18 unchanged sentences
We conduct tabletop exercises for tactical response readiness, perform regular security scans of our environment both from an external and internal perspective, as well as work with a qualified third-party vendor to perform penetration tests of our environment.
−Removed: Any identified risks are included in our overall risk management program, and internal and external auditors validate our IT controls on a regular basis.
+Added: Any identified risks are included in our overall risk management program, and internal auditors validate our IT controls on a regular basis.
We conduct organization-wide cybersecurity training and compliance exercises in connection with our information security program.
−Removed: This training consists of educational material and compliance testing administered to all of our employees, which is tracked and recorded throughout the year.
−Removed: Results and progress are shared with Executive Leadership, the Audit Committee, and the Board.
+Added: This training consists of educational material and compliance testing administered to all of our employees, which is shared with Executive Leadership, the Audit Committee, and the Board.
Employee phishing tests are conducted on a regular basis.
6 unchanged sentences
Additionally, Executive Leadership is briefed on information security at least quarterly by members of our IT security, compliance, governance, and audit teams.
−Removed: The Audit Committee of the Board is responsible for overseeing our risk exposure to information security, cybersecurity, and data protection, as well as the steps management has taken to monitor and control such exposures.
+Added: The Audit Committee of the Board is responsible for overseeing our risk exposure to information security, cybersecurity, AI security, and data protection, as well as the steps management has taken to monitor and control such exposures.
Our IT security department, which assesses and manages our risks from cybersecurity threats, is led by our SVP IT Infrastructure & Security, who reports to our Senior EVP IT.
−Removed: Additional oversight for assessing and managing cybersecurity risk include Executive sponsors, IT, Human Resources, IT Governance Risk and Compliance, Internal Audit, and Legal, as well as members of our Information Security Risk Council, IT Risk Committee, and ERM teams.
+Added: Additional oversight for assessing and managing cybersecurity risk include Executive sponsors, IT, HR, IT Governance Risk and Compliance, Internal Audit, and Legal, as well as members of our Information Security Risk Council, IT Risk Committee, and ERM teams.
We have in place an incident response plan to identify, protect, detect, respond to, and recover from cybersecurity threats and incidents.
1 unchanged sentence
Additionally, we maintain a qualified third-party vendor relationship which is available to the team for on-demand incident response and investigation, as needed.
−Removed: The IT security department team members have degrees applicable to cybersecurity, including Bachelors in Information Systems, Computer Science, Management Information Systems and/or Masters in Cybersecurity, and hold professional certifications, including Certified Information Systems Security Professional, Offensive Security Certified Professional, Global Information Assurance Certification (GIAC) Defensible Security Architecture, GIAC Forensic Examiner, GIAC Incident Handling, and GIAC Open Source Intelligence.
−Removed: Our SVP IT Infrastructure & Security holds a Cybersecurity and Privacy Law Certificate from Mitchell Hamline School of Law, and has 29 years of experience in systems, network, and database administration.
+Added: The IT security department team members have degrees applicable to cybersecurity, including Bachelors in Information Systems, Computer Science, Management Information Systems and/or Masters in Cybersecurity, and hold professional certifications, including Certified Information Systems Security Professional, Offensive Security Certified Professional, Global
+Added: Information Assurance Certification (GIAC) Defensible Security Architecture, GIAC Forensic Examiner, GIAC Incident Handling, and GIAC Open Source Intelligence.
+Added: Our SVP IT Infrastructure & Security holds a Cybersecurity and Privacy Law Certificate from Mitchell Hamline School of Law, is also a Digital Directors Network (DDN) Boardroom Certified Qualified Technology Expert (OTE), and has 30 years of experience in systems, network, and database administration.
Additionally, our Senior IT security department manager is an Offensive Security Certified Professional, and holds GIAC Security Leadership (GSLC), with over 26 years of experience in network performance, availability, and protection.
Impact of Cybersecurity Threats
−Removed: There have been no previous cybersecurity incidents which have materially affected us to date, including our business strategy, results of operations or financial condition.
−Removed: However, any future potential risks from cybersecurity threats, including but not limited to exploitation of vulnerabilities, ransomware, denial of service, supply chain attacks, and the use of artificial intelligence by threat actors engaged in these activities, or other similar threats may materially affect us, including our execution of business strategy, reputation, results of operations and/or financial condition.
+Added: We have not identified risks from cybersecurity threats, including as a result of previous cybersecurity incidents, which have materially affected or are reasonably likely to materially affect us to date, including our business strategy, results of operations or financial condition.
+Added: However, any future potential risks from cybersecurity threats, including but not limited to exploitation of vulnerabilities, ransomware, denial of service, supply chain attacks, and the use of AI by threat actors engaged in these activities, or other similar threats may materially affect us, including our execution of business strategy, reputation, results of operations and/or financial condition.
For additional information regarding cybersecurity threats, see 'Item 1A.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.