9 unchanged sentences
If realized, these risks are reasonably likely to materially affect the Company.
−Removed: Additional information on the cybersecurity risks we face is discussed in Part I, Items 1A-C, “Risk Factors.”
+Added: Additional information on the cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors.”
Cybersecurity Risk Management and Strategy
12 unchanged sentences
As mentioned above, the Board established the Committee to provide dedicated oversight of cybersecurity-related management, strategy, initiatives, risks, threats and remediation activities.
−Removed: The Committee receives regular presentations, reports and updates from the Company’s Chief Trust Officer (“CTrO”) and other members of management on developments regarding the Company’s cybersecurity program, broader cybersecurity trends, evolving industry standards, the threat environment and other topics.
+Added: The Committee receives regular presentations, reports and updates from the Company’s Chief Infrastructure and Trust Officer (“CITO”), Chief Information Security Officer (“CISO”), and other members of management on developments regarding the Company’s cybersecurity program, broader cybersecurity trends, evolving industry standards, the threat environment and other topics.
After each quarterly meeting of the Committee, the Board receives a report from the Chair of the Committee with an update on the Company’s oversight of cybersecurity risks and mitigation efforts.
5 unchanged sentences
Management Oversight and Governance
−Removed: The CTrO, reporting to the Company’s Chief Engineering & Customer Success Officer (“C/E”), is responsible for designing and implementing a security program and strategy based on the mandate provided by the Board and senior management.
−Removed: The CTrO has extensive experience in the management of cybersecurity risk programs, having served in various leadership roles in information technology and information security for over 15 years, including serving as the Chief Security Officer of two other large public technology companies.
−Removed: He also holds an undergraduate and master’s degree in computer science.
+Added: The CITO, reporting to the Company’s Chief Engineering & Customer Success Officer (“C/E”), together with the CISO, reporting to the CITO, are responsible for designing and implementing a security program and strategy based on the mandate provided by the Board and senior management.
+Added: The CITO and CISO each have extensive experience in the management of cybersecurity risk programs, having served in various leadership roles in information technology and information security for over 20 years and 15 years, respectively.
+Added: The CITO also holds an undergraduate degree in computer science.
We believe the Company’s business leaders, including our CEO, CFO, C/E and CLO, who have experience managing cybersecurity risk at the Company and at similar companies, have the appropriate expertise, background and depth of experience to manage risks arising from cybersecurity threats.
−Removed: The CTrO, in coordination with other members of senior management, works collaboratively across the Company to implement a program designed to help protect the Company’s information systems from cybersecurity threats and to promptly respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
+Added: The CITO, in coordination with the CISO and other members of senior management, works collaboratively across the Company to implement a program designed to help protect the Company’s information systems from cybersecurity threats and to promptly respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company are tasked with addressing cybersecurity threats and responding to cybersecurity incidents.
−Removed: Through ongoing communications with these teams, the CTrO and senior management are able to be informed promptly about, and monitor the prevention, detection, investigation, mitigation and remediation of, cybersecurity threats.
+Added: Through ongoing communications with these teams, the CITO, CISO, and senior management are able to be informed promptly about, and monitor the prevention, detection, investigation, mitigation and remediation of, cybersecurity threats.
These teams are expected to operate pursuant to documented plans and playbooks that include processes for escalation of incidents to leadership and to the Committee and Board, as appropriate, based on the severity level of a cybersecurity incident.
21 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.