4 unchanged sentences
We are committed to periodically reviewing these processes internally as well as discussing these threats and our processes with members of our Board as part of our overall cybersecurity risk management system.
−Removed: We have implemented information security policies and standards across the company.
+Added: We have implemented information technology and product security policies and standards across the company.
We provide ongoing cybersecurity training for employees and conduct employee phishing tests.
2 unchanged sentences
We use third-party security tools that help prevent, identify, investigate and resolve vulnerabilities in our systems and products.
−Removed: Certain Ventus offerings are PCI DSS 4.0 compliant, which requires auditing by an external auditor.
+Added: Certain Ventus offerings are PCI DSS 4.0 compliant, and SmartSense and Jolt have achieved SOC 2 Type II attestation.
+Added: These certifications require independent audits by external auditors.
+Added: We are actively pursuing similar certifications for other product lines.
We also have processes to oversee and identify cybersecurity threat risks associated with our use of new third-party service providers, including those who have access to our customer and employee data or our systems.
1 unchanged sentence
However, there can be no assurance that our controls and procedures will be sufficient, and that we will not be materially affected in the future.
−Removed: While we have customary insurance coverage in place designed to address certain cybersecurity risks, such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise.
+Added: While we have customary insurance coverage in place designed to address certain cybersecurity risks,
+Added: such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise.
For more information regarding our cybersecurity risks, see “Technology and Cybersecurity Risks” included as part of our risk factor disclosures in Part I, Item 1A of this report.
5 unchanged sentences
Our Chief Information Officer, who reports to the Chief Executive Officer, has over twenty years of experience in IT, including IT security.
−Removed: In addition, one of our Board members, Hatem Naguib, is the President and Chief Executive Officer of Barracuda, a cybersecurity solutions provider, and brings expertise in IT security.
+Added: In addition, a member of our board of directors, Hatem Naguib, recently retired from his role as President and Chief Executive Officer of Barracuda, a cybersecurity solutions provider, and brings expertise in IT security.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.