2 unchanged sentences
Risk Management
+Added: We recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.
Our risk management program includes focused efforts on identifying, assessing and managing cybersecurity risk, including the following:
• A robust information security training program that requires all company employees with access to our networks to participate in regular and mandatory training on how to be aware of, and help defend against, cyber risks, combined with periodic testing to measure the efficacy of our training efforts.
−Removed: • Alignment of our program with the National Institute of Standards and Technology Cybersecurity Framework to prevent, detect and respond to cyberattacks.
−Removed: • Continuous and robust testing of our systems to assess our vulnerability to cyber risk, which includes targeted penetration testing, tabletop incident response exercises, periodic audits of our systems by outside industry experts and regular vulnerability scanning.
+Added: • Alignment of our program with the National Institute of Standards and Technology Cybersecurity Framework to identify, protect, detect, respond and recover from cyberattacks.
+Added: • Real-time and robust testing of our systems to assess our vulnerability to cyber risk, which includes targeted penetration testing, tabletop incident response exercises, disaster recovery, periodic audits of our systems by outside industry experts and continuous vulnerability scanning.
• Engaging external cybersecurity experts in incident response development and management.
• Business continuity plans and critical recovery backup systems.
+Added: • Maturity assessment and roadmap to sustain/improve security posture based on risk profile.
The Company’s cyber risk management program is supervised by a dedicated Chief Information Officer whose team is responsible for leading enterprise-wide information security strategy, policy, standards, architecture, and processes, as well as managing the Company’s information security and risk management awareness program.
7 unchanged sentences
As reflected in the Audit Committee’s charter, the Board has specifically delegated responsibility for oversight of cybersecurity matters to the Audit Committee, which provides advice and guidance on the adequacy of the Company’s initiatives on, among other things, cybersecurity risk management.
−Removed: The Chief Information Officer presents regular updates to the Audit Committee and the full Board of Directors, on, among other things, the Company’s cyber risks and threats, the status of projects to strengthen the Company’s information security systems, and the emerging threat landscape.
+Added: The Chief Information Officer presents regular updates to the Audit Committee and the full Board of Directors, on, among other things, the Company’s cyber risks and threats, and the status of projects in the Company’s multi-year roadmap to strengthen the Company’s information security systems to address the emerging threat landscape.
The Company also engages third parties to periodically evaluate and audit aspects of the Company’s information security programs, including by conducting vulnerability assessments and penetration testing, and the results of those findings are reported to the Audit Committee and used to help identify potentially material risks and prioritize certain security initiatives.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.