23 unchanged sentences
The board is responsible for overseeing overall risk management for the Company, including review and approval of the enterprise risk management approach and processes implemented by management to identify, assess, manage, and mitigate risk, at least annually.
−Removed: The Board has delegated responsibility for oversight of the Company’s cybersecurity and information security framework and risk management to the Company’s Management Cybersecurity Committee (the “Cybersecurity Committee”).
−Removed: Pursuant to its charter, T he Cybersecurity Committee must consist at least four (4) members of Company’s executive management team, which shall include the Company’s Director of Technology, Chief Operating Officer, Chief Compliance Officer and Chief Financial Officer, each of whom is required to have working familiarity, knowledge and competencies in relevant areas, including data privacy, public policy, information technology (“IT”) strategy, IT development and deployment, or IT risk assessment and management, including information security management.
−Removed: In addition, the Company’s Director of Technology has formal education in information technology and extensive experience working in and leading the Company’s information systems and technology function.
+Added: The board has delegated responsibility for oversight of the Company’s cybersecurity, information security framework, and risk management to the Company’s management cybersecurity committee (the “Cybersecurity Committee”).
+Added: Pursuant to its charter, the Cybersecurity Committee must consist of at least four members of the Company’s executive management team, which shall include the Company’s director of technology, chief operating officer, chief compliance officer, and chief financial officer, each of whom is required to have working familiarity, knowledge, and competencies in relevant areas, including data privacy, public policy, information technology (“IT”) strategy, IT development and deployment, or IT risk assessment and management, including information security management.
+Added: In addition, the Company’s director of technology has formal education in IT and extensive experience working in and leading the Company’s information systems and technology function.
The principal responsibilities and duties of the Cybersecurity Committee, pursuant to its written charter, are to:
1 unchanged sentence
Review and provide oversight on the policies and procedures of the Company in preparation for responding to any material information security or privacy incidents;
−Removed: Review and provide oversight on the Company’s disaster recovery, business continuity, and business resiliency capabilities, including escalation protocols, relating its customer-facing products and services and internal-use information technology systems;
+Added: Review and provide oversight on the Company’s disaster recovery, business continuity, and business resiliency capabilities, including escalation protocols, relating to its customer-facing products and services and internal-use IT systems;
Review annually the appropriateness and adequacy of the Company’s cyber-insurance coverage;
3 unchanged sentences
Perform any other activities required by applicable law, rules, or regulations (including the Securities Exchange Act of 1934 and the NYSE American Stock Exchange regarding reporting and disclosure obligations related to cybersecurity risks, costs, and incidents), and take such other actions and perform and carry out any other responsibilities and duties delegated to it by the board or as the Cybersecurity Committee deems necessary or appropriate consistent with its purpose.
−Removed: The Cybersecurity Committee, including the Company’s Director of Technology, receive regular updates from the Company’s management on cybersecurity matters, results of mitigation efforts and cybersecurity incident response and remediation.
+Added: The Cybersecurity Committee, including the Company’s director of technology, receives regular updates from the Company’s management on cybersecurity matters, results of mitigation efforts, and cybersecurity incident response and remediation.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.