13 unchanged sentences
• Collaborative Approach :
−Removed: Ellington has implemented a cross-functional approach to identifying and evaluating, preventing, mitigating and remediating cybersecurity threats and incidents, while also implementing controls and
−Removed: procedures that provide for the prompt escalation of certain cybersecurity incidents.
+Added: Ellington has implemented a cross-functional approach to identifying and evaluating, preventing, mitigating and remediating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents.
Such escalation allows Ellington to make timely decisions regarding its response to such incidents and whether disclosure to senior management, our Audit Committee and/or the public is appropriate.
18 unchanged sentences
These meetings cover a broad range of topics including implementation planning for the deployment of new hardware and software, patch and vulnerability management, considerations for disaster recovery and business continuity, user access controls, data security and more.
−Removed: In such continued monitoring of its cybersecurity posture, Ellington conducts continuous depreciation of obsolete or unsuitable technology, including legacy hardware and software, has a robust patch and vulnerability management process, and has personnel dedicated to the continued monitoring of new developments in threat actors’ activities in order to take preventative actions.
+Added: In such continued monitoring of its cybersecurity posture, Ellington conducts continuous deprecation of obsolete or unsuitable technology, including legacy hardware and software, has a robust patch and vulnerability management process, and has personnel dedicated to the continued monitoring of new developments in threat actors’ activities in order to take preventative actions.
Ellington also regularly engages third parties to perform assessments of Ellington’s cybersecurity posture, including penetration testing, user access control reviews and independent reviews of Ellington’s information security control environment, and operating effectiveness.
1 unchanged sentence
To date, no risks from cybersecurity threats to Ellington have materially affected or are reasonably likely to materially affect the Company.
+Added: Cyber criminals do, however, target us, Ellington and Ellington’s employees and other third parties.
+Added: Ongoing or future attacks such as these could have impacts on our or Ellington’s operations.
+Added: For additional information on these ongoing risks, please refer to "Part 1.
+Added: Risk Factors—We are highly dependent on Ellington's information systems and those of third-party service providers, including mortgage servicers, and system failures could significantly disrupt our business, which could materially adversely affect our business, financial condition and results of operations, and our ability to pay dividends to our shareholders." and "—Because we are highly dependent on information systems when sharing information with third party service providers, systems failures, breaches or cyber-attacks could significantly disrupt our business, which could have a material adverse effect on our results of operations and cash flows."
While Ellington did experience two business email compromise incidents in recent years, neither had a material impact on our business strategy, results of operations or financial condition.
2 unchanged sentences
Ellington employs internal or external resources whose responsibilities include oversight of their respective firm’s cybersecurity posture.
−Removed: Ellington's cybersecurity team is lead by Ellington's outsourced Chief Technology Officer (the "CTO"), who is primarily responsible for assessing and managing material risks from cybersecurity threats to Ellington.
+Added: Ellington's cybersecurity team is led by Ellington's Chief Technology Officer (the "CTO"), who is primarily responsible for assessing and managing material risks from cybersecurity threats to Ellington.
The CTO has extensive experience in application development, database architecture, systems design, and third-party software integration.
−Removed: During his tenure at Ellington, the CTO has lead large technical efforts such as the development of Ellington’s proprietary whole loan management system and the overhaul of Ellington’s engineering infrastructure and development services.
+Added: During his tenure at Ellington, the CTO has led large technical efforts such as the development of Ellington’s proprietary internally hosted rapid application system and the overhaul of Ellington's engineering infrastructure and development services.
The CTO works closely with Ellington’s head of Data Platform and Infrastructure (the "DPI Head") to manage Ellington’s infrastructure and cybersecurity posture.
−Removed: During his tenure at Ellington, the DPI Head has lead several critical efforts such as the revitalization of Ellington’s hardware, networking and disaster recovery facilities, major improvements to Ellington’s cybersecurity infrastructure, and the development and maintenance of Ellington’s Data Engineering infrastructure.
+Added: During his tenure at Ellington, the DPI Head has led several critical efforts such as the revitalization of Ellington’s hardware, networking and disaster recovery facilities, major improvements to Ellington’s cybersecurity infrastructure, and the development and maintenance of Ellington’s Data Engineering infrastructure.
Ellington’s Senior Systems Administrator (the "SSA") works closely with both the CTO and the DPI Head to implement Ellington’s cybersecurity program and infrastructure.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.