1 unchanged sentence
CYBERSECURITY.
+Added: Risk Management and Strategy
Cybersecurity risk management
9 unchanged sentences
management and the board of directors of material cybersecurity threats and incidents.
−Removed: The Board of Directors has oversight
−Removed: for the most significant risks facing us and for our processes to identify, prioritize, assess, manage and mitigate those risks.
−Removed: Committee of the Board of Directors (the “Audit Committee”) has been designated to oversee cybersecurity risks.
−Removed: Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our management.
+Added: The Board of Directors has
+Added: oversight for the most significant risks facing us and for our processes to identify, prioritize, assess, manage and mitigate those risks.
+Added: The Audit Committee of the Board of Directors (the “Audit Committee”) has been designated to oversee cybersecurity risks.
+Added: The Audit Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our management.
The Board of Directors also receives periodic updates from management and the Audit Committee on cybersecurity risks.
4 unchanged sentences
on our cybersecurity programs, which includes cybersecurity risks and mitigation strategies, vulnerability management, and on-going cybersecurity
−Removed: As of June 30, 2024, we did not
−Removed: identify any cybersecurity incidents that materially affected or are reasonably likely to materially affect our business strategy, results
−Removed: of operations, or financial condition.
−Removed: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide
−Removed: assurances that we have not experienced an undetected cybersecurity incident.
−Removed: It is possible that we may not implement appropriate controls
−Removed: if we do not detect a particular risk.
−Removed: In addition, security controls, no matter how well designed or implemented, may only mitigate and
−Removed: not fully eliminate the risks.
+Added: While none of our directors has formal professional certifications in cybersecurity, several members of the Board have experience
+Added: overseeing information technology and enterprise risk management in prior executive or board roles.
+Added: The Board receives periodic updates
+Added: on cybersecurity matters as part of its overall risk oversight responsibilities.
+Added: Day-to-day responsibility for identifying and managing
+Added: cybersecurity risks rests with our Director of IT Security & Future Solutions and his information security team.
+Added: The team is responsible
+Added: for monitoring our networks, systems, and data, implementing technical safeguards , conducting employee training, and coordinating incident
+Added: response procedures.
+Added: Management provides regular
+Added: reports to the Audit Committee, generally on an annual basis, or more frequently as needed covering:
+Added: · the Company’s cybersecurity strategy and policies,
+Added: · results of system monitoring and testing,
+Added: · recent threat environment developments, and
+Added: · any cybersecurity incidents and responses.
+Added: In addition, in the event
+Added: of a significant cybersecurity incident, the Chief Operating Officer will promptly inform the Chief Executive Officer and General Counsel,
+Added: who in turn will notify the Chair of the Audit Committee and the Board as appropriate.
+Added: Management regularly updates the Audit Committee
+Added: on our cybersecurity programs, which includes cybersecurity risks and mitigation strategies, vulnerability management, and on-going cybersecurity
+Added: We ordinarily do not engage assessors, consultants, auditors or other third parties in connection with such oversight.
+Added: As of June 30, 2025, we did
+Added: not identify any cybersecurity incidents that materially affected or are reasonably likely to materially affect our business strategy,
+Added: results of operations, or financial condition.
+Added: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats
+Added: or provide assurances that we have not experienced an undetected cybersecurity incident.
+Added: It is possible that we may not implement appropriate
+Added: controls if we do not detect a particular risk.
+Added: In addition, security controls, no matter how well designed or implemented, may only mitigate
+Added: and not fully eliminate the risks.
Even when a risk is detected, disruptive events may not always be immediately and thoroughly interpreted
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.