1 unchanged sentence
CYBERSECURITY
+Added: Management and Strategy
+Added: Company has a risk-based cybersecurity program, designed to protect the Company’s operations and information assets.
+Added: Company constantly assesses its cybersecurity risks by evaluating the likelihood of occurrence and the potential impact on the
+Added: The risk identification process considers those common in the oil and gas industry and those that pertain to the technologies
+Added: within the Company’s applications and infrastructure.
+Added: use several key risk mitigation processes and software tools in place to prevent, detect, and respond to cybersecurity attacks.
+Added: Multi-factor authentication and privileged access are required to access the Company’s network in order to protect internal
+Added: data and ensure appropriate access.
+Added: The Company utilizes security vulnerability scanning software and 24/7 monitoring in an effort
+Added: to detect and prevent significant cybersecurity threats as well as uses email and spam filtering.
+Added: Company also uses a backup and recovery methodology that supports the replication of data across multiple secure data centers
+Added: with the intent to prevent local and cloud backup data from accidental destruction and unavailability in the event of data loss
+Added: or a major cyber event.
+Added: The Company also has contracted retainers with third party vendors in the event they are required to assist
+Added: during a major cybersecurity incident.
+Added: due diligence is performed when considering purchasing third party software and utilizing third party hosted providers.
+Added: evaluation considers the security architecture, confidentiality and criticality of data, as well as methods and practices used
+Added: by third party vendors to encrypt, transmit, store, back up, and recover data.
+Added: board of directors of the Company has oversight of the Company’s risk management, including cybersecurity.
+Added: Company’s senior officers are responsible for cybersecurity risk management and regularly communicate with the board of
+Added: directors regarding risks and threats, including the status of current cybersecurity risk prevention and threat detection efforts.
+Added: Jeffery Guzy, Chief Financial Officer is the primary individual responsible for assessing and managing cybersecurity risks.
+Added: has extensive experience managing information technology departments of oil and gas organizations.
+Added: This includes responsibilities
+Added: for securing the solutions, data, and infrastructure for both corporate and field operations technology.
+Added: The Company’s technology
+Added: environment is managed by an experienced team of professionals who follow an extensive set of policies and procedures related
+Added: to data security.
+Added: Company is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially
+Added: affect the Company, including its business strategy, results of operations, or financial condition.
+Added: Please see Item
+Added: 1A—Risk Factors— “ Cyber-attacks targeting systems and infrastructure used by the oil and gas industry
+Added: and related regulations may adversely impact our operations and, if we are unable to obtain and maintain adequate protection for
+Added: our data, our business may be adversely affected ” in this Annual Report on Form 10-K for further discussion regarding
+Added: the Company’s cybersecurity risks.
the critical importance of robust cybersecurity measures, the Company is committed to developing, implementing and maintaining
1 unchanged sentence
Our management team actively evaluates and addresses cybersecurity risks in alignment with our business objectives and operational
−Removed: To date, our operations or financial standing have not been materially impaired by any cybersecurity challenges.
−Removed: ahead, the Company will mandate comprehensive cybersecurity training for both the Board and employees, covering key areas such
−Removed: as physical security of assets, data privacy and other information security policies and procedures.
+Added: The Company utilizes third party dedicated servers to protect its confidential information and has installed malware detection
+Added: applications to monitor any security breaches.
+Added: To date, our operations or financial standing have not been materially impaired
+Added: by any cybersecurity challenges.
+Added: Looking ahead, the Company will mandate comprehensive cybersecurity training for both the Board
+Added: and employees, covering key areas such as physical security of assets, data privacy and other information security policies and
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.