6 unchanged sentences
There can be no guarantee that our policies, procedures and processes will be properly followed in every instance or that those policies, procedures and processes will be effective.
−Removed: We are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: We are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have
+Added: materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
However, we can provide no assurance that there will not be incidents in the future or that they will not materially affect us.
26 unchanged sentences
Our cybersecurity policies and procedures are periodically assessed by our external cybersecurity consultant.
−Removed: These assessments include a variety of activities including information security maturity assessments, penetration tests, and independent reviews of our information security control environment and operating effectiveness.
+Added: These assessments include a variety of activities including information security maturity assessments,
+Added: penetration tests, and independent reviews of our information security control environment and operating effectiveness.
The results of significant assessments are reported to management, the Board and its Nominating and Corporate Governance Committee.
3 unchanged sentences
They receive periodic reports from management and our external cybersecurity consultant about the identification, prevention, detection, mitigation and remediation of cybersecurity incidents, including material security risks and information security vulnerabilities.
−Removed: Our Nominating and Corporate Governance Committee directly oversees our cybersecurity program.
+Added: Our Nominating and Corporate Governance Committee oversees risks arising from our cybersecurity program.
The Nominating and Corporate Governance Committee receives periodic updates from management and our external cybersecurity consultant on cybersecurity risk resulting from risk assessments, progress of risk reduction initiatives, external auditor feedback, control maturity assessments, and relevant internal and industry cybersecurity incidents.
Management’s Role
−Removed: Our chief financial officer (“CFO”) has primary responsibility for assessing and managing material risks from cybersecurity threats.
−Removed: The CFO meets periodically with our external cybersecurity consultant to review security performance metrics and identify security risks.
−Removed: The CFO and our external cybersecurity consultant also consider and make recommendations on security policies and procedures, security service requirements and risk mitigation strategies to the Nominating and Corporate Governance Committee.
+Added: Our Chief Financial Officer has primary responsibility for assessing and managing material risks from cybersecurity threats.
+Added: The Chief Financial Officer meets periodically with our external cybersecurity consultant to review security performance metrics and identify security risks.
+Added: The Chief Financial Officer and our external cybersecurity consultant also consider and make recommendations on security policies and procedures, security service requirements and risk mitigation strategies to the Nominating and Corporate Governance Committee .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.