4 unchanged sentences
We have implemented processes for assessing, identifying and managing material risks from cybersecurity threats as part of our overall risk management program.
−Removed: Our cybersecurity program is informed by the National Institute of Standards and Technology Cybersecurity Framework as well as other globally recognized standards.
+Added: Our cybersecurity program is informed by the National Institute of Standards and Technology Cybersecurity Framework and other applicable globally recognized standards.
We use a layered defense model, incorporating a wide range of technologies and practices in an effort to prevent, detect and mitigate threats.
−Removed: These measures include intrusion detection and prevention systems, multi-factor authentication, encryption and endpoint protection tools.
+Added: These measures include intrusion detection and prevention systems, multi-factor authentication, account management and access controls, encryption and endpoint protection tools.
We also implement threat detection and response solutions.
−Removed: To address emerging threats, we employ automated monitoring, vulnerability scans and patch management processes.
+Added: To address emerging threats, we employ automated monitoring, vulnerability scans and patch management processes, network monitoring and defenses, antivirus/antimalware protections and network segmentations.
Regular assessments, such as penetration tests, security audits and table-top exercises, are conducted to identify vulnerabilities and promote incident response and risk mitigation.
We also provide privacy and information security trainings for our employees on a recurring basis.
−Removed: From time to time, we engage assessors, consultants and other third parties to assist with assessing, identifying and managing cybersecurity risks, including assisting us to conduct some of the foregoing assessments.
−Removed: Our cybersecurity risk management processes also are informed by intelligence received from recognized cybersecurity industry experts and other third-party sources, and as appropriate we engage outside counsel to advise on regulatory compliance and other cybersecurity risk management efforts.
+Added: From time to time, we engage auditors, assessors, consultants and other third parties to assist with assessing, identifying and managing cybersecurity risks, including assisting us to conduct some of the foregoing assessments.
+Added: Our cybersecurity risk management processes also are informed by intelligence received from law enforcement and other governmental agencies, private sector intelligence networks, recognized cybersecurity and intelligence firms and other third-party sources, and as appropriate we engage outside counsel to advise on regulatory compliance and other cybersecurity risk management efforts.
In addition, we have processes designed to oversee and identify cybersecurity risks associated with our use of third-party service providers.
Where appropriate based on the data and intellectual property to which these providers are reasonably expected to have access, we conduct security assessments and due diligence reviews of third-party systems for compliance with our security standards, and we include data protection language in our agreements with these third parties.
−Removed: Further, as part of our cybersecurity risk management processes, we maintain an incident response plan (IRP) that establishes a set of procedures for reporting and handling cybersecurity events.
−Removed: The IRP delegates to an internal incident response team the initial assessment, investigation and remediation of the event and includes, among other procedures, guidelines for escalation to senior management and engagement with law enforcement.
−Removed: In certain instances, events are escalated to the Cybersecurity Incident Disclosure Subcommittee, which is a subcommittee of the Company’s Risk Management Committee (RMC) (discussed further below) and is responsible for, among other things, the accurate and timely disclosure of
−Removed: material cybersecurity incidents under the federal securities laws, including making the materiality determination and approving related securities disclosures.
+Added: Further, as part of our cybersecurity risk management processes, we maintain a cybersecurity incident response plan (CIRP) that establishes a set of procedures for reporting and handling cybersecurity events.
+Added: The CIRP delegates to an internal incident response team the initial assessment, investigation and remediation of the event and includes, among other procedures, guidelines for escalation to senior management and engagement with law enforcement.
+Added: In certain instances, events are escalated to the Cybersecurity Incident Disclosure Subcommittee, which is a subcommittee of the Company’s Risk Management Committee (RMC) (discussed further below) and is responsible for, among other things, the accurate and timely disclosure of material cybersecurity incidents under the federal securities laws, including making the materiality determination and approving related securities disclosures.
As discussed in further detail in Item 1A – Risk Factors, the Company faces an increasingly challenging cybersecurity environment, and from time to time the persistent efforts of bad actors to gain unauthorized access to our and our service providers’ information systems and our confidential and proprietary information are successful.
4 unchanged sentences
The Chair of the Audit Committee reports on its discussion, including concerning cybersecurity matters, to the full Board.
−Removed: In addition, from time to time, senior management briefs the Audit Committee, the Audit Committee Chair and the Board on cybersecurity matters potentially of interest, including cybersecurity events, regulatory disclosures and regulatory trends.
−Removed: Day-to-day management of our information security strategy and operations is currently the responsibility of our CISO, who reports into our Chief Financial Officer.
−Removed: Prior to joining the Company, our CISO held senior leadership roles in various other organizations, including as CISO for a publicly traded, global retailer and as a consultant advising organizations on information security strategy, and as a Special Agent with the U.S.
−Removed: Secret Service focusing on electronic crimes.
+Added: addition, from time to time, senior management briefs the Audit Committee, the Audit Committee Chair and the Board on cybersecurity matters potentially of interest, including cybersecurity events, regulatory disclosures and regulatory trends.
+Added: Day-to-day management of our information security strategy and operations is currently the responsibility of our CISO, who reports to our Chief Information and Data Officer and our Chief Security Officer, both of whom report to our Chief Financial Officer.
+Added: Our CISO has approximately 15 years of experience working in information security positions, including having served as CISO for publicly traded companies.
That experience is supplemented by the collective experience and expertise of our dedicated internal teams of cybersecurity personnel.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.