2 unchanged sentences
Risk Management and Strategy
−Removed: The Company has implemented and maintains multiple layers of physical, administrative and technical security processes designed to protect our manufacturing facilities from disruptions that may result from cybersecurity incidents, as well as to safeguard the confidentiality of our critical systems, and data residing on those systems, including employee data, customer data, and intellectual property.
+Added: The Company has implemented and maintains multiple layers of physical, administrative and technical security processes designed to protect our manufacturing facilities from disruptions that may result from cybersecurity incidents, as well as to safeguard the confidentiality of our critical systems, and data residing on those systems, including employee data, customer data, and IP.
Our risk assessment and management of material risks from cybersecurity threats is integrated into our overall enterprise risk management process, as well as our information systems processes.
4 unchanged sentences
The Company has obtained Trusted Information Security Assessment Exchange (TISAX) certification labels within the United States, Germany, and China.
−Removed: The Company is also continues working on its ISO 27001 certification.
+Added: The Company is also continuing to work on its ISO 27001 certification.
Our internal information security team oversees and works collaboratively with various information security service providers.
Our cybersecurity program incorporates external guidance and expertise through the use of third-party service providers to assist in the identification, assessment and management of risks specific to cybersecurity threats, including vendors providing threat intelligence, risk mitigation, dark web monitoring, external scanning and scoring, threat and reputation monitoring, forensics, cyber-insurance, advisory services, and legal counsel.
+Added: Our security processes include assessing risks arising from engagement of third-party security service providers.
+Added: Our approach to selecting and overseeing such security service providers includes structured due diligence and an ongoing monitoring process.
+Added: Prior to engagement, we conduct risk‑based vetting of technical competencies, attestations or certifications, policies and controls related to access management, data handling, encryption, incident response, and conflicts of interest and independence.
+Added: Contractual arrangements with security service providers are tailored to risk and generally include confidentiality and data protection obligations, restrictions on use and disclosure of our information, and requirements for secure transmission, processing, and termination rights for control failures or noncompliance.
+Added: We put in place least‑privilege access, multifactor authentication, and other technical safeguards as appropriate.
We have an incident response plan that includes scenario-based playbooks for managing cybersecurity incidents and associated crisis communication procedures designed to facilitate coordination across the Company and with our partners, customers, the public and others.
5 unchanged sentences
In addition, on at least an annual basis, the Board receives reports, summaries or presentations related to cybersecurity threats, risk, mitigation and related processes.
−Removed: Our cybersecurity risk assessment and management processes are implemented and maintained by our Vice President of Information Technology and Information Security Officer ("VP of IT") , who is supported by other members of management, as necessary.
−Removed: Our VP of IT is responsible for approving budgets, cybersecurity incident preparedness, approving cybersecurity processes, reviewing security assessments and other security-related reports, and providing the Chief Financial Officer ("CFO") with regular updates on cybersecurity-related matters.
+Added: Our cybersecurity risk assessment and management processes are implemented and maintained by our Vice President of Information Technology and Information Security Officer ("VP of IT") , who is supported by other
+Added: members of management, as necessary.
+Added: Our VP of IT is responsible for approving budgets, cybersecurity incident preparedness, approving cybersecurity processes, reviewing security assessments and other security-related reports, engaging security service providers, and providing the Chief Financial Officer ("CFO") with regular updates on cybersecurity-related matters.
The Company also has an IT Executive Steering Committee comprised of the VP of IT, CFO, General Counsel, Chief Operating Officer and Chief Technology Officer, and Vice President of Operations.
The VP of IT provides regular cybersecurity updates to the Audit Committee.
−Removed: The Company's VP of IT has served in this role for three years and has more than 25 years of relevant experience.
−Removed: In addition, we have an information security team comprised of
−Removed: dozens of employees dedicated to cybersecurity with extensive experience and relevant certifications.
+Added: The Company's VP of IT has served in this role for four years and has more than 25 years of relevant experience.
+Added: In addition, we have an information security team comprised of dozens of employees dedicated to cybersecurity with extensive experience and relevant certifications.
The VP of IT is responsible for hiring appropriate personnel, assisting with the integration of cybersecurity risk considerations into our overall risk management strategy, communicating key priorities to relevant personnel, and mitigating and remediating in the event of a cybersecurity incident.
1 unchanged sentence
Management works with our incident response team to help mitigate and remediate certain escalated cybersecurity incidents.
−Removed: In addition, our incident response and vulnerability management programs include reporting certain cybersecurity incidents to the Audit Committee and, in certain circumstances, to the Board .
+Added: In addition, our incident response and vulnerability management programs include reporting certain cybersecurity incidents to the Audit Committee and, in appropriate circumstances, to the Board .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.