−Removed: STAFF COMMENTS
−Removed: CYBERSECURITY
+Added: UNRESOLVED STAFF COMMENTS
CYBERSECURITY
1 unchanged sentence
risk management is an important part of our overall risk management efforts.
−Removed: We maintain a cybersecurity program that is comprised
−Removed: of policies, procedures, controls and plans whose objective is to help us prevent and effectively respond to cybersecurity threats
−Removed: or incidents.
−Removed: Through our cybersecurity risk management process, we continuously monitor cybersecurity vulnerabilities and potential
−Removed: attack vectors to company systems.
−Removed: We maintain various measures to safeguard against cybersecurity threats such as monitoring
−Removed: systems, security controls, policy enforcement, data encryption, employee training, tools and services from third-party providers
−Removed: and management oversight to assess, identify and mitigate risks from cybersecurity threats.
−Removed: We conduct regular testing of these
−Removed: controls and systems including vulnerability scanning, penetration testing and simulating the execution of parts of our disaster
−Removed: recovery plan.
−Removed: All employees are required to pass a mandatory cybersecurity training course on an annual basis and we regularly
−Removed: conduct phishing simulations to train our employees on how to recognize phishing attempts.
+Added: We maintain a cybersecurity program that is comprised of
+Added: policies, procedures, controls and plans whose objective is to help us prevent and effectively respond to cybersecurity threats or incidents.
+Added: Through our cybersecurity risk management process, we continuously monitor cybersecurity vulnerabilities and potential attack vectors
+Added: to company systems.
+Added: We maintain various measures to safeguard against cybersecurity threats such as monitoring systems, security controls,
+Added: policy enforcement, data encryption, employee training, tools and services from third-party providers and management oversight to assess,
+Added: identify and mitigate risks from cybersecurity threats.
+Added: We conduct regular testing of these controls and systems including vulnerability
+Added: scanning, penetration testing and simulating the execution of parts of our disaster recovery plan.
+Added: All employees are required to pass
+Added: a mandatory cybersecurity training course on a regular basis and we regularly conduct phishing simulations to train our employees on
+Added: how to recognize phishing attempts.
have implemented cybersecurity frameworks, policies and practices which incorporate industry-standards and contractual requirements.
−Removed: We also contractually flow cybersecurity regulatory requirements to our subcontractors as required by the Defense Federal Acquisition
−Removed: Regulation Supplement and other government agency specific requirements.
−Removed: These contractual flow downs include the requirement
−Removed: that our subcontractors implement certain information security controls.
−Removed: Additionally, we gather information and review the SOC-2
−Removed: reports of certain third-parties who integrate with our systems, such as our payroll processor, managed solutions provider and
−Removed: software as a service providers on an annual basis to identify and manage risk.
−Removed: We continuously evaluate and seek to improve and
−Removed: mature our cybersecurity processes.
−Removed: We apply lessons learned from our defense and monitoring efforts to help prevent future attacks
−Removed: and utilize data analytics to detect anomalies and search for cyber threats.
−Removed: Additionally, our Internal Audit function regularly
−Removed: assesses our program effectiveness through audits of systems and processes to help maintain compliance with policies.
+Added: We gather information and review the SOC-2 reports of certain third parties who integrate with our systems, such as our payroll processor,
+Added: managed solutions provider and software as a service provider on an annual basis to identify and manage risk.
+Added: We continuously evaluate
+Added: and seek to improve and mature our cybersecurity processes.
+Added: We apply lessons learned from our defense and monitoring efforts to help
+Added: prevent future attacks and utilize data analytics to detect anomalies and search for cyber threats.
+Added: Additionally, our Internal Audit
+Added: function regularly assesses our program effectiveness through audits of systems and processes to help maintain compliance with policies.
Cybersecurity
−Removed: threats of all types, such as attacks from computer hackers, cyber criminals, nation-state actors, social engineering and other
−Removed: malicious internet-based activities, continue to increase.
−Removed: We believe that our current preventative actions and response planning
−Removed: provide adequate measures of protection against cybersecurity risks.
−Removed: While we have implemented measures to safeguard our information
−Removed: technology systems, the evolving nature of cybersecurity attacks and vulnerabilities means that these protections may not always
−Removed: be effective.
−Removed: In 2024, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to
−Removed: materially affect our business strategy, results of operations, or financial condition.
−Removed: However, despite our efforts, we cannot
−Removed: eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced undetected cybersecurity incidents.
−Removed: For additional information about these risks, see Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K.
−Removed: board of directors has oversight of our strategic and business risk management and oversees management’s execution of our
−Removed: cybersecurity risk management program.
+Added: threats of all types, such as attacks from computer hackers, cyber criminals, nation-state actors, social engineering and other malicious
+Added: internet-based activities, continue to increase.
+Added: We believe that our current preventative actions and response planning provide adequate
+Added: measures of protection against cybersecurity risks.
+Added: While we have implemented measures to safeguard our information technology systems,
+Added: the evolving nature of cybersecurity attacks and vulnerabilities means that these protections may not always be effective.
+Added: did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy,
+Added: results of operations, or financial condition.
+Added: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats,
+Added: or provide assurances that we have not experienced undetected cybersecurity incidents.
+Added: For additional information about these risks,
+Added: see Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K.
+Added: board of directors has oversight of our strategic and business risk management and oversees management’s execution of our cybersecurity
+Added: risk management program.
The board receives regular updates from management on our cybersecurity risks.
−Removed: management updates the board as necessary, regarding any material cybersecurity incidents, as well as incidents with lesser impact
−Removed: Management is responsible for identifying, assessing, and managing cybersecurity risks on an ongoing basis, establishing
−Removed: processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures,
−Removed: maintaining cybersecurity policies and procedures, and providing regular reports to our board of directors.
−Removed: In the event of an
−Removed: incident, we intend to follow our incident response plan, which outlines the steps to be followed from incident detection to mitigation,
−Removed: recovery and notification, including notifying functional areas (e.g.
−Removed: legal), as well as senior leadership and the board, as appropriate.
+Added: In addition, management updates
+Added: the board as necessary, regarding any material cybersecurity incidents, as well as incidents with lesser impact potential.
+Added: is responsible for identifying, assessing, and managing cybersecurity risks on an ongoing basis, establishing processes to ensure that
+Added: such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity
+Added: policies and procedures, and providing regular reports to our board of directors.
+Added: In the event of an incident, we intend to follow our
+Added: incident response plan, which outlines the steps to be followed from incident detection to mitigation, recovery and notification, including
+Added: notifying functional areas, as well as senior leadership and the board, as appropriate.
Director of Information Technology leads our cybersecurity program and is responsible for our overall information security strategy,
policy, security engineering, operations and cyber threat detection and response.
−Removed: The Director of Information Technology manages
−Removed: a team of information technology professionals with broad experience, including in cybersecurity threat assessments and detection,
−Removed: mitigation technologies, incident response, insider threats and regulatory compliance.
−Removed: Our Director of Information Technology
−Removed: brings extensive experience in cybersecurity, including conducting DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)
−Removed: audit and overseeing NIST (National Institute of Standards and Technology) internal audits.
−Removed: This expertise ensures our organization
−Removed: aligns with strict industry standards and maintains robust compliance measures.
−Removed: cybersecurity program is regularly assessed through management self-evaluation and ongoing monitoring procedures to evaluate our
−Removed: program effectiveness, including assessments associated with internal controls over financial reporting as well as vulnerability
−Removed: management through active discovery and testing to validate patching and configuration.
+Added: The Director of Information Technology manages a team
+Added: of information technology professionals with broad experience, including in cybersecurity threat assessments and detection, mitigation
+Added: technologies, incident response, insider threats and regulatory compliance.
+Added: Our Director of Information Technology brings extensive experience
+Added: in cybersecurity, including conducting DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) audits and overseeing NIST (National
+Added: Institute of Standards and Technology) internal audits.
+Added: This expertise ensures our organization aligns with strict industry standards
+Added: and maintains robust compliance measures.
+Added: cybersecurity program is aligned with NIST SP 800-171 and the requirements of the Cybersecurity Maturity Model Certification (CMMC) applicable
+Added: to our Department of Defense (DOD) contracts and when flowed down through prime contractors.
+Added: We are currently in the process of achieving
+Added: CMMC Level 2.0 certification.
+Added: Our program includes policies, procedures and controls design to safeguard controlled unclassified information
+Added: and to detect, respond to, and recover from cybersecurity incidents.
+Added: We continue to invest in cybersecurity capabilities and third-party
+Added: assessments to support ongoing compliance.
+Added: We also contractually flow CMMC requirements to our subcontractors as required by the Defense
+Added: Federal Acquisition Regulation Supplement.
+Added: Failure to achieve or maintain these requirements could adversely affect our ability to perform
+Added: on or compete for certain government contracts.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.