21 unchanged sentences
Management of the Company’s third parties, including vendors and service providers, is conducted through a risk-based approach and the level of due diligence is driven from risk factors established by our Risk Management program.
−Removed: The process provides awareness and collaboration
−Removed: across internal teams including, but not limited to, Information Technology, Information Security and Business Continuity.
+Added: The process provides awareness and collaboration across internal teams including, but not limited to, Information Technology, Information Security and Business Continuity.
In addition to ongoing monitoring of select vendors, a review is conducted on new or significantly changed third parties, applications, and technology to ensure that systems and third parties meet certain baseline requirements.
8 unchanged sentences
A multi-step approach is applied to identify, report and remediate these vulnerabilities, and the Company adjusts its information security policies, standards, processes and practices as necessary based on the information provided by these assessments.
−Removed: The results of key assessments are reported in summary to the Board annually.
+Added: The results of key assessments are reported in summary to the Board on an ongoing basis.
The Risk Committee of the Board provides direction and oversight of the enterprise-wide risk management framework of the Company, including the management of risks arising from cybersecurity threats.
4 unchanged sentences
To facilitate the success of the Company’s cybersecurity risk management program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents.
−Removed: Through ongoing communications with these teams, the COO, Information Security, and Risk Management teams monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Corporate Crisis Management Team and ultimately the Board when appropriate.
−Removed: We believe our Board and management, including the Chief Operating Officer, have the appropriate expertise, background, and depth of experience to manage risks arising from cybersecurity threats, including applicable knowledge gained through industry experience, internal and external training, and periodic discussions with consultants and peers with applicable knowledge and expertise.
+Added: Through ongoing communications with these teams, the COO, Information Security, and Risk Management teams monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Corporate Crisis
+Added: Management Team and ultimately the Board when appropriate.
+Added: We believe our Board and management, including the COO, have the appropriate expertise, background, and depth of experience to manage risks arising from cybersecurity threats, including applicable knowledge gained through industry experience, internal and external training, and periodic discussions with consultants and peers with applicable knowledge and expertise.
In addition, members of our management hold varying levels of relevant cybersecurity certifications.
To our knowledge, neither cybersecurity threats, nor the results including as a result of any previous cybersecurity incidents have materially affected the Company, including its business strategy, results of operations or financial condition.
−Removed: With regard to the possible impact of future cybersecurity threats or incidents, see Item 1A, Risk Factors - Risks Related to Out Business .
+Added: With regard to the possible impact of future cybersecurity threats or incidents, see Item 1A, Risk Factors - Risks Related to Our Business .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.