22 unchanged sentences
Pursuant to our incident response policy, if we are notified of a cybersecurity incident impacting a third-party service provider that affects our information systems or data, we will respond on the same basis as any other incident.
−Removed: We are implementing a business use case review process and vendor risk assessment for all third-party service providers that will
−Removed: access or implicate our materially significant technology or data.
+Added: We are implementing a business use case review process and vendor risk assessment for all third-party service providers that will access or implicate our materially significant technology or data.
If we deem the cybersecurity risk of a particular service provider too great, such service provider will not be approved or access will be terminated.
−Removed: Based on information known to us, we also do not believe any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: Based on information known to us, we do not believe any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
We can give no assurance that we have detected or protected against all cybersecurity threats or incidents.
1 unchanged sentence
Cybersecurity Governance
−Removed: As described above, we have engaged a third-party IT and cybersecurity firm to whom we have outsourced primary responsibility to oversee, implement and manage our processes and controls to assess, identify, and manage material risks from cybersecurity threats.
+Added: As described above, we have engaged a third-party IT and cybersecurity firm to whom we have outsourced primary responsibility to oversee, implement and manage our processes and controls to assess, identify, and manage material risks from
+Added: cybersecurity threats.
Members of this dedicated third-party IT and cybersecurity team include a virtual chief information security officer (vCISO) who is responsible for the overall development and implementation of our cybersecurity strategy and responses as well as individuals having the position of cybersecurity analyst, cybersecurity engineer, and director of information security.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.