16 unchanged sentences
While the particular personnel assigned to an incident response team will depend on the particular facts and circumstances, the response team is led by the CISO or his delegee.
−Removed: In addition, the Audit Committee approved a Company policy that supplements the Franklin Templeton incident response plan with respect to cybersecurity incidents that have or are expected to impact the Company, including by impacting the Advisor’s ability to provide services to the Company pursuant to the Advisory Agreement.
+Added: In addition, the Audit Committee approved a Company policy that supplements the Franklin Templeton incident response plan with respect to cybersecurity incidents that have impacted or are expected to impact the Company, including by impacting the Advisor’s ability to provide services to the Company pursuant to the Advisory Agreement.
Pursuant to this policy the Advisor and Franklin Templeton are required to notify and brief Company senior management and the Audit Committee with respect to certain matters related to applicable cybersecurity incidents.
8 unchanged sentences
Franklin Templeton undertakes regular internal and external security audits and vulnerability assessments to reduce the risk of a cybersecurity incident and they implement business continuity, contingency and recovery plans to mitigate the impact of an incident.
−Removed: As part of these efforts, Franklin Templeton periodically engages consultants (e.g., Cobalt, Crowdstrike and EY) to conduct external reviews of its vulnerabilities, including penetration testing and compromise assessments.
−Removed: Franklin Templeton employs best practice identity and access management including broad adoption of multifactor authentication, geo-location blocking, behavior analytics and controls aligned to a zero trust model.
+Added: As part of these efforts, Franklin Templeton periodically engages consultants to conduct external reviews of its vulnerabilities, including penetration testing and compromise assessments.
+Added: Franklin Templeton employs identity and access management including broad adoption of multifactor authentication, geo-location blocking, behavior analytics and controls aligned to a zero trust model.
Franklin Templeton and the Advisor recognize that threat actors frequently target employees to gain unauthorized access to information systems.
Therefore, a key element of their prevention efforts is employee training on their data privacy and cyber security procedures.
−Removed: For example, all new hires receive mandatory privacy and information security training.
−Removed: In addition, current employees of the Advisor must complete mandatory annual cybersecurity and data trainings, which are supplemented by regular phishing and other cyber-related testing and trainings that we conduct throughout the year.
+Added: For example, new hires receive mandatory privacy and information security training.
+Added: In addition, current employees of the Advisor must complete mandatory annual cybersecurity and data trainings, which are supplemented by regular phishing and other cyber-related awareness activities and trainings that we conduct throughout the year.
We recognize that third parties that provide information systems used by the Advisor to provide services to the Company can be subject to cybersecurity incidents that could impact the Company.
−Removed: To mitigate third party risk, Franklin Templeton maintains a vendor code of conduct, which is designed to require third party vendors to comply with our requirements for maintenance of passwords, as well as other confidentiality, security, and privacy procedures.
+Added: To mitigate third party risk, Franklin Templeton requires third party vendors to comply with our confidentiality, security, and privacy requirements.
Third-party IT vendors are also subject to additional diligence such as questionnaires and inquiries.
−Removed: As discussed above, to support its preparedness Franklin Templeton has an incident response plan that it regularly updates.
+Added: As discussed above, to support its preparedness Franklin Templeton has an incident response plan that it periodically updates.
In addition, Franklin Templeton performs regularly scheduled tabletop exercises and periodic drills at least once a year to test its incident response procedures, identify improvement opportunities and exercise team preparedness.
2 unchanged sentences
Cybersecurity incidents may be detected through a variety of means, which may include, but are not limited to, automated event-detection notifications or similar technologies which are monitored by the Franklin Templeton cyber defense team, notifications from employees, borrowers or service providers, and notifications from third party information technology system providers.
−Removed: Franklin Templeton also has a comprehensive threat intelligence program that performs proactive analyses leveraging internal, government and third party provided intelligence to identify and mitigate risks to the firm.
−Removed: Once a potential cybersecurity incident is identified, including a third party cybersecurity event, the incident response team designated pursuant to the Franklin Templeton incident response plan follows the procedures set forth in the plan to investigate the potential incident, including determining the nature of the event (e.g.
−Removed: ransomware or personal data breach) and assessing the severity of the event and sensitivity of any compromised data.
+Added: Franklin Templeton also has a threat intelligence program that performs proactive analyses leveraging internal, government and third party provided intelligence to identify and mitigate risks to the firm.
+Added: Once a potential cybersecurity incident is identified, including a third party cybersecurity event, the incident response team designated pursuant to the Franklin Templeton incident response plan follows the procedures set forth in the plan to investigate the potential incident, including determining the nature of the event and assessing the severity of the event..
Containment, Eradication, Recovery, and Reporting
−Removed: In the event of a cybersecurity incident, the Franklin Templeton incident response team is initially focused on containing the cybersecurity incident as quickly as possible consistent with the procedures in the incident response plan.
−Removed: Containment procedures may include off-lining systems, including by disconnecting network cable, utilizing network-management tools to isolate the host, altering the DNS entry of impact hosts, and coordinating with service providers.
+Added: In the event of a cybersecurity incident, the Franklin Templeton incident response team is responsible for deciding on a containment strategy to respond to the cybersecurity incident consistent with the procedures in the incident response plan.
Once a cybersecurity incident is contained the focus shifts to remediation.
−Removed: Eradication and recovery activities depend on the nature of the cybersecurity incident and may include rebuilding systems and/or hosts, replacing compromised files with clean versions, validation of files or data that may have been affected, and increased network monitoring or logging to identify recurring attacks.
−Removed: Franklin Templeton has relationships with a number of third party service providers to assist with cybersecurity containment and remediation efforts, including a forensic investigation firm, a ransomware recovery vendor, a communications firm, and various law firms.
−Removed: Following the conclusion of an incident, the Franklin Templeton incident response team will generally reassess the effectiveness of the cybersecurity program and incident response plan, make adjustments as appropriate and report to our senior management and Audit Committee on these matters.
+Added: Eradication and recovery activities depend on the nature of the cybersecurity incident and may include rebuilding systems and/or hosts, replacing compromised files with clean versions or validation of files or data that may have been affected.
+Added: Franklin Templeton has relationships with a number of third party service providers to assist with cybersecurity containment and remediation efforts.
+Added: Following the conclusion of an incident, the Franklin Templeton incident response team will generally reassess the effectiveness of the cybersecurity program and incident response plan, identify potential adjustments as appropriate and report to our senior management and Audit Committee on these matters.
Cybersecurity Risks
−Removed: As of December 31, 2023, we are not aware of any material cybersecurity incidents that impacted the Company in the last three years.
+Added: As of December 31, 2024, we are not aware of any instances of material cybersecurity incidents that impacted the Company in the last three years.
We and our Advisor routinely face risks of potential incidents, whether through cyber-attacks or cyber intrusions over the Internet, ransomware and other forms of malware, computer viruses, attachment to emails, phishing attempts, extortion or other scams;
however, we have been able to prevent or sufficiently mitigate harm from such risks.
−Removed: Although the Advisor and Franklin Templeton, on our behalf, make efforts to maintain the security and integrity of the information technology systems the Advisor uses on our behalf, these systems and the proprietary, confidential and personal information that resides on or is transmitted through them are subject to the risk of a security incident or disruption, and there can be no assurances regarding our security efforts and measures or those of our third party providers.
See “Item 1A–Risk Factors–Our business could suffer in the event our Advisor or any other party that provides us with services essential to our operations experiences system failures or cyber-incidents or a deficiency in cybersecurity.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.