3 unchanged sentences
The impact could include weakened financial condition, litigation risk, degrading mining operations, loss of competitiveness, fraud, extortion, harm to employees, violation of applicable privacy or other regulations that could result in regulatory action and fines.
−Removed: We have developed and implemented a cybersecurity program to manage the confidentiality, integrity and availability of our data and information systems that support our business.
+Added: Risk Management and Strategy
+Added: We maintain a cybersecurity program to manage the confidentiality, integrity and availability of our data and information systems that support our business.
The program is aligned with the National Institute of Standards and Technology Cybersecurity Framework 2.0 and is integrated into our overall risk management program.
1 unchanged sentence
We have implemented policies, procedures and technological tools to prevent, detect and mitigate cybersecurity risks posed by third parties.
−Removed: We use third party providers to help us consistently monitor and evaluate our cybersecurity program and performance through actions that include hiring a contract Chief Information Security Officer (“CISO”) with decades of cybersecurity experience to help manage our program.
−Removed: We also use industry standard technology tools including vulnerability scans, penetration tests, firewalls, endpoint detection and threat intelligence.
−Removed: A written cybersecurity incident response plan that we tabletop yearly and cybersecurity insurance are also important pillars in our approach to managing the risk of a cyber event.
+Added: We use third-party security vendors to further strengthen our cybersecurity posture.
+Added: These partners provide advanced monitoring, detection, and response capabilities that complement our internal controls and staff expertise.
+Added: Their services include continuous threat intelligence, vulnerability management, and incident response support, which are integrated into our cybersecurity program.
+Added: A written cybersecurity incident response plan that we tabletop yearly and cybersecurity insurance are also key components of our approach to managing the risk of a cyber event.
Our incident response plan contains a materiality analysis framework based on Federal Information Processing Standards Publication 199.
5 unchanged sentences
As part of communicating the importance of cybersecurity at an enterprise-wide level, we require that all company employees participate in annual cybersecurity training.
−Removed: Our IT Steering and Risk Committee (“ITSRC”) has been delegated the responsibility for managing cybersecurity risk for the company.
−Removed: This committee is chaired by our Chief Technology Officer and includes a diverse cross section of company stakeholders including the Senior IT Manager, General Counsel, VP of Organizational Development and a member of our Third Party Audit team.
−Removed: As of July 1, 2024, we added an outsourced virtual CISO who is a key advisor to the ITSRC, specifically for his decades of expertise in managing and maturing a cybersecurity program that includes mitigation, incident prevention, detection and remediation disciplines.
−Removed: The ITSRC meets at least semi-annually to assess our approach to evolving cybersecurity threats and its impact on our cybersecurity program.
+Added: Our IT Steering and Risk Committee (“ITSRC”) has been delegated the responsibility for managing cybersecurity risk for the company by the Board of Directors (the “Board”).
+Added: This committee is chaired by our Chief Technology Officer & Chief Operating Officer and includes a diverse cross section of company stakeholders including the CFO, Director of IT, SVP of Security, and our General Counsel.
+Added: On May 1, 2025, we added an outsourced virtual CISO who is a key advisor to the ITSRC, bringing over a decade of expertise in managing and maturing cybersecurity program that includes mitigation, incident prevention, detection and remediation disciplines.
The ITSRC is also responsible for maintaining and monitoring legal and regulatory requirements and compliance as well as oversight of the adequacy of company cyber insurance.
−Removed: Our third party security vendors, in collaboration with our Senior IT Manager, keep the ITSRC apprised of efforts surrounding the prevention, detection, mitigation and remediation of any cyber threats or cybersecurity incidents.
−Removed: The Board of Directors (the “Board”) is entrusted with the oversight of the management of cybersecurity risk and our cybersecurity program.
+Added: Our third-party security vendors, in collaboration with our Director of IT, keep the ITSRC apprised of efforts surrounding the prevention, detection, mitigation and remediation of any cyber threats or cybersecurity incidents.
+Added: The Board is entrusted with the oversight of the management of cybersecurity risk and our cybersecurity program.
The Board administers this oversight through its audit committee and the ITSRC.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.