6 unchanged sentences
Although such risks have not materially affected us, including our business strategy, results of operations or financial condition, to date, we and our vendors have , from time to time, experienced threats to and breaches of our data and systems.
−Removed: For more information about the cybersecurity risks we face, see the section entitled “Risk Factors — Risks Related to Information Technology and Data Privacy”.
+Added: For more information about the cybersecurity risks we face, see the section titled “Risk Factors — Risks Related to Information Technology and Data Privacy”.
Risk Management and Strategy
We have implemented internal controls including regular risk assessments designed to address financial, operational and information technology (including cybersecurity) risks and controls across our organization.
−Removed: These assessments are overseen by our Director of IT and VP of Finance.
+Added: These assessments are overseen by our Director of IT and Chief Accounting Officer.
We implement cybersecurity controls and procedures designed to address cyber risks and threats, supported by third-party technologies and security advisors and providers.
2 unchanged sentences
We also maintain a Cyber Incident Response Plan, which is overseen by our Director of IT and is designed to coordinate our response to information security incidents.
+Added: Finally, we hold and maintain third-party insurance coverage for cybersecurity risks commensurate with industry standards for a company of our size and stage.
Cybersecurity Oversight
1 unchanged sentence
The Director of IT role is currently held by an individual who has more than 20 years of professional IT management experience and maintains a Global Information Assurance Certification.
−Removed: The Director of IT reports to our VP of Finance, who together are responsible for coordinating information security risk assessments and overseeing periodic testing of our cybersecurity controls.
−Removed: Our VP of Finance meets with the audit committee of our board of directors periodically for the audit committee to provide guidance on the prioritization of the risk remediation and ongoing implementation of cybersecurity improvements across our organization.
+Added: The Director of IT reports to our Chief Accounting Officer, who together are responsible for coordinating information security risk assessments and overseeing periodic testing of our cybersecurity controls.
+Added: Our Chief Accounting Officer meets with the audit committee of our board of directors periodically for the audit committee to provide guidance on the prioritization of the risk remediation and ongoing implementation of cybersecurity improvements across our organization.
+Added: We also engage an external auditing firm with information security expertise to conduct regular auditing, testing, and review of our information technology risks, processes, and operations.
Management also generally provides quarterly updates to the audit committee on cybersecurity and other information technology risks.
−Removed: We have implemented a process for the Director of IT and the VP of Finance to receive incident reports and report quarterly (and, if applicable, in the event of a cybersecurity incident), to our internal disclosure committee and the audit committee, as appropriate.
+Added: We have implemented a process for the Director of IT and the Chief Accounting Officer to receive incident reports and report quarterly (and, if applicable, in the event of a cybersecurity incident), to our internal disclosure committee and the audit committee, as appropriate.
Management presents to the entire board of directors on an annual basis, including any key findings identified in our cybersecurity assessments.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.