1 unchanged sentence
Cybersecurity
−Removed: We maintain a proactive cybersecurity program that is aligned with our business and is dedicated to managing information technologies (“IT”) risks to our Company.
−Removed: We have established policies, standards, processes, and practices for assessing, identifying and managing material risks from cybersecurity threats.
−Removed: These measures are integrated into our overall risk management program and governance structure, demonstrating our commitment to cybersecurity in a manner consistent with our business activities.
−Removed: We employ an array of controls, technologies, and other processes designed to identify, protect against, detect, respond to, and mitigate cybersecurity risks.
−Removed: These measures are aligned with the frameworks established by the National Institute of Standards and Technology (NIST).
−Removed: Our IT activities are primarily outsourced for monitoring and maintenance to third parties and are subject to independent controls over IT.
−Removed: These controls include but are not limited to, internal reporting, monitoring and detection tools, threat intelligence, and general and role-based training.
−Removed: We consistently evaluate and enhance the effectiveness of our cybersecurity program, ensuring continuous evolution and improvement.
−Removed: Overseeing the assessment and management of our exposure to various risks, including cybersecurity, is a key oversight responsibility for the Board of Directors.
−Removed: These risks are identified, measured, monitored, and managed across key risk categories, which include the consideration of cybersecurity risks.
−Removed: Our chief financial officer (CFO) facilitates the Company’s oversight, which includes an assessment of our risk environment at least once per year.
−Removed: The review incorporates risk assessment and evaluation.
−Removed: The Audit Committee assists the Board with its oversight of cybersecurity risk.
−Removed: Our CFO reviews the oversight program with the Audit Committee, including reviewing existing risks and significant emerging risks across the Company’s key risk categories.
−Removed: In reviewing specific threats and risks with the Board, senior management may incorporate reports from consultants and other third-party advisors.
−Removed: To date, we have not experienced a cybersecurity threat or incident ;
−Removed: therefore, there has been no cybersecurity impact on our results of operations or financial condition.
−Removed: However, unauthorized access to our information and systems and other disruptions to our business operations could occur in the future.
+Added: We rely on information technology systems to operate our business and store and process data, including confidential business information and personal information of our customers and employees.
+Added: Generally, these systems are maintained by third parties, who assume responsibility for data security.
+Added: We are, however, subject to cybersecurity risks, including unauthorized access to our systems, data breaches, service disruptions, and other incidents.
+Added: Cybersecurity Risk Management and Strategy
+Added: We maintain processes to identify, assess, manage, and mitigate material risks posed by cybersecurity threats.
+Added: These processes are integrated into our overall risk management framework and include, among other things, risk assessments, monitoring of information technology systems, employee training, and the use of third-party service providers and security tools.
+Added: We also maintain incident response and business continuity processes designed to address cybersecurity incidents, including incidents involving third-party service providers.
+Added: Cybersecurity risks are evaluated in the context of potential operational, financial, legal, and reputational impacts.
+Added: While we seek to manage these risks, cybersecurity threats continue to evolve, and there can be no assurance that our processes will prevent all cybersecurity incidents.
+Added: Responsibility for oversight of cybersecurity risks resides with our management team, which regularly assesses cybersecurity risks and the effectiveness of related processes and controls.
+Added: Senior management is informed of material cybersecurity risks and incidents, as appropriate, and is responsible for implementing and maintaining our cybersecurity risk management practices.
+Added: The Board of Directors oversees the Company’s risks, including cybersecurity risks, and receives information from management on material risks and related mitigation efforts as part of its overall risk oversight function.
+Added: Cybersecurity Incidents
+Added: As of the date of this Annual Report, we have not experienced a cybersecurity incident that has materially affected our business, operating results, or financial condition.
+Added: However, we may experience cybersecurity incidents in the future that could have such effects.
+Added: Cybersecurity risks are described in more detail under Item 1A, “Risk Factors—Cybersecurity incidents or security breaches involving customer or employee information could adversely affect our business.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.