1 unchanged sentence
CYBERSECURITY
−Removed: Company has developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and
−Removed: availability of our critical systems and information.
−Removed: We designed and assessed our cybersecurity risk based on the Payment Card Industry
−Removed: Data Security Standard (PCI DSS).
−Removed: This does not imply that we meet any particular technical standards, specifications, or requirements,
−Removed: only that we use these frameworks as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: cybersecurity risk management program is integrated into our overall enterprise risk management program and shares common methodologies,
−Removed: reporting channels, and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic,
−Removed: operational, and financial risk areas.
+Added: The Company has developed
+Added: and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical
+Added: systems and information.
+Added: We designed and assessed our cybersecurity risk based on the Payment Card Industry Data Security Standard (PCI
+Added: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use these frameworks
+Added: as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: Our cybersecurity risk management
+Added: program is integrated into our overall enterprise risk management program and shares common methodologies, reporting channels, and governance
+Added: processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk
Our cybersecurity risk management program includes:
−Removed: assessments that are designed to help identify material cybersecurity risks to our critical systems and information.
−Removed: security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3)
−Removed: our response to cybersecurity incidents.
−Removed: use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls.
−Removed: ● Cybersecurity
−Removed: awareness training of our employees, including our incident response personnel.
−Removed: cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
−Removed: have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially
−Removed: affected the Company, including our operations, business strategy, results of operations, or financial condition.
−Removed: We face risks from
−Removed: cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy,
−Removed: results of operations, or financial condition.
−Removed: Cybersecurity
−Removed: Board considers cybersecurity risk as part of its risk oversight function and has delegated oversight of cybersecurity and other information
−Removed: technology risks to the Company’s Chief Executive Officer and Chief Financial Officer , who oversee management’s implementation
−Removed: of our cybersecurity risk management program and incident response plans.
−Removed: management team and incident response team have overall responsibility for assessing and managing our material risks from cybersecurity
−Removed: The team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity
−Removed: personnel and our retained external cybersecurity consultants that conduct vulnerability scans on a quarterly basis per PCI DSS standards.
−Removed: While cyber-attacks are common threats to all businesses, the Company did not experience a material cyber security incident in either
−Removed: fiscal year 2025 or 2024.
−Removed: management team is informed about and monitors the prevention, detection, mitigation, and remediation of key cybersecurity risks and
−Removed: incidents through various means.
−Removed: This may include briefings from internal security personnel, threat intelligence and other information
−Removed: obtained from governmental, public, or private sources, including external consultants engaged by us, and alerts and reports produced
−Removed: by security tools deployed in the information technology environment.
+Added: Risk assessments that are designed to help identify material cybersecurity risks to our critical systems and information.
+Added: A security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents.
+Added: The use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls.
+Added: Cybersecurity awareness training of our employees, including our incident response personnel.
+Added: A cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
+Added: We have not identified risks
+Added: from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected the Company,
+Added: including our operations, business strategy, results of operations, or financial condition.
+Added: We face risks from cybersecurity threats that,
+Added: if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial
+Added: Cybersecurity Governance
+Added: Our Board considers cybersecurity
+Added: risk as part of its risk oversight function and has delegated oversight of cybersecurity and other information technology risks to the
+Added: Company’s Chief Executive Officer and Chief Financial Officer , who oversee management’s implementation of our cybersecurity
+Added: risk management program and incident response plans.
+Added: Our management team and incident
+Added: response team have overall responsibility for assessing and managing our material risks from cybersecurity threats.
+Added: The team has primary
+Added: responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our
+Added: retained external cybersecurity consultants that conduct vulnerability scans on a quarterly basis per PCI DSS standards.
+Added: While cyber-attacks
+Added: are common threats to all businesses, the Company did not experience a material cyber security incident in either fiscal year 2026 or
+Added: Our management team is informed
+Added: about and monitors the prevention, detection, mitigation, and remediation of key cybersecurity risks and incidents through various means.
+Added: This may include briefings from internal security personnel, threat intelligence and other information obtained from governmental, public,
+Added: or private sources, including external consultants engaged by us, and alerts and reports produced by security tools deployed in the information
+Added: technology environment.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.