3 unchanged sentences
As such, we have in the past been, and likely will in the future be, the target of cybersecurity threats and other efforts to breach or compromise our services and underlying infrastructure.
−Removed: With trust as our foremost value and the foundation of everything we do, we recognize the importance of maintaining the safety and security of our systems and data, as our customers trust our technology to deliver the highest levels of security, privacy, performance, compliance and availability at scale.
+Added: With trust as our foremost value and the foundation of everything we do, we recognize the importance of maintaining the safety and security of our systems and data.
Management is responsible for the day-to-day administration of the Company’s cybersecurity policies, processes, practices and risk management.
3 unchanged sentences
If realized, these risks are reasonably likely to materially affect the Company.
−Removed: Additional information on the cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors.”
+Added: Additional information on the cybersecurity risks we face is discussed in Part I, Items 1A-C, “Risk Factors.”
Cybersecurity Risk Management and Strategy
−Removed: When a company purchases our service offerings, they gain a trusted digital advisor who will work together with them in efforts to protect customer data.
−Removed: We aim to provide the most secure and compliant enterprise cloud platform on the market and we work to build trust and in-depth defense into all of our systems.
−Removed: Among other things, we employ a diverse, experienced team of cybersecurity professionals, engage in community events and offer free online cybersecurity incident prevention training to enable our customers to focus on their business, knowing their data is safe and accessible as needed.
+Added: When a company purchases our service offerings, they gain a trusted digital advisor who will work together with them in their efforts to protect their data.
+Added: We aim to provide a secure and compliant enterprise cloud platform and we work to build trust and in-depth defense into all of our systems.
+Added: Among other things, we employ an experienced team of cybersecurity professionals, engage in community events and offer free online cybersecurity incident prevention training to help enable our customers to focus on their business, knowing their data is safe and accessible as needed.
We seek to address material cybersecurity risks through a company-wide approach that assesses, ranks and prioritizes cybersecurity threats, vulnerabilities and issues as they are identified to maintain the confidentiality, integrity and availability of our information systems and the information that we collect and store.
4 unchanged sentences
The results of such tests and assessments are evaluated by management and periodically reported to the Committee.
−Removed: The Company further adjusts its cybersecurity policies, standards, processes and practices based on these results.
+Added: The Company further adjusts its cybersecurity policies, standards, processes and practices based on these results and evolving industry practices.
The Company also publishes attestations of its various certifications, audits, and penetration tests on its global compliance webpage.
6 unchanged sentences
While regular meetings of the Committee are scheduled on a quarterly cadence, the Committee is authorized to meet with management or individual directors at any time it deems appropriate to discuss matters relevant to the Committee.
−Removed: The Company’s policy is for the Board and the Committee to receive prompt and timely information regarding any
−Removed: cybersecurity risk (including any incident) that meets pre-established reporting thresholds, as well as ongoing updates regarding any such risk.
+Added: In between meetings, the Board and the Committee receive information regarding relevant cybersecurity risks
+Added: (including cybersecurity incidents) that meet pre-established reporting thresholds, as well as ongoing updates regarding any such risks.
Management Oversight and Governance
−Removed: The CTrO, reporting to the Company’s Chief Engineering Officer (“C/E”), is responsible for designing and implementing a security program and strategy based on the mandate provided by the Board and senior management.
−Removed: The CTrO has extensive experience in the management of cybersecurity risk management programs, having served in various leadership roles in information technology and information security for over 15 years, including serving as the Chief Security Officer of two other large public technology companies.
+Added: The CTrO, reporting to the Company’s Chief Engineering & Customer Success Officer (“C/E”), is responsible for designing and implementing a security program and strategy based on the mandate provided by the Board and senior management.
+Added: The CTrO has extensive experience in the management of cybersecurity risk programs, having served in various leadership roles in information technology and information security for over 15 years, including serving as the Chief Security Officer of two other large public technology companies.
He also holds an undergraduate and master’s degree in computer science.
We believe the Company’s business leaders, including our CEO, CFO, C/E and CLO, who have experience managing cybersecurity risk at the Company and at similar companies, have the appropriate expertise, background and depth of experience to manage risks arising from cybersecurity threats.
−Removed: The CTrO, in coordination with other members of senior management, works collaboratively across the Company to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
+Added: The CTrO, in coordination with other members of senior management, works collaboratively across the Company to implement a program designed to help protect the Company’s information systems from cybersecurity threats and to promptly respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company are tasked with addressing cybersecurity threats and responding to cybersecurity incidents.
−Removed: Through ongoing communications with these teams, the CTrO and senior management are informed promptly about, and monitor the prevention, detection, investigation, mitigation and remediation of, cybersecurity threats.
−Removed: These teams are expected to operate pursuant to documented plans and playbooks that include processes for escalation of incidents to leadership and to the Committee and Board, as appropriate, based on the severity level of an incident.
+Added: Through ongoing communications with these teams, the CTrO and senior management are able to be informed promptly about, and monitor the prevention, detection, investigation, mitigation and remediation of, cybersecurity threats.
+Added: These teams are expected to operate pursuant to documented plans and playbooks that include processes for escalation of incidents to leadership and to the Committee and Board, as appropriate, based on the severity level of a cybersecurity incident.
In addition, the Company periodically consults with outside advisors and experts to assist with assessing, identifying and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the Company’s risk management environment.
2 unchanged sentences
The Company has implemented a robust, cross-functional approach to identifying, assessing and managing cybersecurity threats and risks.
−Removed: The Company’s program includes controls and procedures designed to properly identify, classify, and escalate cybersecurity risks to provide management with visibility and prioritization of risk mitigation efforts and to publicly report material cybersecurity incidents when appropriate.
+Added: The Company’s program includes controls and procedures designed to properly identify, classify, and escalate cybersecurity risks and incidents to provide management with visibility and prioritization of risk mitigation efforts and to publicly report material cybersecurity incidents when appropriate.
• Threat Intelligence .
4 unchanged sentences
• Incident Response and Recovery Planning .
−Removed: The Company has established and maintains robust incident response, business continuity and disaster recovery plans designed to address the Company’s response to a cybersecurity incident, including the public disclosure and reporting of material incidents in a timely manner.
+Added: The Company has established and maintains incident response, business continuity and disaster recovery plans designed to address the Company’s response to a cybersecurity incident, including the public disclosure and reporting of material incidents in a timely manner.
These plans and procedures serve to guide and document a rigorous incident response program that reflects the roles of an array of stakeholders, including personnel providing technical, operational, engineering, legal and other perspectives across the Company.
1 unchanged sentence
• Third-Party Risk Management .
−Removed: The Company maintains a robust, risk-based approach to identifying and overseeing cybersecurity threats presented by certain third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business in the event of a significant cybersecurity incident affecting those third-party systems.
+Added: The Company maintains a risk-based approach to identifying and overseeing cybersecurity threats presented by certain third parties , including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business in the event of a significant cybersecurity incident affecting those third-party systems.
• Education and Awareness .
−Removed: The Company regularly provides employee training on security-related duties and responsibilities, including knowledge about how to recognize security incidents and how to proceed if an actual or suspected incident should occur.
+Added: The Company regularly provides employee training on security-related duties and responsibilities, including knowledge about how to recognize cybersecurity incidents and how to proceed if an actual or suspected incident should occur.
This training is mandatory for employees across the Company, and is intended to provide the Company’s employees with effective tools to address cybersecurity threats, and to communicate the Company’s evolving information security policies, standards, processes and practices.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.