to recognize and respond to cybersecurity threats.
−Removed: All new hires receive mandatory privacy and information security training.
+Added: A key element of our prevention efforts is training employees to recognize and respond to cybersecurity threats.
+Added: New hires receive mandatory privacy and information security training.
Employees must also complete mandatory ongoing annual cybersecurity and data trainings, which are supplemented throughout the year by regular phishing and other cyber-related awareness activities.
−Removed: Additionally, we conduct specialized training for our high-risk employees on an annual basis and specialized training for employees with access to certain sensitive information systems.
−Removed: These trainings and tests are tracked throughout the year for each employee and are directly tied to their overall compensation.
−Removed: We recognize that our third-party vendors can be subject to cybersecurity incidents which may impact us.
To mitigate third-party risk, vendor access to our network resources is reviewed, authorized, and monitored for appropriateness.
2 unchanged sentences
Cybersecurity incidents may be detected through a variety of means and indicators, which may include, but are not limited to, alerts from customers, employees, vendors, service providers, other third parties, and/or automated event-detection notifications.
−Removed: Once a potential cybersecurity incident is identified, including a third-party cybersecurity event, the incident response coordinator follows the procedures pursuant to the CSIRP to investigate the potential incident, including classifying the nature and severity of the event.
+Added: Once a potential cybersecurity incident is identified, including a third-party cybersecurity event, the IRT follow the procedures pursuant to the CSIRP to investigate the potential incident.
Containment, Eradication, Recovery, and Reporting
1 unchanged sentence
The IRT also directs and coordinates eradication and recovery efforts.
−Removed: Eradication and recovery activities depend on the nature of the cybersecurity incident, which may include, but are not limited to, rebuilding systems and/or hosts, replacing compromised files with clean versions, or validation of files or data that may have been affected.
Containment, eradication, and recovery may be aided by third-party vendors or investigators.
−Removed: Our CSIRP provides clear communication protocols, including with respect to members of management, which may include, depending on the incident's classification and other circumstances, members of the IRT, CEO, CFO, CIO, General Counsel, Audit Committee, and external counsel.
+Added: Our CSIRP provides clear communication protocols, including with respect to members of management, which may include, depending on the incident's classification and other circumstances, members of the IRT, CEO, CFO, CIO,
+Added: General Counsel, Audit Committee, and external counsel.
In addition, the CSIRP considers communications and reporting to tenants, regulators, and law enforcement.
Post-Incident Activity
−Removed: After recovery, the IRT conducts a post-incident analysis to identify potential enhancements to the cybersecurity program that can mitigate the risk and/or severity of future incidents.
−Removed: The results of these reviews are shared with management and the Audit Committee.
+Added: After recovery, the IRT conducts a post-incident analysis for significant cybersecurity incidents to identify potential enhancements to the cybersecurity program that can mitigate the risk and/or severity of future incidents.
+Added: The results of these reviews are shared with management and the Audit Committee as appropriate.
Cybersecurity Risks
−Removed: As of December 31, 2024, we have not had any known instances of material cybersecurity incidents.
+Added: As of December 31, 2025, we have not had any known instances of material cybersecurity incidents, including third-party incidents, during any of the prior three fiscal years.
However, there can be no assurance that our cybersecurity efforts and measures will be effective or that attempted cybersecurity incidents or disruptions would not be successful or damaging.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.