1 unchanged sentence
Cybersecurity
−Removed: Company has processes in place for assessing, identifying, preventing, and managing material risks from cybersecurity threats, including
−Removed: related to the use of third party service providers.
−Removed: In addition, the Company leverages the security and monitoring tools of third party
−Removed: service providers.
−Removed: These processes are integrated into the Company’s overall risk management program and systems, as overseen by
−Removed: the Board, primarily through the Audit Committee.
−Removed: maintain physical, technical and administrative safeguards to prevent and identify cybersecurity risks, and have implemented practices
−Removed: and procedures to address cybersecurity risks.
+Added: Management and Strategy
+Added: The Company has processes
+Added: in place for assessing, identifying, preventing, and managing material risks from cybersecurity threats, including related to the use
+Added: of third-party service providers.
+Added: In addition, the Company leverages the security and monitoring tools of third-party service providers.
+Added: These processes are integrated into the Company’s overall risk management program and systems, as overseen by the Board, primarily
+Added: through the Audit Committee.
+Added: We maintain physical, technical
+Added: and administrative safeguards to prevent and identify cybersecurity risks, and have implemented practices and procedures to address cybersecurity
To this end, among other things, we:
−Removed: annual mandatory training for our employees regarding cybersecurity threats as a means to
−Removed: equip them with effective tools to address cybersecurity threats, and to communicate our
−Removed: evolving information security policies, standards, processes and practices;
−Removed: regular simulation modules for all employees to enhance awareness and responsiveness to possible
−Removed: cybersecurity management and incident training for employees involved in our systems and
−Removed: processes that handle sensitive data;
−Removed: cyber liability insurance that is intended to provide protection against the potential losses
−Removed: arising from a cybersecurity incident.
−Removed: are currently working with outside counsel to further develop a formal cybersecurity incident response plan.
−Removed: we are regularly exposed to malicious technology-related events and threats, none of these threats or incidents, either individually
−Removed: or in the aggregate of related occurrences, have materially affected the Company in the period covered by this Annual Report on Form
−Removed: In determining materiality, cybersecurity incidents are reviewed not only for potential financial impacts, which could include
−Removed: potential legal and regulatory penalties, stolen assets or funds, system damage, forensic and remediation costs, lost revenue or litigation
−Removed: costs, but also the breadth and sensitivity of data exposure, data exfiltration, impacts on the ability to operate our business or provide
−Removed: our services and loss of investor confidence.
−Removed: Board executes its oversight responsibility for risk management both directly and through delegating oversight of certain of these risks
−Removed: to its committees, and the Board has authorized the Audit Committee to oversee risks related to cybersecurity threats.
−Removed: Our Audit Committee
−Removed: has primary oversight responsibility for cybersecurity and information security risk management and controls.
−Removed: As part of its oversight
−Removed: function, the Audit Committee oversees the Company’s risk assessment and risk management policies, including related to cybersecurity
−Removed: and the overall data protection program.
−Removed: Our senior management is responsible for assessing and managing the
−Removed: Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including the identification
−Removed: of risks through an enterprise risk management framework and the creation of appropriate risk management programs and policies to address
−Removed: The Company’s Senior Manager, IT, has 24 years of experience in enterprise IT and has primary responsibility for managing
−Removed: our cybersecurity program and efforts, and our finance and IT teams are responsible for the testing and audit of our information-technology
−Removed: related internal controls.
−Removed: Item 1A, Risk Factors , for additional information on the Company’s cybersecurity risk profile, in particular the risk factors
−Removed: under the headings entitled “ Risks relating to data privacy could create additional liabilities for us ” and “ Security
−Removed: breaches and other disruptions could compromise our information and expose us to liability, which would cause our business and reputation
+Added: annual mandatory training for our employees regarding cybersecurity threats as a means to equip them with effective tools to address
+Added: cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices;
+Added: regular simulation modules for all employees to enhance awareness and responsiveness to possible threats;
+Added: cybersecurity management and incident training for employees involved in our systems and processes that handle sensitive data;
+Added: cyber liability insurance that is intended to provide protection against the potential losses arising from a cybersecurity incident.
+Added: We are currently working
+Added: with outside counsel to further develop a formal cybersecurity incident response plan as a part of our review of and improvements to
+Added: the Company’s cybersecurity policies.
+Added: While we are regularly exposed
+Added: to malicious technology-related events and threats, none of these, either individually or in the aggregate of related occurrences, have
+Added: materially affected the Company in the period covered by this Annual Report on Form 10-K.
+Added: In determining materiality, cybersecurity incidents
+Added: are reviewed not only for potential financial impacts, which could include potential legal and regulatory penalties, stolen assets or
+Added: funds, system damage, forensic and remediation costs, lost revenue or litigation costs, but also the breadth and sensitivity of data
+Added: exposure, data exfiltration, impacts on the ability to operate our business or provide our services and loss of investor confidence.
+Added: The Board executes its oversight
+Added: responsibility for risk management both directly and through delegating oversight of certain risks to its committees.
+Added: The Board has authorized
+Added: the Audit Committee to oversee risks related to cybersecurity threats.
+Added: Our Audit Committee has primary oversight responsibility for cybersecurity
+Added: and information security risk management and controls.
+Added: As part of its oversight function, the Audit Committee oversees the Company’s
+Added: risk assessment and risk management policies, including related to cybersecurity and the overall data protection program.
+Added: Our senior management is responsible for assessing
+Added: and managing the Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including
+Added: the identification of risks through an enterprise risk management framework and the creation of appropriate risk management programs
+Added: and policies to address such risks.
+Added: In particular, the Company’s Senior Manager, IT, has 24 years of experience in enterprise IT
+Added: and has primary responsibility for managing our cybersecurity program and efforts.
+Added: Our finance and IT teams are responsible for the testing
+Added: and audit of our information-technology related internal controls.
+Added: See Item 1A, Risk Factors ,
+Added: for additional information on the Company’s cybersecurity risk profile, in particular the risk factor under the headings entitled
+Added: “ Risks relating to data privacy could create additional liabilities for us ”.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.