4 unchanged sentences
The Company’s cybersecurity risks are evaluated at least annually through our enterprise risk management program, which is a company-wide effort to identify, assess, manage, report and monitor material risks that may affect our ability to achieve our business objectives.
−Removed: To manage our cybersecurity program, we have established a cross-functional cybersecurity oversight committee and cybersecurity team, both led by our Chief Information Officer ("CIO") .
−Removed: Our cybersecurity oversight committee and cybersecurity team, with the support of external cyber-specialist resources, include technical experts in cybersecurity risk management, incident response and security operations with extensive experience in the operations of networks, network security and infrastructure management.
+Added: To manage our cybersecurity program, we have established a cybersecurity team led by our Chief Information Officer ("CIO") .
+Added: Our cybersecurity team, with the support of external cyber-specialist resources, include technical experts in cybersecurity risk management, incident response and security operations with extensive experience in the operations of networks, network security and infrastructure management.
In addition, members of our cybersecurity team have cybersecurity experience or certifications, such as the Certified Information Systems Security Professional certification.
Our CIO is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from professionals on the cybersecurity management team and through the use of technological tools and software.
−Removed: Policies, procedures and controls under our cybersecurity program are designed in consideration of published frameworks, including the Center for Information Security ("CIS") Critical Security Controls, and routinely evaluated for ongoing adherence to those frameworks.
+Added: Policies, procedures and controls under our cybersecurity program are designed in consideration of published frameworks, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, and routinely evaluated for ongoing adherence to those frameworks.
Our cybersecurity program includes a process for incident response and continuous improvement.
We periodically enlist outside advisors to evaluate the maturity of our cybersecurity program, review processes and policies, conduct penetration and vulnerability tests and simulation exercises, and to monitor and help identify potential cybersecurity incidents.
−Removed: We provide annual cybersecurity awareness training to our employees and contractors to help identify potential cybersecurity threats and attacks, perform targeted phishing campaigns, use multifactor authentication for secure access to our systems and networks and tabletop exercises to simulate and prepare for potential incidents.
+Added: We provide annual cybersecurity awareness training to our employees and contractors to help identify potential cybersecurity threats and attacks, perform targeted phishing campaigns, use multifactor authentication for secure access to our systems and networks and tabletop exercises
+Added: to simulate and prepare for potential incidents.
When considering to engage with third-party service providers, we assess the risks from cybersecurity threats posed by such engagement and continue to evaluate those risks throughout the duration of the relationship.
2 unchanged sentences
The Audit Committee performs an annual review of the Company’s cybersecurity program, which includes an update of the cybersecurity threat landscape, discussion of management’s actions to identify and detect threats, and a review of assessments, penetration tests and other audits performed by internal and external parties.
−Removed: In addition, management periodically arranges for outside experts to present to the Audit Committee on cyber governance frameworks, regulatory developments, industry practices and risk management.
−Removed: None of the cybersecurity risks, including as a result of any prior incidents we have experienced, have had a material adverse impact on our operations, business or financial condition.
+Added: None of the risks from cybersecurity threats, including as a result of any prior cybersecurity incidents we have experienced, have materially affected, or are reasonably likely to materially affect, our results of operations, business strategy or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.