2 unchanged sentences
As discussed further in "Item 1.
−Removed: Business—Our Manager and Ellington," we are externally managed and advised by our Manager, an affiliate of Ellington.
−Removed: Our Manager does not have any employees and instead relies on the employees of Ellington to fulfill its obligations to us pursuant to a services agreement.
+Added: Business—Our Adviser and Ellington," we are externally managed and advised by our Adviser, an affiliate of Ellington.
+Added: Our Adviser does not have any employees and instead relies on the employees of Ellington to fulfill its obligations to us pursuant to a services agreement.
We rely on Ellington's information systems in conducting our day-to-day operations.
5 unchanged sentences
• Governance :
−Removed: As discussed in more detail below under "Governance," our Board of Trustees' oversight of cybersecurity risk management is supported by the Audit Committee of our Board of Trustees (the “Audit Committee”), which regularly interacts with our management team and other professionals who are responsible for assessing and managing material risks from cybersecurity threats at Ellington.
+Added: As discussed in more detail below under "Governance," our Board's oversight of cybersecurity risk management is supported by the Audit Committee of our Board (the “Audit Committee”), which regularly interacts with our management team and other professionals who are responsible for assessing and managing material risks from cybersecurity threats at Ellington.
• Collaborative Approach :
3 unchanged sentences
Ellington deploys technical safeguards that are designed to protect information systems from cybersecurity threats.
−Removed: These systems cover many facets of cyber security including identity protection, anti-virus and anti-malware defense, data loss prevention, endpoint protection (including managed detection and response services), patch and vulnerability management and others.
+Added: These systems cover many facets of cyber security including identity protection, anti-virus and anti-malware defense, data loss prevention, endpoint protection (including managed detection and response services),
+Added: patch and vulnerability management and others.
Ellington regularly evaluates new technologies as the cyber security landscape evolves.
16 unchanged sentences
Ellington also regularly engages third parties to perform assessments of Ellington’s cybersecurity posture, including penetration testing, user access control reviews and independent reviews of Ellington’s information security control environment, and operating effectiveness.
−Removed: The results of such assessments, tests and reviews are reported to the Audit Committee and our Board of Trustees, and Ellington adjusts its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, tests and reviews, including the implementation of new software and technologies.
−Removed: To date, no risks from cybersecurity threats to Ellington have materially affected or are reasonably likely to materially affect the Company.
+Added: The results of such assessments, tests and reviews are reported to the Audit Committee and our Board, and Ellington adjusts its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, tests and reviews, including the implementation of new software and technologies.
+Added: To date, no risks from cybersecurity threats to Ellington have materially affected or are reasonably likely to materially affect us.
Cyber criminals do, however, target us, Ellington and Ellington’s employees and other third parties.
3 unchanged sentences
While Ellington did experience two business email compromise incidents in recent years, neither had a material impact on our business strategy, results of operations or financial condition.
−Removed: Our Board of Trustees, through the Audit Committee, oversees our cybersecurity risk management process.
+Added: Our Board, through the Audit Committee, oversees our cybersecurity risk management process.
Our Audit Committee receives regular presentations and reports on cybersecurity risks at Ellington, each of which addresses a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
11 unchanged sentences
The CTO's reports cover a range of topics including, at various times, a discussion of the primary cybersecurity risks facing Ellington, an overview of Ellington’s cybersecurity program, common attack vectors and types, the primary functions of Ellington’s cybersecurity program, how Ellington’s cybersecurity programs are applied to critical cybersecurity areas, any recent cybersecurity incidents, Ellington’s ongoing focus areas in its cybersecurity program, Ellington’s employee education program, management of patches and system vulnerabilities, various threat detection methods, malicious activity monitoring, any new cybersecurity focus areas for Ellington, a review of Ellington’s key technologies, Ellington’s incident response procedures and Ellington’s backup systems and redundancy and disaster recovery processes.
+Added: We do not own any properties.
+Added: Our principal offices are located in leased space at 53 Forest Avenue, Old Greenwich, CT 06870.
+Added: The offices of our Adviser and Ellington are at the same location.
+Added: As part of our Advisory Agreement, our Adviser is responsible for providing offices necessary for all operations, and accordingly, all lease responsibilities belong to our Adviser.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.