1 unchanged sentence
Cybersecurity.
−Removed: Risk Management, Strategy and Governance
−Removed: The Trust has no employees or internal information systems and is managed
−Removed: by the Sponsor.
−Removed: Thus, the Trust relies on the Sponsor and VanEck, the parent company of the Sponsor, as well as the ETH Custodian
−Removed: and Additional ETH Custodian and other service providers to protect the Trust’s information from cybersecurity threats.
−Removed: has policies, standards, and procedures on information security (the “Cybersecurity Documents”).
−Removed: The Cybersecurity Documents
−Removed: govern the procurement, use, storage, protection and permissions of data systems, applications and devices.
−Removed: The Cybersecurity Documents
−Removed: outline the correct usage of elements and tasks on the networks/infrastructure to ensure safe operation, high availability, performance,
−Removed: and data accuracy.
−Removed: VanEck has adopted the National Institute of
−Removed: Standards and Technology’s (“NIST”) cybersecurity framework as its security outline.
−Removed: The program is reviewed annually.
+Added: Risk Management, Strategy and
+Added: The Trust has no employees or internal information systems
+Added: and is managed by the Sponsor.
+Added: Thus, the Trust relies on the Sponsor and VanEck, the parent company of the Sponsor, as well as
+Added: the ETH Custodian and Additional ETH Custodian and other service providers to protect the Trust’s information from cybersecurity
+Added: VanEck has policies, standards, and procedures on information security (the “Cybersecurity Documents”).
+Added: Cybersecurity Documents govern the procurement, use, storage, protection and permissions of data systems, applications and devices.
+Added: Cybersecurity Documents outline the correct usage of elements and tasks on the networks/infrastructure to ensure safe operation,
+Added: high availability, performance, and data accuracy.
+Added: VanEck has adopted the National Institute
+Added: of Standards and Technology’s (“NIST”) cybersecurity framework as its security outline.
+Added: The program is reviewed
Using the NIST framework as a guide, VanEck’s cybersecurity program is organized around the following program domains:
−Removed: ● Identify critical assets, data, systems and capabilities, cybersecurity strategy and governing elements, threats and cybersecurity
−Removed: ● Protect assets (data, systems, networks, personnel, etc.) from external or internal malicious actors and failed practices
−Removed: ● Detect anomalies and security events through environments monitoring, analysis, remediation, and reporting.
−Removed: Engage outside vendors
−Removed: to periodically test the network infrastructure and software applications against known vulnerabilities and to ensure the use of a best
+Added: critical assets, data, systems and capabilities, cybersecurity strategy and governing
+Added: elements, threats and cybersecurity risks
+Added: assets (data, systems, networks, personnel, etc.) from external or internal malicious
+Added: actors and failed practices
+Added: anomalies and security events through environments monitoring, analysis, remediation,
+Added: and reporting.
+Added: Engage outside vendors to periodically test the network infrastructure
+Added: and software applications against known vulnerabilities and to ensure the use of a best
practice security program
−Removed: ● Respond to incidents regardless of source or causality
−Removed: ● Recover through planning, improvements and communications (external and internal)
−Removed: ● Conduct after-action evaluation to identify what went well, what did not go well and improve VanEck systems on the back of an issue
−Removed: VanEck employs third-party firms to assess its
−Removed: cybersecurity posture, conduct penetration testing, and forensic analysis.
−Removed: VanEck maintains a risk-based approach to identifying
−Removed: and overseeing cybersecurity risks presented by third parties, including vendors, service providers, counterparties and clients, as well
−Removed: as the systems of third parties that could significantly and adversely impact VanEck’s business in the event of a cybersecurity
−Removed: incident affecting those third-party systems.
−Removed: Third-party risks are included within VanEck’s NIST framework, and risk identification
−Removed: and mitigation are supported by VanEck’s cybersecurity program.
−Removed: VanEck also performs diligence on certain third parties and monitors
−Removed: cybersecurity threats and risks identified through such diligence.
+Added: to incidents regardless of source or causality
+Added: through planning, improvements and communications (external and internal)
+Added: after-action evaluation to identify what went well, what did not go well and improve
+Added: VanEck systems on the back of an issue
+Added: VanEck employs third-party firms to assess
+Added: its cybersecurity posture, conduct penetration testing, and forensic analysis.
+Added: VanEck maintains a risk-based approach
+Added: to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers, counterparties
+Added: and clients, as well as the systems of third parties that could significantly and adversely impact VanEck’s business in the
+Added: event of a cybersecurity incident affecting those third-party systems.
+Added: Third-party risks are included within VanEck’s NIST
+Added: framework, and risk identification and mitigation are supported by VanEck’s cybersecurity program.
+Added: VanEck also performs diligence
+Added: on certain third parties and monitors cybersecurity threats and risks identified through such diligence.
Roles and Responsibilities
−Removed: Roles and responsibilities for cybersecurity have
−Removed: been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of the firm and
−Removed: VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level employees.
+Added: Roles and responsibilities for cybersecurity
+Added: have been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of
+Added: the firm and VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level
Cybersecurity is closely aligned with not only risk management, but also with business continuity planning and response.
−Removed: the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated to the staff
−Removed: Specifically, VanEck’s Chief Information Security Officer, reporting to the co-chair of the Risk Management Committee,
−Removed: is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations with a special
−Removed: emphasis on proper desktop and email security and conduct.
−Removed: Special training is also given to recently on-boarded staff.
−Removed: Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information Security Officer, are responsible
−Removed: for the day-to-day operations of the firm cybersecurity infrastructure including normal operations as well as any remedial work required
−Removed: in response to an incident.
−Removed: The communication responsibility in the event of an incident is shared by VanEck’s CEO and the General
−Removed: Since our commencement of operations, we have not
−Removed: experienced a material information security breach incident and we are not aware of any cybersecurity risks that are reasonably likely
−Removed: to materially affect our business.
−Removed: However, future incidents could have a material impact on our business strategy, results of operations,
−Removed: or financial condition.
+Added: In addition, the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated
+Added: to the staff globally.
+Added: Specifically, VanEck’s Chief Information Security Officer , reporting to the co-chair of the Risk Management
+Added: Committee, is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations
+Added: with a special emphasis on proper desktop and email security and conduct.
+Added: Special training is also given to recently on-boarded
+Added: VanEck’s Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information
+Added: Security Officer, are responsible for the day-to-day operations of the firm cybersecurity infrastructure including normal operations
+Added: as well as any remedial work required in response to an incident.
+Added: The communication responsibility in the event of an incident
+Added: is shared by VanEck’s CEO and the General Counsel.
+Added: Since our commencement of operations,
+Added: we have not experienced a material information security breach incident and we are not aware of any cybersecurity risks that are
+Added: reasonably likely to materially affect our business.
+Added: However, future incidents could have a material impact on our business strategy,
+Added: results of operations, or financial condition.
See “Item 1A.
−Removed: Risk Factors— Other Risks—Due to the increased use of technologies, intentional
−Removed: and unintentional cyber-attacks pose operational and information security risks.”
+Added: Risk Factors— Other Risks—Due to the increased
+Added: use of technologies, intentional and unintentional cyber-attacks pose operational and information security risks.”
Not applicable.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.