1 unchanged sentence
CYBERSECURITY
−Removed: Cybersecurity is an integral part of the Board’s risk analysis and discussions with management.
−Removed: At least annually, the full Board is updated on the Company’s cybersecurity risks and risk mitigation strategy by our Director of Operations & Information Technology, who is responsible for management of our Information Technology program.
−Removed: The Board also receives ad hoc updates, as needed, about material changes to the Company’s cybersecurity program and/or the cybersecurity landscape, including briefings on major legislative and regulatory developments, from our Director of Operations & Information Technology.
−Removed: Our Director of Operations & Information Technology regularly evaluates the Company’s cybersecurity risk profile and leads the development of strategies to mitigate risks and address cybersecurity issues that may arise, in consultation with members of our senior management team.
−Removed: Our Director of Operations & Information Technology has approximately 20 years of experience in his field, and Bachelor of Science in Information Technology Concentration in Information Systems Security and an MBA in Business Analytics.
−Removed: We have formal policies and procedures that address cybersecurity incident response and disaster recovery from interference with our critical applications.
−Removed: The Cybersecurity Incident Response Plan, designed for our business environment, features the Director of IT and Operations as the incident coordinator.
−Removed: In the event of any suspicious activity or security breach, Energy Focus swiftly conducts an assessment to gauge the severity and scope of the incident, employing thorough investigation techniques to identify the root cause and affected systems.
−Removed: Immediate containment measures are then executed to prevent further unauthorized access or damage.
−Removed: Throughout the incident response process, transparent and timely communication is upheld with internal stakeholders and relevant external parties, ensuring alignment, and understanding of response efforts.
−Removed: Following successful mitigation and restoration of normal operations, Energy Focus conducts a comprehensive post-incident review to glean insights and lessons learned.
−Removed: These findings inform ongoing enhancements to our cybersecurity protocols, further bolstering our resilience against future threats.
−Removed: The incident coordinator oversees the detection, containment, and recovery procedures outlined in the plan.
−Removed: Effective communication protocols ensure timely notification to both internal and external stakeholders.
−Removed: Regular training sessions bolster staff preparedness, while post-incident reviews facilitate continuous improvement.
−Removed: Appendices offer essential contact information and tools necessary for incident response.
−Removed: Cybersecurity user awareness training is mandatory for all new hires and for existing employees on an annual basis to help protect our employees and the Company against cybersecurity threats.
−Removed: This annual training is customized to address specific cybersecurity challenges and scenarios that we may face within the real estate investment industry.
−Removed: Novel cybersecurity threats to the Company that are identified by our Information Technology team are communicated to all employees by email, as needed, in an effort to promote awareness and protect the Company from cyber-attacks.
+Added: Our Board of Directors assigned specific oversight responsibility for cybersecurity to our Audit Committee, which also oversees our general risk management.
+Added: The Audit Committee reviews and discusses with management our policies, practices, and risks related to information security and cybersecurity.
+Added: Our Chief Executive Officer has primary responsibility for assessing, monitoring, and managing cybersecurity risks.
+Added: To strengthen our cybersecurity posture, we engage with external consultants for regular risk assessments, penetration testing, and vulnerability analyses, allowing for proactive identification and mitigation of potential threats.
+Added: We also rigorously verify the cybersecurity practices of our third-party service providers, vendors, and partners, conducting due diligence before establishing relationships and ongoing monitoring to verify compliance with our cybersecurity standards.
+Added: Our Principal Financial Officer provides an update to the Audit Committee on any risks related to cybersecurity on a quarterly basis.
+Added: Our incident response plan includes notifying the Audit Committee, and then the Board of Directors, of any material threats or incidents that arise.
Risk Management and Strategy
13 unchanged sentences
Our Director of Operations & Information Technology regularly evaluates the Company’s cybersecurity risk profile and leads the development of strategies to mitigate risks and address cybersecurity issues that may arise, in consultation with members of our senior management team.
−Removed: Our Director of Operations & Information Technology has approximately 20 years of experience in his field, and our Director of Operations & Information Technology holds certifications in cybersecurity from accredited information technology certification providers.
We have formal policies and procedures that address cybersecurity incident response and disaster recovery from interference with our critical applications.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.