2 unchanged sentences
Risk Management and Strategy
−Removed: The Company has developed a standards-based information security program to address risks from cybersecurity threats.
−Removed: The program includes policies and procedures that identify how security measures and controls are developed, implemented, and maintained.
−Removed: The maturity and effectiveness of the security program is reviewed biennially by a reputable third party.
+Added: The Company maintains an information security program designed in alignment with the ISO/IEC 27001 and ISO/IEC 27002 standards to address risks arising from cybersecurity threats.
+Added: The program consists of documented policies, standards, and procedures that define the design, implementation, operation, and maintenance of security controls.
+Added: The maturity and effectiveness of the information security program are evaluated biennially by an independent third party.
A risk assessment is conducted annually.
2 unchanged sentences
likelihood and severity of risk, impact on the Company and others if a risk materializes, feasibility and cost of controls, and impact of controls on operations and others.
−Removed: Specific controls that are used to some extent by the Company include endpoint threat detection and response (EDR), identity and access management (IAM), multi-factor authentication (MFA), firewalls and intrusion detection and prevention, and vulnerability and patch management.
−Removed: An internal information security audit program is in place to ensure controls remain operational and effective.
+Added: Specific controls used by the Company include, endpoint threat detection and response (EDR), identity and access management (IAM), multi-factor authentication (MFA), firewalls and intrusion detection and prevention systems, vulnerability and patch management, and ongoing employee information security awareness and training programs.
+Added: An internal information security audit program is maintained to help ensure that these controls remain operational and effective.
Third-party security firms are used by the Company in different capacities to provide or operate some of these controls and technology systems.
9 unchanged sentences
The Company (or third parties it relies on) may not be able to fully, continuously, and effectively implement security controls as intended.
−Removed: As described above, we utilize a risk-based approach and judgment to determine the security controls to implement and it is possible we may not implement appropriate controls if we do not recognize or underestimate a particular risk.
+Added: As described above, we utilize a risk-based approach and judgment to determine the security controls to implement and it is possible we may not implement appropriate controls if we do not recognize or if we underestimate a particular risk.
In addition, security controls, no matter how well designed or implemented, may only mitigate and not fully eliminate risks.
And events, when detected by security tools or third parties, may not always be immediately understood or acted upon.
−Removed: The Company activated their incident response plan to address a security incident in 2024.
−Removed: The Company is not aware of additional cybersecurity threats or any material cybersecurity incidents to date that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: On July 10, 2024, we detected unauthorized occurrences on a portion of our information technology (IT) systems.
−Removed: Upon detecting the unauthorized occurrences, we immediately began taking steps to contain, assess and remediate the cybersecurity incident, including beginning an investigation with leading external cybersecurity specialists, activating our incident response plan, and shutting down some systems.
−Removed: As a result of these and other measures, we believe the threat actor was ejected from our IT systems on July 10, 2024.
−Removed: After we shut down some of our systems, we experienced disruption to certain of our operations, including interrupted manufacturing at our domestic plants and delayed order fulfillment for our retail network and delay of some wholesale shipments.
−Removed: Within a few days of the incident, we were able to resume retail order fulfillment and caught up on fulfilling wholesale orders that were delayed as a result of the cybersecurity incident.
−Removed: We have fully restored the IT systems and data and our investigation has not found evidence that any of our core operating systems for manufacturing, wholesale and retail order processing and fulfillment, or financial reporting were impacted.
−Removed: While we believe the impacts were not material to our financial condition and results of operations for the fiscal year, we estimate that between $1,000 and $2,000 of sales were lost due to the shutdown during the cybersecurity incident.
−Removed: During the third quarter of 2024, we also incurred legal and remediation costs related to the incident of approximately $98 which are included in selling, general and administrative expenses.
−Removed: In addition, cost of goods sold for year ended November 30, 2024 includes $609 for wages paid to hourly production employees during the work stoppage resulting from the cybersecurity incident.
−Removed: Because no inventory was produced during the temporary shutdown of our manufacturing operations, these wages were charged directly to expense.
−Removed: We are seeking reimbursement of certain costs, expenses and losses stemming from the cybersecurity incident and have submitted a claim to our cybersecurity insurer.
−Removed: We expect final resolution and payment of the claim during the first half of 2025.
+Added: In fiscal 2024, the Company activated its incident response plan to address a cybersecurity incident that was resolved without material impact to the Company.
+Added: The Company is not aware of any additional cybersecurity threats or incidents to date that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations or financial condition.
Additionally, in Item 1A Risk Factors under the heading of "Risks Related to Electronic Data Processing and Digital Information,” forward-looking cybersecurity threats that could have a material impact on the Company are discussed.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.