5 unchanged sentences
To this end, we have implemented processes designed to assess, identify and manage risks from potential unauthorized occurrences on or through our information technology systems that may result in adverse effects on the confidentiality, integrity and availability of these systems and the data residing therein.
−Removed: These processes are managed and monitored by a dedicated information technology team, which is led by our Chief Technology Officer (“CTO”), and include mechanisms, controls, technologies, systems and other processes designed to prevent or mitigate data loss, theft, misuse or other security incidents or vulnerabilities affecting the data and maintain a stable information technology environment.
+Added: These processes are managed and monitored by a dedicated information technology team, led by our Chief Information Security Officer (“CISO”), who also serves as our Chief Information Officer, and include mechanisms, controls, technologies, systems and other processes designed to prevent or mitigate data loss, theft, misuse or other security incidents or vulnerabilities affecting the data and maintain a stable information technology environment.
For example, we conduct penetration and vulnerability testing, data recovery testing, security audits and ongoing risk assessments, including due diligence on and audits of our key technology vendors and other contractors and suppliers.
11 unchanged sentences
Despite ongoing efforts to continually improve our and our vendors’ ability to protect against cyber incidents, we may not be able to protect all information systems, and such incidents may lead to reputational harm, revenue and client loss, legal actions and statutory penalties, among other consequences.
−Removed: To date, risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition, and we do not believe that such risks are reasonably likely to have such an effect over the long term.
−Removed: However, there can be no guarantee that we will not be the subject of future successful cybersecurity attacks, threats or incidents that materially affect our business strategy, results of operations or financial condition.
+Added: Based on the information available as of the date of this Annual Report, we believe that risks from cybersecurity threats, including as a result of previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition, and as of the date of this Annual Report, the Company is not aware of any material risks from cybersecurity threats that are reasonably likely to do so.
+Added: However, there can be no guarantee that we will not be the subject of future cybersecurity attacks, threats or incidents that may materially affect our business strategy, results of operations or financial condition.
Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors,” under the heading “Risks Related to Information Technology.”
−Removed: Our CTO, who reports directly to our Chief Executive Officer, is responsible for assessing and managing cybersecurity risks.
−Removed: Our CTO has gained substantial information technology and cybersecurity knowledge from over 25 years of work experience at the Company and elsewhere.
−Removed: Our CTO receives reports on cybersecurity threats from our dedicated information technology team on an ongoing basis and, in conjunction with management, regularly review risk management measures implemented by the Company to identify and mitigate data protection and cybersecurity risks.
−Removed: Our CTO also works closely with our legal and compliance departments to oversee compliance with legal, regulatory and contractual security requirements.
+Added: Our CISO , who reports to our Chief Financial Officer, is responsible for assessing and managing cybersecurity risks.
+Added: Our CISO has over 20 years of experience in cybersecurity, risk management and information security governance and holds Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM) certifications.
+Added: Our CISO receives reports on cybersecurity threats from our dedicated information technology team on an ongoing basis and, in conjunction with management, regularly review risk management measures implemented by the Company to identify and mitigate data protection and cybersecurity risks.
+Added: Our CISO also works closely with our legal and compliance departments to oversee compliance with legal, regulatory and contractual security requirements.
The Board, as a whole and at the committee level, has oversight for the most significant risks facing us and for our processes to identify, prioritize, assess, manage and mitigate those risks.
The Board’s Audit and Compliance Committee, which is comprised solely of independent directors, has been designated by our Board to oversee cybersecurity risks.
−Removed: The Audit and Compliance Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our CTO, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
+Added: The Audit and Compliance Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our CISO, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
The Board also receives updates from management and the Audit and Compliance Committee on cybersecurity risks on at least an annual basis.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.