6 unchanged sentences
The process consists of structured reviews, discussions, and mitigation planning, and includes risks identified by our cybersecurity functions.
−Removed: The cybersecurity ERM process is administered by InfoSec with input from each business segment and function, continually monitors material cybersecurity risks facing Comtech, including cybersecurity threats and threats to our internal systems, our products, services and programs for customers, and our supply chain.
−Removed: Our CISO has extensive experience leading information technology for global organizations across communications, aerospace and defense, and works directly with our CEO, Chief Financial Officer, Executive Vice President ("EVP") of Systems and IT Controls, and other members of senior management to assess cybersecurity threats as part of our ERM process.
+Added: The cybersecurity ERM process is administered by InfoSec with input from each business segment and function.
+Added: InfoSec continually monitors material cybersecurity risks facing Comtech, including cybersecurity threats and threats to our internal systems, our products, services and programs for customers, and our supply chain.
+Added: Our cybersecurity risk management team has extensive experience leading information technology for global organizations across communications, aerospace and defense, and works directly with our CEO, Chief Financial Officer, Executive Vice President ("EVP") of Systems and IT Controls, and other members of senior management team to assess cybersecurity threats as part of our ERM process.
To manage and remediate cybersecurity risks identified as part of our ERM process and to manage emerging cybersecurity threats in real time;
4 unchanged sentences
The policies and controls we have implemented to date reflect our adherence to these requirements and have been assessed by external organizations, including industry partners.
+Added: During fiscal year 2025 and through the date of this filing, based on the information available, we did not identify any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents (as such terms are defined in Item 106(a) of Regulation S-K), that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: Please see Cybersecurity Risks under Item 1A - Risk Factors under Part I of this Form 10-K for more information about risks to us from cybersecurity threats.
Enterprise Cybersecurity
−Removed: Our enterprise cybersecurity program aligns with the National Institute of Standards and Technology (“NIST”) standards, among others, and includes processes and controls for the deployment of new IT systems by the Company and controls over new and existing systems operation.
+Added: Our enterprise cybersecurity program aligns with the National Institute of Standards and Technology (“NIST”) standards, among others, and includes processes and controls for the deployment of new IT systems by us and controls over new and existing systems operation.
We monitor and conduct regular testing of these controls and systems, including vulnerability management through active discovery and testing to regularly assess patching and configuration status.
3 unchanged sentences
Our information technology systems used in connection with programs for the U.S.
−Removed: government align with the NIST standard and meet the requirements of 32 CFR Part 117 (National Industrial Security Program Operating Manual) and other applicable U.S.
+Added: government align with the NIST standard and meet the requirements of 32 CFR Part 117 (National Industrial Security Program Operating Manual or "NISPOM") and other applicable U.S.
government guidance.
14 unchanged sentences
Our cybersecurity program is regularly assessed through management self-evaluations and ongoing monitoring procedures to evaluate our program effectiveness, including vulnerability management through active discovery and testing to validate patching and configuration.
−Removed: Additionally, our InfoSec function regularly assesses our program effectiveness through audits of our entities, systems, and processes to help maintain compliance with policies.
+Added: Additionally, InfoSec regularly assesses our program effectiveness through audits of our entities, systems, and processes to help maintain compliance with policies.
As cybersecurity threats are continuously evolving, we also periodically engage with third parties to perform maturity assessments of our program to identify potential risk areas and improvement opportunities.
2 unchanged sentences
Several external organizations also evaluate our enterprise cybersecurity program, including the U.S.
−Removed: Defense Contract Management Agency ("DCMA") and Cybersecurity Maturity Model Certificate Third Party Assessment Organization.
+Added: Defense Contract Management Agency ("DCMA") and Cybersecurity Maturity Model Certificate or "CMMC" Third Party Assessment Organization.
Moreover, some of our products are audited or reviewed for regulatory compliance certification pursuant to the relevant DoD risk management framework.
2 unchanged sentences
The Technology, Innovation, and Cyber Committee of the Board of Directors also reviews enterprise cybersecurity risks in connection with its oversight of cybersecurity and compliance risks.
−Removed: Our CISO leads our enterprise cybersecurity program and is responsible for assessing and managing enterprise cybersecurity risks in coordination with the EVP of Systems and IT Controls.
−Removed: Our CISO regularly updates the Technology, Innovation and Cyber Committee and Board of Directors on cybersecurity risks as they relate to our information and operational technology systems and our suppliers and partners, as well as provides regular updates on enterprise cybersecurity incidents and key defenses and mitigation strategies.
−Removed: Our CISO regularly reviews enterprise cybersecurity risks, controls, program policy and processes, including training, oversees policy and program development, implementation, and updates, and informs senior leadership on cybersecurity-related issues and activities affecting the organization.
−Removed: Additionally, our CISO is regularly apprised of enterprise cybersecurity events, threats, and activities, including with respect to incidents, protection vulnerabilities, software update needs and lifecycle status.
+Added: Our cybersecurity risk management team leads our enterprise cybersecurity program and is responsible for assessing and managing enterprise cybersecurity risks.
+Added: Our cybersecurity risk management team regularly updates the Technology, Innovation and Cyber Committee and Board of Directors on cybersecurity risks as they relate to our information and operational technology systems and our suppliers and partners, as well as provides regular updates on enterprise cybersecurity incidents and key defenses and mitigation strategies.
+Added: Our cybersecurity risk management team regularly reviews and manages enterprise cybersecurity risks, controls, program policy and processes, including training, oversees policy and program development, implementation, and updates, and informs senior leadership on cybersecurity-related issues and activities affecting the organization.
+Added: Additionally, our cybersecurity risk management team regularly monitors and leads efforts to address and remediate, as appropriate, enterprise cybersecurity events, threats, and activities, including with respect to incidents, protection vulnerabilities, software update needs and lifecycle status.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.