9 unchanged sentences
● Business continuity plans and critical recovery backup systems .
−Removed: Our cybersecurity risk management program is supervised by our Director of Information Systems whose team is responsible for leading enterprise-wide information security strategy, policy, standards, architecture, and processes, as well as managing the Company’s information security and risk management awareness program.
+Added: Our cybersecurity risk management program is supervised by our Director of Information Systems , who has over 20 years of relevant experience, and whose team is responsible for leading enterprise-wide information security strategy, policy, standards, architecture, and processes, as well as managing the Company’s information security and risk management awareness program .
Cybersecurity Incident Response Process
3 unchanged sentences
Our Board is engaged in the oversight of cybersecurity threat risk management.
−Removed: As reflected in the Audit Committee’s charter, the Board has specifically delegated responsibility for oversight of cybersecurity matters to the Audit Committee, which provides advice and guidance on the adequacy of the Company’s initiatives on, among other things, cybersecurity risk management.
+Added: As reflected in the Audit Committee’s charter, the Board has specifically delegated responsibility for oversight of cybersecurity matters to the Audit Committee , comprised solely of independent directors.
+Added: The Audit Committee reviews and discusses our cybersecurity risks and threats and provides advice and guidance on the adequacy of the Company’s initiatives on, among other things, cybersecurity risk management.
Periodic updates are provided to the Audit Committee on, among other things, our cybersecurity risks and threats, the status of projects to strengthen the Company’s information security systems, and the emerging threat landscape.
−Removed: We also engage third parties to periodically evaluate and audit aspects of our information security programs, including by conducting vulnerability assessments and penetration testing, and the results of those findings are reported to the Audit Committee and used to help identify potentially material risks and prioritize certain security initiatives.
+Added: We also engage third parties to periodically evaluate and audit aspects of our information security programs, including by conducting vulnerability assessments and penetration testing.
+Added: These partnerships enable us to leverage specialized knowledge and insights, with the goal of ensuring our cybersecurity strategies and processes remain current.
+Added: The results of those findings are reported to the Audit Committee and used to help identify potentially material risks and prioritize certain security initiatives.
We face a number of cybersecurity risks in connection with our business.
−Removed: Based on the information we have as of the date of this Annual Report, we do not believe that any risks from cybersecurity threats, including as a result of any
−Removed: previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company’s business strategy, results of operations or financial position.
+Added: Due to evolving cybersecurity threats, it has been and will continue to be difficult to prevent, detect, mitigate, and remediate cybersecurity incidents.
+Added: We may also rely on information technology and third-party vendors to support our operations, including to collect and store sensitive data.
+Added: Despite ongoing efforts to continued improvement of our ability to protect against cyber incidents, we may not be able to protect all information systems, and such incidents may lead to reputational harm, revenue and client loss, legal actions, statutory penalties, among other consequences.
+Added: Based on the information we have as of the date of this Annual Report, we do no t believe that any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company’s business strategy, results of operations or financial position.
See Item 1A, Risk Factors, of this Annual Report for further discussion of cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.