3 unchanged sentences
We recognize the importance of developing, implementing and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity and availability of our data.
+Added: Civeo leverages controls modeled in the Center for Internet Security (CIS) and the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) to evaluate our cybersecurity capabilities and to inform the implementation and configuration of certain systems, processes, and technologies.
Our processes for assessing, identifying, and managing material risks from cybersecurity threats have been integrated into our overall risk management system and processes.
−Removed: Cybersecurity events are collected, evaluated and, when appropriate, escalated to the Chief Information Security Officer (CISO) for impact analysis utilizing the cybersecurity risk management policy.
−Removed: Cybersecurity risks are monitored and evaluated by management through an internal compliance program with oversight by internal audit.
−Removed: We engage a variety of cybersecurity partners to perform penetration testing and quarterly audits on our cybersecurity profile.
−Removed: These partnerships enable us to leverage specialized knowledge and insights, and are meant to help our cybersecurity strategies and processes in remaining risk appropriate.
−Removed: In order to promote a company-wide culture of cybersecurity risk management, management has also implemented a variety of required programs to both test and train our employees on cybersecurity fundamentals, including both annual and ongoing information security awareness training.
+Added: Cybersecurity events are collected, evaluated and, when appropriate, escalated to the Chief Information Security Officer (CISO) for impact analysis utilizing our cybersecurity risk management policy.
Our cybersecurity policies and procedures encompass data privacy, incident response, information security and risks from our use of third-party vendors.
−Removed: In order to help develop these policies and procedures, we monitor the privacy and cybersecurity laws, regulations and guidance applicable to us in the regions where we do business, as well as proposed privacy and cybersecurity laws, regulations, guidance and emerging risks.
−Removed: We also have conducted a cyber breach simulation exercise with the assistance of a third party cybersecurity consultant.
−Removed: The exercise focused on incident management and communication processes.
−Removed: Company business functions, executive management and members of the Board participated.
−Removed: The goal was to identify opportunities for greater efficiency, coordination, and alignment.
−Removed: We face risks from various security threats, including cybersecurity threats to gain unauthorized access to sensitive information or to render data or systems unusable or hold them for ransom.
−Removed: Cybersecurity attacks in particular develop and evolve rapidly, including from emerging technologies, such as advanced forms of artificial intelligence.
−Removed: Such attacks include, but are not limited to, malicious software, attempts to gain unauthorized access to data, ransomware attacks and other electronic security breaches that could lead to disruptions in critical systems, unauthorized release of or denial of access to confidential or otherwise protected information and corruption of data.
−Removed: We have experienced, and expect to continue to confront, efforts by hackers and other third parties to gain unauthorized access or deny access to, or otherwise disrupt, our information systems and networks.
+Added: In order to help develop these policies and procedures, we monitor applicable privacy and cybersecurity laws, regulations and guidance in the regions where we do business, as well as proposed privacy and cybersecurity laws, regulations, guidance and emerging risks.
+Added: Cybersecurity risks are monitored and evaluated by management through an internal compliance program with oversight by internal audit.
+Added: We engage various third-party cybersecurity partners , such as auditors, assessors and consultants to perform penetration testing and audits on our cybersecurity profile.
+Added: With the assistance of a third-party cybersecurity consultant, we also conducted three cyber breach simulation exercises in the last five quarters, focused on incident management and communication processes.
+Added: These third-party partnerships enable us to leverage specialized knowledge and insights, and are meant to ensure our cybersecurity strategies and processes remain appropriately tailored to the company’s risk profile.
+Added: In order to promote a company-wide culture of cybersecurity risk management, management has also implemented programs to both test and train our employees on cybersecurity fundamentals, including both annual and ongoing information security awareness training.
Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations, or financial condition, but we face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to have such an affect.
1 unchanged sentence
As discussed in Part I, Item 1A, “Risk Factors,” under the heading “Financial/Accounting Risks – We may not have adequate insurance for potential liabilities and insurance may not cover certain liabilities,” we maintain cyber risk insurance to mitigate our exposure to these threats.
−Removed: Risk oversight is a responsibility of the Board.
−Removed: The Board has delegated responsibility for monitoring technology and cybersecurity risks to the Audit Committee.
+Added: While the Board maintains responsibility for risk oversight it has delegated responsibility for evaluating technology and cybersecurity risks to the Audit Committee .
The Board reviews the Company's cybersecurity risk posture, strategy and execution on at least an annual basis while the Audit Committee receives cybersecurity updates quarterly.
The CISO and executive management play a pivotal role in informing the Audit Committee on cybersecurity risks.
−Removed: Executive management, including the CISO, regularly meets with the Audit Committee to discuss cybersecurity risks, review quarterly cyber metrics and oversee progress against our annual action plans.
+Added: Executive management, including the CISO, meets regularly with the Audit Committee to discuss cybersecurity risks, review
+Added: quarterly cyber metrics and oversee progress against our annual action plans.
These briefings may encompass a broad range of topics, including:
3 unchanged sentences
• Compliance with regulatory requirements and industry standards.
−Removed: In addition to our scheduled meetings, the Audit Committee and executive management maintain an ongoing dialogue regarding emerging or potential cybersecurity risks.
−Removed: Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with the CISO.
−Removed: Our CISO has cybersecurity expertise from over 18 years of experience in the field of cybersecurity.
−Removed: His background includes extensive experience as CISO at Civeo and previously for a Fortune 500 company.
−Removed: He also oversees our cybersecurity governance programs, assists with testing our compliance with applicable standards, leads our efforts to remediate known risks and leads our employee training program.
−Removed: The CISO is informed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques.
−Removed: The CISO implements and oversees processes for the monitoring of our information systems.
−Removed: This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities.
−Removed: The Company deploys a Security Operations Center team who monitor and escalate cybersecurity events.
−Removed: In the event of a cybersecurity incident, the CISO is equipped with an incident response plan, which is intended to mitigate the impact of the incident and includes long-term strategies for remediation and prevention of future incidents.
−Removed: The CISO regularly updates executive management on cybersecurity risks and incidents.
+Added: In addition to our scheduled meetings, the Audit Committee and executive management maintain an ongoing dialogue regarding emerging or potential cybersecurity risks, and the CISO regularly updates executive management on cybersecurity risks and incidents.
+Added: Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with the CISO who has over 18 years of experience in the field of cybersecurity, including at Civeo and previously for a Fortune 500 company.
+Added: The CISO implements and oversees processes for the monitoring of our information systems, which includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities.
+Added: The CISO also oversees our cybersecurity governance programs, assists with testing our compliance with applicable standards, leads our efforts to remediate known risks and leads our employee training program.
+Added: The Company deploys a Security Operations Center team who monitor and escalate cybersecurity events to the CISO.
+Added: In the event of a cybersecurity incident, the Company maintains an incident response plan, which is intended to facilitate response, escalation, and mitigate the impact of the incident and includes long-term strategies for remediation and prevention of future incidents.
Significant cybersecurity matters and certain strategic risk management decisions are escalated to the Audit Committee and the Board.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.