6 unchanged sentences
• Alignment of our program with the National Institute of Standards and Technology Cybersecurity Framework 2.0 to identify, protect, detect, respond and recover from cyberattacks.
−Removed: • Real-time and robust testing of our systems to assess our vulnerability to cyber risk, which includes targeted penetration testing, tabletop incident response exercises, disaster recovery, periodic audits of our systems by outside industry experts and continuous vulnerability scanning.
+Added: • Real-time and robust testing of our systems to assess our vulnerability to cyber risk, which includes continuous penetration testing, tabletop incident response exercises, disaster recovery, periodic audits of our systems by outside industry experts and continuous vulnerability scanning.
• Engaging external cybersecurity experts in incident response development and management.
1 unchanged sentence
• Maturity assessment and roadmap to sustain/improve security posture based on risk profile.
−Removed: The Company’s cyber risk management program is supervised by a dedicated Chief Information Officer whose team is responsible for leading enterprise-wide information security strategy, policy, standards, architecture, and processes, as well as managing the Company’s information security and risk management awareness program.
+Added: The Company’s cyber risk management program is supervised by a dedicated Chief Information Officer (CIO) with over 25 years of experience in the information technology field, and who has served as our CIO since 2021.
+Added: Our CIO is supported by a team with broad experience in cybersecurity management, with numerous related certifications.
+Added: The Company’s CIO and his team are responsible for leading enterprise-wide information security strategy, policy, standards, architecture, and processes, as well as managing the Company’s information security and risk management awareness program.
We provide regular awareness training to our employees, including periodic phishing tests, to help identify, avoid and mitigate cybersecurity threats.
9 unchanged sentences
We face a number of cybersecurity risks in connection with our business.
−Removed: Based on the information we have as of the date of this Annual Report on Form 10-K, we do not believe that any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company’s business strategy, results of operations or financial position.
+Added: Based on the information we have as of the date of this Annual Report on Form 10-K, we do not believe that we have experienced any cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company’s business strategy, results of operations or financial position.
See Item 1A, Risk Factors, of this Annual Report on Form 10-K for further discussion of cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.