16 unchanged sentences
We place a high priority on cybersecurity within our organization.
−Removed: This includes regular cybersecurity training for employees, focusing on relevant risks to their job duties (e.g.
−Removed: social engineering, ransomware, denial of service, and other risks).
+Added: This includes regular cybersecurity training for employees, focusing on relevant risks to their job duties (e.g., social engineering, ransomware, denial of service, and other risks).
As part of our cybersecurity risk management program, we conduct internal tests to identify potential vulnerabilities.
Additionally, we organize annual tabletop exercises led by third-party consultants to enhance our readiness for different scenarios, assess our core information systems and cybersecurity practices, improve decision-making and prioritization, and promote monitoring and reporting across business functions.
−Removed: We annually engage third parties to perform cybersecurity audits to identify opportunities and enhancements to strengthen our policies and practices.
+Added: We regularly engage third parties to perform cybersecurity audits to identify opportunities and enhancements to strengthen our policies and practices.
We also annually engage an independent third party to perform internal and external penetration testing of our systems.
7 unchanged sentences
While these risks and threats require active and ongoing efforts to mitigate, we have not identified any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our operations , business strategy, or financial condition.
−Removed: Our Chief Information Officer (“CIO”) is directly responsible for the implementation of our cybersecurity risk management program.
+Added: Our Chief Information Officer (“CIO”) is directly responsible for the implementation of our cybersecurity risk management program, and our Senior Director of Information Security reports directly to the CIO.
Our CIO is additionally primarily responsible for our overall information security, strategy, policy, security engineering, architecture, operations and cybersecurity threat detection and the management of cybersecurity risk.
5 unchanged sentences
The cybersecurity team routinely tests the CIRP across the organization to validate the procedures for appropriately escalating potentially material cybersecurity risks and incidents.
−Removed: In the event of a cybersecurity incident, senior management, including our General Counsel, CIO, and Chief Financial Officer (“CFO”), are tasked with conducting an assessment of the incident.
+Added: In the event of a cybersecurity incident, senior management, including our General Counsel, CIO, and Chief Financial Officer (“CFO”), are tasked with assessing the incident.
This assessment involves evaluating relevant quantitative and qualitative factors as well as considering SEC guidance.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.