3 unchanged sentences
Fuel Tech regularly evaluates cybersecurity risk from computer viruses and more sophisticated and targeted cyber-related attacks such as ransomware, as well as cybersecurity failures resulting from human error and technological errors.
−Removed: Such risks are reviewed by our Information Technology Steering Committee on a quarterly basis, or more frequently if deemed appropriate.
+Added: Such risks are reviewed by our Information Technology Steering Committee on a monthly basis, or more frequently if deemed appropriate.
Our overall strategy in combatting known cybersecurity risks includes a variety of individual tactics, including:
the use of antivirus software, virtual private networks, email security, as well as other software to prevent and detect data intrusions.
+Added: ● the use of Multi-Factor Authentication (MFA) to add another layer of protection to company accounts and sensitive data.
the deployment of updates and patches as they are available and maintaining the current versions of major software to reduce the exposure to vulnerabilities.
−Removed: the use of third -party service to conduct mandatory online training for all employees regarding identifying and avoiding cyber-security risks.
+Added: the use of third -party service to conduct quarterly mandatory online training for all employees regarding identifying and avoiding cyber-security risks.
+Added: ● the use of monthly phishing prevention campaigns to stimulate and measure awareness in order to prevent incidents caused by human error.
the review of the security procedures used by third parties that may host or otherwise have access to Fuel Tech’s data.
−Removed: the deployment of third -party cyber-security experts to perform penetration testing on our internal and external networks and systems in an effort to identify potential vulnerabilities.
+Added: the deployment of third -party cyber-security experts to perform annual penetration testing on our internal and external networks and systems in an effort to identify potential vulnerabilities.
if necessary, the use of third -party security experts if and when an incident is detected
4 unchanged sentences
Day-to day management of cybersecurity threats is conducted by our Information Technology department which is charged with identifying and reporting threats to senior management.
−Removed: On a quarterly basis, cybersecurity is reviewed by our Information Technology Steering Committee, which is comprised of our Chief Executive Officer, Chief Financial Officer, General Counsel and Head of Information Technology.
+Added: On a monthly basis, cybersecurity is reviewed by our Information Technology Steering Committee, which is comprised of our Chief Executive Officer, Chief Financial Officer, General Counsel and Head of Information Technology.
Board Oversight
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.