1 unchanged sentence
Cybersecurity.
−Removed: Overview of Cybersecurity Risk Management Program
−Removed: Cybersecurity is an ongoing priority, and we remain focused on our obligation to assess, identify and manage risks from cybersecurity threats and cybersecurity incidents.
−Removed: We have developed and implemented a cybersecurity risk management program that employs a multitude of measures and processes that aid in these efforts.
−Removed: This program is designed to protect our information systems, detect cybersecurity threats and ensure our compliance with applicable privacy and cybersecurity laws.
−Removed: Our cybersecurity risk management program is integrated into our overall enterprise risk management program and is considered an integral part of our overall risk assessment process.
−Removed: For example, we report, review and consider results and findings from external and internal security and privacy assessments as part of our overall risk assessment process, and we analyze how cybersecurity risks interplay with operational, financial, compliance and reputational risks.
−Removed: As part of our cybersecurity risk management program, we undertake various activities, including, but not limited to, detective, preventative, and automated controls;
−Removed: user access controls;
−Removed: a centralized security information and management system;
−Removed: periodic assessments, including penetration testing;
−Removed: periodic trainings and simulations;
−Removed: and policies for the handling of personally identifiable information.
−Removed: We closely monitor the privacy and cybersecurity laws and regulations and conduct related reviews of our policies.
−Removed: We have implemented incident response plans providing for response, containment, reporting and disclosure and recovery, including providing training and remediation steps for internal threats.
−Removed: We also carry customary cybersecurity risk insurance.
−Removed: In addition, we use third party service providers, when appropriate, to assess, test or otherwise assist with certain aspects of our cybersecurity risk management program.
−Removed: For example, we leverage external assessors such as security researchers and penetration testers to identify vulnerabilities in our information systems.
−Removed: Further, our cybersecurity risk management program includes processes that address cybersecurity risks associated with our use of third-party services providers that have access to our information systems and/or employee, agent or agent client confidential information.
+Added: Overview of the Cybersecurity Program
+Added: Compass operates a cybersecurity program designed to identify, assess, and mitigate cybersecurity risks to protect our information assets, ensure business continuity, and maintain stakeholder trust.
+Added: Guided by industry best practices, including the National Institute of Standards and Technology's Cybersecurity Framework ("NIST CSF") and the Center for Internet Security ("CIS") Critical Controls, we focus on continuous improvement to address emerging threats and vulnerabilities.
+Added: We recognize the evolving nature of cybersecurity threats and regularly enhance our security controls, processes, and policies to adapt to these risks.
+Added: As part of our cybersecurity program, we undertake various activities and programs, including, but not limited to:
+Added: detective, preventative, corrective, and technical controls;
+Added: identity and access management systems;
+Added: periodic risk assessments, including penetration testing;
+Added: periodic end-user training and simulations;
+Added: incident response;
+Added: vulnerability management;
+Added: infrastructure and application security;
+Added: corporate security;
+Added: and policies for the handling of personally identifiable information and other restricted data.
+Added: We closely monitor privacy and cybersecurity laws and regulations and conduct related reviews of our policies.
+Added: We have implemented incident response plans that provide for the response, containment, eradication, reporting, and disclosure of security incidents.
+Added: We also carry customary cybersecurity risk insurance and have a retainer in place for third-party incident response and forensics resources.
+Added: Cybersecurity Risk Management Program
+Added: Cybersecurity is an ongoing priority, and we have developed and implemented a cybersecurity risk management program designed to identify, assess, prioritize, and mitigate cybersecurity risks to ensure our compliance with applicable privacy and cybersecurity laws.
+Added: Our cybersecurity risk management program is integrated with our overall enterprise risk management program and is a crucial component of our risk assessment process .
+Added: For instance, we report on, review, and consider the results and findings from external and internal security and privacy assessments as part of our risk program.
+Added: Additionally, we analyze how cybersecurity risks interact with operational, financial, compliance, and reputational risks.
+Added: When appropriate, we also engage third-party service providers to evaluate, test, or assist with specific elements of our cybersecurity risk management program .
+Added: For instance, we utilize external assessors, including security researchers and penetration testers, to identify and report vulnerabilities in our information systems.
+Added: Further, our cybersecurity risk management program includes a third-party risk management program to assess and manage cybersecurity risks associated with our use of third-party services providers that have access to our information systems and/or employee, agent or agent client confidential information .
For example, we perform certain due diligence before engaging third-party service providers and consider potential cybersecurity risks and exposures in our choice among providers.
We also generally require our third-party service providers that could potentially introduce cybersecurity risks to our information systems or sensitive consumer personal information to contractually agree to maintain a cybersecurity risk management program aimed at mitigating those risks and be subject to external cybersecurity audits.
−Removed: Cybersecurity Risk Management Program Assessments and Risks Associated With Cybersecurity Threats
−Removed: While we have assessed our cybersecurity risk management program periodically in the past, in the second half of 2023, we started to utilize a leading industry cybersecurity framework in our assessments.
−Removed: Specifically, we use this framework to assess our cybersecurity controls against industry best practices in the areas of:
−Removed: identify and protect assets, detect and respond to suspicious activity, as well as recover from cybersecurity incidents.
−Removed: Based on the results of our initial assessment, we have developed a multi-year plan that allows us to focus on the highest priorities.
−Removed: Under the plan, we are required to make additional investments to enhance our processes and practices over a period of time.
−Removed: Additionally, as part of our continuous overall cybersecurity posture assessment, we conduct incident simulations based on recent public cybersecurity incidents, incorporating the tactics, techniques and procedures threat actors have used when targeting organizations.
−Removed: We leverage results from these simulations to take corrective action or otherwise augment our abilities to defend and protect our information systems.
−Removed: While we have been subject to a number of cybersecurity threats and experienced non-material incidents in the past, they have not had a material adverse effect on our business, financial condition or results of operations.
−Removed: Our third party services providers have been also subject to a number of cybersecurity threats and incidents but to date, none of those threats and incidents have had a materially adverse effect on our business, financial condition or results of operations.
+Added: Cybersecurity Risks Associated With Cybersecurity Threats
+Added: While we have been subject to a number of cybersecurity threats and experienced non-material incidents in the past, as of the date of this Annual Report, they have not had a material adverse effect on our business, financial condition or results of operations .
+Added: Our third-party service providers have also been subject to a number of cybersecurity threats and incidents, but to date, none of those threats and incidents have had a materially adverse effect on our business, financial condition, or results of operations.
+Added: Please refer to the “Risk Factors” section of this Annual Report for additional information related to the cybersecurity risks that could potentially impact our business.
Cybersecurity Governance
−Removed: Our Information Security team oversees our cybersecurity risk management program, which is described in more detail above.
−Removed: In conjunction with the Company’s in-house legal team, this team is principally responsible for managing our cybersecurity risk assessment processes, our security controls, and our response to cybersecurity threats and incidents.
−Removed: Our Information Security team is segmented into six subteams and includes a dedicated Governance, Risk and Compliance subteam that is responsible for risk assessment, risk mitigation strategies, regulatory compliance, audits, internal governance and policy enforcement.
−Removed: We have also established a Security and Privacy Committee (“Committee”), co-chaired by our Senior Vice President, Head of Engineering and General Counsel, that meets monthly.
+Added: Our Information Security team oversees our cybersecurity program, which is described in more detail above.
+Added: In conjunction with the Company’s in-house legal team, this team is principally responsible for managing our cybersecurity risk management program, our security controls, and our response to cybersecurity threats, and incidents.
+Added: We have also established a Security and Privacy Committee (“Committee”), co-chaired by our Senior Vice President, Head of Engineering, Chief Information Security Officer (“CISO”) and General Counsel, that meets monthly.
This Committee is responsible for setting cybersecurity policies, strategies, and priorities, as well as ensuring that cybersecurity initiatives are aligned with the Company’s objectives.
−Removed: Members of the Committee may, from time to time, include representatives from security and compliance, internal audit, legal, product, engineering, finance, operations, strategy and people and culture functions.
+Added: Members of the Committee may, from time to time, include representatives from information security, internal audit, legal, product, engineering, finance, operations, strategy and people and culture functions.
In addition to the monthly communications at the Committee level, our Information Security team collaborates with senior leadership across our organization on a regular basis as part of the Company’s overall enterprise risk management program.
−Removed: Our Chief Information Security Officer (“CISO”) recently left the Company and we are in the process of recruiting a new, permanent CISO.
−Removed: We have engaged a temporary third-party CISO (sometimes referred to as a “Virtual CISO”) to oversee the cybersecurity risk management program and assist the Information Security team.
−Removed: Our Virtual CISO has over 20 years of experience working in the Information Security field, and is a Certified Information Systems Security Professional.
−Removed: Specifically, she has experience managing and administering enterprise infrastructure, network communications, and information security.
−Removed: Our Virtual CISO receives regular reports from the Information Security team and will provide advice to the team with incident responses, execute any remediation plans, assist with drafting policy, and perform industry standard simulations and security assessments.
−Removed: The Virtual CISO reports to our Senior Vice President and Head of Engineering.
−Removed: Our Virtual CISO will report quarterly to the Audit Committee of the Board of Directors (“the “Audit Committee”), which is responsible for overseeing the Company’s cybersecurity risk management program and cybersecurity risks.
−Removed: that report, our Virtual CISO is expected to cover topics such as (i) an overview of our overall cybersecurity strategy and posture, (ii) results and recommendations from cybersecurity risk assessments and audits, (iii) vulnerabilities in our information systems, (iv) progress towards pre-determined risk-mitigation goals, (v) identified and potential cybersecurity risks and threats, (vi) cybersecurity incidents of certain impact in accordance with the Company’s cybersecurity policies, and (vii) programs related to mitigation of cybersecurity risks and potential threats, among other things.
+Added: In 2024, we hired a new Chief Information Security Officer to oversee the cybersecurity program and lead the Information Security team.
+Added: Our CISO has over 17 years of experience building security teams and driving security initiatives for public, high-growth, and regulated companies.
+Added: He is a Certified Information Systems Security Professional and reports to our Senior Vice President and Head of Engineering.
+Added: Our CISO reports quarterly to the Audit Committee of our board of directors (the “Audit Committee”), which is responsible for overseeing the Company’s cybersecurity risk management program and cybersecurity risks.
+Added: As part of that report, our CISO covers topics such as (i) an overview of our overall cybersecurity strategy and posture, (ii) results and recommendations from cybersecurity risk assessments and audits, (iii) vulnerabilities in our information systems, (iv) progress towards pre-determined risk-mitigation goals, (v) identified and potential cybersecurity risks and threats, (vi) cybersecurity incidents of certain impact in accordance with the Company’s cybersecurity policies, and (vii) programs related to mitigation of cybersecurity risks and potential threats, among other things.
The Audit Committee reports to the full board of directors regarding its activities, including reports that it receives from our CISO.
−Removed: Once hired, we expect our permanent CISO to continue strengthening our information security posture, assist with incident response and any remediation plans, and provide quarterly reports to the Audit Committee, as we transition from using a Virtual CISO.
We are headquartered in New York, New York, where we occupy approximately 32,500 square feet of office space pursuant to a lease that is expected to expire in June 2030 subject to the terms thereof.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.