2 unchanged sentences
We maintain a comprehensive process for detecting, assessing, and managing material risks from cybersecurity threats as part of our overall enterprise risk management system and processes.
−Removed: Our Chief Technology Officer (“CTO”) oversees our Chief Information Security Officer and a dedicated team of information security professionals who are responsible for our cybersecurity risk management program.
−Removed: Our CTO oversees our information security professionals’ efforts to prevent, detect, mitigate, and remediate cybersecurity and other emerging technology risks and incidents and the efforts for assessing and managing our material risks from cybersecurity threats.
+Added: Our Chief Technology Officer ("CTO") oversees our Chief Information Security Officer ("CISO") and a dedicated team of information security professionals who are responsible for our cybersecurity risk management program.
+Added: Our CISO oversees our information security professionals’ efforts to prevent, detect, mitigate, and remediate cybersecurity and other emerging technology risks and incidents and the efforts for assessing and managing our material risks from cybersecurity threats.
Our cybersecurity and risk management program includes technical security controls, policy enforcement mechanisms, monitoring systems, employee training, contractual arrangements, tools, and related services from third-party providers.
−Removed: Our CTO has over twenty years of extensive experience in information technology and security.
−Removed: We use the National Institute of Standards and Technology Cybersecurity Framework ("NIST CSF") as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: Our CISO has over twenty years of extensive experience in information technology and security.
+Added: Our cybersecurity risk management program is informed in part by the National Institute of Standards and Technology Cybersecurity Framework ("NIST CSF") as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
This does not mean that we meet any particular technical standards, specifications, or requirements of the NIST CSF.
−Removed: We routinely engage consultants and other third parties to assist with our cybersecurity risk management, including third-party penetration tests of our various information technology environments.
−Removed: As part of our current due diligence review and contracting process with third-party vendors that may have access to our data or systems, we perform an information security review of the vendor’s program and require such contracts to include certain minimum-security safeguards and notification requirements, where applicable.
+Added: We routinely engage consultants and other third parties to assist with our cybersecurity risk management, including third-party penetration tests of our various information technology environments and certain assessments from time to time to assist us in evaluating our program against various industry or best practice standards.
+Added: Our cybersecurity risk management program includes certain components to assist in managing third-party risk.
+Added: For example, w e require contracts with certain third-party vendors that have access to confidential data or key systems to include certain minimum data protection and notification requirements, where applicable.
We also carry cybersecurity insurance with coverage for costs associated with a cybersecurity incident.
−Removed: We have an established incident response plan to address and guide our employees and management on our response to a cybersecurity incident.
−Removed: The Company has two management committees that assist with cybersecurity incidents and risk management.
+Added: We have established an incident response plan to address and guide our employees and management on our response to a cybersecurity incident.
+Added: The Company has two management committees that assist with cybersecurity incidents and cybersecurity and privacy risk management.
These committees consist of senior leadership and cross-functional members from across our organization.
1 unchanged sentence
The Cybersecurity Disclosure Committee ("CD Committee") assists senior management in fulfilling their responsibilities for oversight of the accuracy and timeliness of disclosures made by the Company in response to cybersecurity incidents and vulnerabilities.
−Removed: event a potentially significant cybersecurity incident is identified by our information security team, such incident is reported to the CD Committee to consider applicable disclosures, with the assistance of outside counsel as needed.
−Removed: In addition, senior leadership prepares an enterprise risk management report identifying and evaluating enterprise risks, including cybersecurity risks, which is regularly presented to the Audit Committee.
+Added: In the event a potentially significant cybersecurity incident is identified by our information security team, such incident is reported to the CD Committee to consider applicable disclosures, with the assistance of outside counsel as needed.
+Added: Senior leadership also prepares an enterprise risk management report identifying and evaluating enterprise risks, including cybersecurity risks, which is regularly presented to the Audit Committee.
Our executive leadership team, along with oversight from the Audit Committee of the Board of Directors , are responsible for our overall enterprise risk management system and processes and regularly consider cybersecurity risks in the context of other material risks to the Company.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.