7 unchanged sentences
These processes also include overseeing and identifying risks from cybersecurity threats associated with the use of third-party service providers.
−Removed: The Company’s Chief Digital and eCommerce Officer (CDEO) oversees the Company’s incident response plan and related processes designed to assess and manage material risks from cybersecurity threats.
−Removed: The CDEO is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents pursuant to criteria set forth in the Company’s incident response plan and related processes.
−Removed: The experience of our Response Team includes cybersecurity incident response, in-depth security assessments and security evaluation exercises to evaluate security profile, security research, education and outreach, and security tool development.
−Removed: The Company does not use any third-party consultants for assessment, management or identification of cyber security risks.
−Removed: The Response Team conducts regular internal testing of the Company’s cyber security systems.
+Added: The Company's Senior Director of IT ("SDIT") oversees the Company's incident response plan and related processes designed to assess and manage material risks from cybersecurity threats.
+Added: The SDIT is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents pursuant to criteria set forth in the Company’s incident response plan and related processes.
+Added: The experience of the Company's Response Team includes cybersecurity incident response, in-depth security assessments and security evaluation exercises to evaluate security profile, security research, education and outreach, and security tool development.
+Added: The Company uses a third-party consultant for monitoring, management and identification of cyber security risks.
+Added: The Response Team also conducts regular internal testing of the Company’s cyber security systems.
Board of Directors
5 unchanged sentences
The Company’s Board of Directors has received training on cyber security and governance of the Company’s processes for minimizing threats and response to incidences .
−Removed: The Company’s management, including members of its ERM Committee, the Response Team, and the Company’s CDEO, assess and manage material risks from cybersecurity threats.
+Added: The Company’s management, including members of its ERM Committee, the Response Team, and the Company’s SDIT, assess and manage material risks from cybersecurity threats.
The ERM Committee is responsible for establishing and monitoring the integrity and effectiveness of controls and other procedures, which are designed to ensure that (1) all information required to be disclosed is recorded, processed, summarized, and reported accurately and on a timely basis, and (2) all such information is accumulated and communicated to the Audit Committee, as appropriate, to allow for timely decisions regarding such disclosures.
1 unchanged sentence
Accordingly, the Company’s cybersecurity risk management processes have been integrated into the Company’s overall enterprise risk management processes.
−Removed: The Chief Executive Officer, Chief Financial Officer, Chief Commercial Officer, Chief Operating Officer, and General Counsel comprise the Company’s ERM Committee.
+Added: The Chief Executive Officer, Chief Financial Officer, Chief Operating Officer, and General Counsel comprise the Company’s ERM Committee.
The ERM Committee is responsible for establishing and monitoring the integrity and effectiveness of controls and other procedures, including controls and procedures related to managing material risks from cybersecurity threats, which are designed to ensure that (1) all information required to be disclosed is recorded, processed, summarized, and reported accurately and on a timely basis, and (2) all such information is accumulated and communicated to management and the Audit Committee, as appropriate, to allow for timely decisions regarding such disclosures.
−Removed: The CDEO or a delegate thereof informs the ERM Committee of cybersecurity incidents that may be material pursuant to escalation criteria set forth in the Company’s Cybersecurity Policy and related processes.
−Removed: The CDEO regularly reports to the ERM Committee concerning material risks from cybersecurity threats to the extent necessary pursuant to the escalation criteria set forth in the Company’s processes described herein.
+Added: The SDIT or a delegate thereof informs the ERM Committee of cybersecurity incidents that may be material pursuant to escalation criteria set forth in the Company’s Cybersecurity Policy and related processes.
+Added: The SDIT periodically reports to the ERM Committee concerning material risks from cybersecurity threats to the extent necessary pursuant to the escalation criteria set forth in the Company’s processes described herein.
As of the date of this Annual Report on Form 10-K, the Company is not aware of any cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.