9 unchanged sentences
We have implemented internal controls including regular risk assessments designed to address financial, operational and information technology (including cybersecurity) risks and controls across our organization.
−Removed: These assessments are overseen by our Director of IT and Chief Accounting Officer.
+Added: These assessments are overseen by our Head of IT and Chief Accounting Officer.
We implement cybersecurity controls and procedures designed to address cyber risks and threats, supported by third-party technologies and security advisors and providers.
1 unchanged sentence
In addition, we engage external third-party information security consultants to periodically conduct information security testing and assessments, and to evaluate our overarching information security program and specific incident response procedures.
−Removed: We also maintain a Cyber Incident Response Plan, which is overseen by our Director of IT and is designed to coordinate our response to information security incidents.
+Added: We also maintain a Cyber Incident Response Plan, which is overseen by our Head of IT and is designed to coordinate our response to information security incidents.
Finally, we hold and maintain third-party insurance coverage for cybersecurity risks commensurate with industry standards for a company of our size and stage.
Cybersecurity Oversight
−Removed: The Director of IT is responsible for implementing and maintaining the information security program.
−Removed: The Director of IT role is currently held by an individual who has more than 20 years of professional IT management experience and maintains a Global Information Assurance Certification.
−Removed: The Director of IT reports to our Chief Accounting Officer, who together are responsible for coordinating information security risk assessments and overseeing periodic testing of our cybersecurity controls.
+Added: The Head of IT is responsible for implementing and maintaining the information security program.
+Added: The Head of IT role is currently held by an individual who has more than 20 years of professional IT management experience and maintains a Global Information Assurance Certification.
+Added: The Head of IT reports to our Chief Accounting Officer, who together are responsible for coordinating information security risk assessments and overseeing periodic testing of our cybersecurity controls.
Our Chief Accounting Officer meets with the audit committee of our board of directors periodically for the audit committee to provide guidance on the prioritization of the risk remediation and ongoing implementation of cybersecurity improvements across our organization.
1 unchanged sentence
Management also generally provides quarterly updates to the audit committee on cybersecurity and other information technology risks.
−Removed: We have implemented a process for the Director of IT and the Chief Accounting Officer to receive incident reports and report quarterly (and, if applicable, in the event of a cybersecurity incident), to our internal disclosure committee and the audit committee, as appropriate.
+Added: We have implemented a process for the Head of IT and the Chief Accounting Officer to receive incident reports and report quarterly (and, if applicable, in the event of a cybersecurity incident), to our internal disclosure committee and the audit committee, as appropriate.
Management presents to the entire board of directors on an annual basis, including any key findings identified in our cybersecurity assessments.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.