2 unchanged sentences
Risk Management and Strategy
−Removed: To mitigate cybersecurity risks we strive to continually assess and improve our processes and procedures.
−Removed: We engage with industry-leading managed security service providers to supplement our efforts in identifying, assessing, preventing, and responding to cybersecurity threats.
−Removed: We are working to align our information technology operations and information security processes to the National Institute of Standards and Technology’s framework.
−Removed: We have adopted a cloud-first strategy which is a foundational element to our overall cybersecurity posture.
−Removed: For essential systems, we utilize SaaS-based software partners who annually conduct Statement on Standards for Attestation Engagements.
−Removed: We have adopted a cybersecurity risk management process that is designed to identify and mitigate potential cybersecurity risks and is currently being integrated into our overall enterprise risk management process.
−Removed: We regularly assess our cybersecurity vulnerability by utilizing credible, third-party cybersecurity experts to conduct annual internal penetration tests and monthly vulnerability scans.
−Removed: These threat intelligence and monitoring activities, tests, and scans help us identify potential cybersecurity risks.
−Removed: We seek to mitigate cybersecurity risks we identify through a variety of methods;
−Removed: however, we acknowledge that even a robust, well-designed information technology control environment may not fully eliminate cybersecurity risk .
−Removed: It is possible that we will be unable to detect certain vulnerabilities in time to remediate them, or that our implemented controls may not operate as intended.
−Removed: To date, we have not experienced any material cybersecurity incidents.
−Removed: We remain subject to the risks from cybersecurity threats that, if realized, are reasonably likely to materially affect the Company’s business strategy, results of operations, or financial condition.
−Removed: Our Board of Directors considers cybersecurity as part of its risk oversight function.
−Removed: While management is responsible for the day-to-day management of risk, our Board of Directors maintains oversight of management’s implementation of our cybersecurity risk management processes.
−Removed: Our Board of Directors receives briefings on material cybersecurity incidents, as necessary.
−Removed: Our Vice President of Information Technology provides principal oversight and guidance of our cybersecurity risk management strategy, programs, and processes.
−Removed: The Vice President of Information Technology has over 30 years of experience in information technology, leading organizations through strategic technology and process improvement initiatives, including over 15 years of extensive experience in cybersecurity.
−Removed: He is supported by a team of technical experts who have received formal training and possess relevant experience in addition to managed cybersecurity service providers who specialize in preventing, identifying, and responding to cybersecurity threats.
−Removed: As part of our annual enterprise risk assessment, technology cybersecurity risks are ranked and reviewed by management.
−Removed: In the event of a cybersecurity incident, the Vice President of Information Technology would prepare a comprehensive assessment for management that summarizes potential and actual impacts and includes any steps needed to remediate the identified issues.
−Removed: If the cybersecurity incident was deemed to be material by management, the Vice President of Information Technology would brief our
−Removed: Board of Directors on the matter, at which time determinations would be made by the Board of Directors on the need to report or disclose the cybersecurity incident to our customers or investors.
+Added: To mitigate cybersecurity risks, we continuously assess and enhance our security processes and procedures.
+Added: We collaborate with industry-leading managed security service providers to strengthen our ability to identify, assess, prevent, and respond to cybersecurity threats.
+Added: Our information technology operations and security processes are being aligned with the National Institute of Standards and Technology (NIST) framework to further standardize and improve our security posture.
+Added: As part of our commitment to a cloud-first strategy, we prioritize the use of SaaS-based solutions for critical business functions.
+Added: These third-party providers conduct annual Statement on Standards for Attestation Engagements ("SSAE") audits, ensuring compliance with industry best practices.
+Added: We have adopted a cybersecurity risk management framework designed to identify and mitigate potential cybersecurity risks, which is being integrated into our overall enterprise risk management program.
+Added: Our risk assessments are informed by third-party cybersecurity experts, who conduct annual internal penetration tests and monthly vulnerability scans to continuously evaluate and strengthen our security posture.
+Added: Cybersecurity risks are categorized using a Critical, High, Medium, and Low risk scoring methodology.
+Added: These assessments are performed through a combination of automated tools, manual audits, and expert evaluations, allowing us to implement effective controls that enhance our security framework.
+Added: In addition, we have introduced annual cybersecurity awareness training, phishing simulations, and ongoing communication initiatives to strengthen organizational awareness of cybersecurity risks and threat prevention.
+Added: To date, we and our subsidiaries have not experienced any material cybersecurity incidents.
+Added: Cybersecurity is a key component of our enterprise risk oversight framework, with our Board of Directors actively engaged in overseeing cybersecurity risk management.
+Added: While management is responsible for day-to-day cybersecurity operations, the Board ensures that our cybersecurity risk management strategies are effectively implemented.
+Added: The Board is briefed on material cybersecurity incidents as necessary to maintain transparency and informed decision-making.
+Added: Our Vice President of Information Technology leads our cybersecurity strategy, programs, and risk management processes.
+Added: With over 30 years of experience in IT, including 15+ years in cybersecurity, the Vice President provides strategic oversight and ensures alignment with industry best practices.
+Added: This role is supported by a team of cybersecurity professionals with formal training and specialized expertise, as well as partnerships with managed security service providers focused on proactive threat detection, incident response, and risk mitigation.
+Added: As part of our annual enterprise risk assessment, cybersecurity risks are ranked and reviewed by executive management.
+Added: In the event of a cybersecurity incident, the Vice President of Information Technology, in collaboration with our cybersecurity partners, would conduct a comprehensive impact assessment.
+Added: This assessment would outline both potential and actual risks, along with
+Added: necessary remediation steps.
+Added: If an incident is deemed material, the Vice President would escalate the matter to the Board of Directors, who would determine whether disclosure to customers or investors is required.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.