12 unchanged sentences
In response to such assessments, controls are embedded into our processes and technology by our Director of Operations & Information Technology to seek to mitigate risks to our systems and processes from cybersecurity incidents.
−Removed: We continuously evaluate if we have adequate controls in place utilizing a risk-based approach that aligns with the National Institute of Standards and Technology Cybersecurity Framework (NIST).
−Removed: Our information technology department diligently monitors our daily operations, overseeing the security of our computer networks through implemented systems and processes aimed at safeguarding sensitive data.
−Removed: Utilizing encryption and authentication technologies, we fortify our systems against unauthorized access and data loss.
+Added: We continuously evaluate if we have adequate controls in place utilizing a risk-based approach that is informed by the National Institute of Standards and Technology Cybersecurity Framework (NIST).
+Added: Our information technology department monitors our daily operations, overseeing the security of our computer networks through implemented systems and processes aimed at safeguarding sensitive data.
+Added: We utilize security technologies and controls designed to help protect our systems against unauthorized access and data loss.
This proactive approach ensures the integrity and confidentiality of our data, mitigating potential risks posed by cyber threats.
2 unchanged sentences
Effective communication channels with these vendors are maintained to enable timely notification of any cybersecurity incidents that could impact our company.
−Removed: Although risks from cybersecurity threats have to date not materially affected, and we do not believe they are reasonably likely to materially affect, us, our business strategy, results of operations or financial condition, like other companies in our industry, we could, from time to time, experience threats and security incidents related to our and our third-party vendors’ information systems.
+Added: Although risks from cybersecurity threats have to date not materially affected, and based on information currently available, we do not believe they are reasonably likely to materially affect, us, our business strategy, results of operations or financial condition, like other companies in our industry, we could, from time to time, experience threats and security incidents related to
+Added: our third-party vendors’ information systems.
For more information, please see Item 1A.
7 unchanged sentences
Cybersecurity user awareness training is mandatory for all new hires and for existing employees on an annual basis to help protect our employees and the Company against cybersecurity threats.
−Removed: This annual training is customized to address specific cybersecurity challenges and scenarios that we may face within the real estate investment industry.
+Added: This annual training is customized to address specific cybersecurity challenges and scenarios that we may face within our operating environment.
Novel cybersecurity threats to the Company that are identified by our Information Technology team are communicated to all employees by email, as needed, in an effort to promote awareness and protect the Company from cyber-attacks.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.