7 unchanged sentences
Department of Commerce’s National Institute of Standards and Technology (NIST) Cybersecurity Framework to guide our cybersecurity program.
−Removed: CNX’s cybersecurity team includes executive officers and dedicated cybersecurity personnel, such as our Vice President of Information and Technology, who has approximately 30 years of technical leadership and cybersecurity expertise, and multiple cybersecurity engineers.
−Removed: Led by professionals with deep cybersecurity expertise across multiple industries, the team takes a cross-functional approach to addressing risks and engages in discussions with the Board of Directors and executive management as needed.
+Added: CNX’s cybersecurity team includes executive officers and dedicated cybersecurity personnel.
+Added: The team is led by our Vice President Chief Information and Technology Officer, who has approximately 30 years of technical leadership and cybersecurity expertise, and multiple cybersecurity engineers.
+Added: The team is staffed by professionals with deep cybersecurity expertise across multiple industries, the team takes a cross-functional approach to addressing risks and engages in discussions with the Board of Directors and executive management as needed.
We have developed a written incident response plan (IRP) that delineates the procedures to be followed for handling a variety of cybersecurity incidents;
1 unchanged sentence
establishes cybersecurity incident response levels;
−Removed: provides for the conducting of legally privileged investigations to enable us to meet applicable legal obligations, including possible notification requirements;
+Added: provides for the conducting of legally privileged investigations designed to enable us to meet applicable legal obligations, including possible notification requirements;
and outlines the roles and responsibilities for various personnel in the event of a cybersecurity incident.
4 unchanged sentences
CNX leverages substantial technological tools and partners to augment and enable the efforts of its internal cybersecurity team.
−Removed: Separately, management and oversight of the risks from cybersecurity threats associated with our engagement of third-party service providers is currently included in our internal auditing procedures and we have plans to further mature these procedures in the current fiscal year.
+Added: Separately, management and oversight of the risks from cybersecurity threats associated with our engagement of third-party service providers are currently included in our internal auditing procedures and we have plans to further mature these procedures in the current fiscal year.
The Board , in coordination with the ESCR Committee, is responsible for the oversight of risks from cybersecurity threats.
2 unchanged sentences
The CNX IRP calls for prompt and timely direct notifications and updates to the Board (or its committees) as necessary in connection with potentially significant cybersecurity incidents that may occur.
−Removed: On a periodic basis, the Board and the ESCR Committee discuss our approach to cybersecurity with our Vice President Information and Technology.
+Added: On a periodic basis, the Board and the ESCR Committee discuss our approach to cybersecurity with our Vice President - Chief Information and Technology Officer.
Management’s role in assessing and managing our material risks from cybersecurity threats, as well as making final materiality determinations and disclosures and other compliance decisions, is documented in the CNX IRP, and our processes for identifying, prioritizing, and remediating vulnerabilities are documented via the Company’s vulnerability management program procedures.
−Removed: In connection with and pursuant to the IRP, our dedicated incident response team works collaboratively across CNX to carry out a program that has been designed to protect our information system from cybersecurity threats, assess and manage risks arising from any such threats, and to promptly respond to potential cybersecurity incidents.
+Added: In connection with and pursuant to the IRP, our dedicated incident response team works collaboratively
+Added: across CNX to carry out a program that has been designed to protect our information system from cybersecurity threats, assess and manage risks arising from any such threats, and to promptly respond to potential cybersecurity incidents.
To date, there have been no risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, which have materially affected, or have been reasonably likely to materially affect, the Company, including our business strategy, results of operations or financial condition.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.