3 unchanged sentences
Managing Material Risks & Integrated Overall Risk Management
−Removed: We are developing processes, including those intended to follow an internal Information Technology (IT) Security Policy, which seek to assess, identify, and manage material risks from cybersecurity threats to the IT systems and information that we create, use, transmit, receive, and maintain.
+Added: We have developed and continue to develop processes , including those intended to follow an internal Information Technology (IT) Security Policy, which seek to assess, identify, and manage material risks from cybersecurity threats to the IT systems and information that we create, use, transmit, receive, and maintain.
We also seek to integrate these processes and policies into our overall enterprise risk management system and processes.
11 unchanged sentences
However, as discussed under “Risk Factors” in Part I, Item 1A of this Annual Report, cybersecurity threats pose multiple and potentially material risks to us, including potentially to our results of operations and financial condition.
−Removed: See “Risk Factors — Failure to protect our information technology infrastructure against cyber-based attacks, network security breaches, service interruptions, or data corruption could significantly disrupt our operations and adversely affect our business strategy and operating results.” As cybersecurity threats become more frequent, sophisticated, and coordinated, it is reasonably likely that we may expend greater resources to continue to modify and enhance protective measures against such security risks.
+Added: See also “Risk Factors — Failure to protect our information technology infrastructure against cyber-based attacks, network security breaches, service interruptions, or data corruption could significantly disrupt our operations and adversely affect our business strategy and operating results.” As cybersecurity threats become more frequent, sophisticated, and coordinated, it is reasonably likely that we may expend greater resources to continue to modify and enhance protective measures against such security risks.
Board of Directors Oversight
3 unchanged sentences
The Audit Committee reports to the Board as necessary with respect to its activities, including making such reports and recommendations to the Board as it deems necessary and appropriate.
−Removed: Management’s Role Managing Risk
−Removed: The role of the Chief Information Security Officer (CISO) has been assigned to our VP, Information Technology, who has 20 years of IT experience and reports to the CFO.
−Removed: The CISO and the CFO inform the Audit Committee on cybersecurity risks.
−Removed: They provide briefings to the Audit Committee on no less than an annual basis or on an ad hoc basis when needed.
−Removed: These briefings encompass:
−Removed: Evaluation of existing cybersecurity risks;
−Removed: Status of ongoing cybersecurity initiatives and strategies from the cybersecurity roadmap;
−Removed: Incident reports and learnings from cybersecurity events.
Risk Management Personnel
14 unchanged sentences
Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the Board of Directors, which has oversight and may provide guidance on critical cybersecurity issues.
+Added: Management’s Role Managing Risk
+Added: The role of the Chief Information Security Officer (CISO) has been assigned to our VP, Information Technology, who has more than 20 years of IT experience and reports to the CFO.
+Added: The CISO and the CFO inform the Audit Committee on cybersecurity risks.
+Added: They provide briefings to the Audit Committee on no less than an annual basis or on an ad hoc basis when needed.
+Added: These briefings encompass:
+Added: Evaluation of existing cybersecurity risks;
+Added: Status of ongoing cybersecurity initiatives and strategies from the cybersecurity roadmap ;
+Added: Incident reports and learnings from cybersecurity events.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.