4 unchanged sentences
The techniques used by cyber attackers change frequently and may be difficult to detect for long periods of time.
−Removed: See “Risk Factors” for additional information about the risks to our business associated with a breach or compromise to our information technology (“IT”) systems.
+Added: Risk Factors for additional information about the risks to our business associated with a breach or compromise to our IT systems.
We have implemented security measures that are designed to detect and protect against cyberattacks .
−Removed: In particular, we seek to assess, identify and manage cybersecurity risks through the processes described below:
+Added: Our processes and procedures align with the National Institute of Standards and Technology Cybersecurity Framework.
+Added: I n particular, we seek to assess, identify and manage cybersecurity risks through the processes described below:
Risk Assessment
10 unchanged sentences
Employees who access our systems are required to undergo annual cybersecurity training and, each year, employees are required to test their understanding of our cybersecurity policies.
−Removed: Further, our employees that handle personally identifiable information are required to undergo training, including phishing exercises and awareness programs on the appropriate management, use and protection of that information.
+Added: Further, our employees that handle PII are required to undergo training, including phishing exercises and awareness programs on the appropriate management, use and protection of that information.
Access Controls
8 unchanged sentences
We also have a program in place to monitor our retained data by identifying PII and ensuring it is not stored outside of approved locations and systems.
+Added: We maintain policies that govern the deletion of PII to limit the information exposed to a potential cyberattack.
We have endeavored to use strong, up-to-date encryption algorithms and to regularly update and patch systems in an effort to guard against vulnerabilities.
Similarly, we have sought to manage encryption keys with use of a secure key management system and rotation of keys after use.
−Removed: We have implemented secure protocols, including, e.g., HTTPS for web traffic and SFTP for file transfers.
−Removed: Processes designed to monitor for cybersecurity incidents are also intended to protect our data.
+Added: We have implemented secure protocols, including, e.g., hypertext transfer protocol secure for web traffic and secure file transfer protocol for file transfers.
+Added: Processes designed to monitor cybersecurity incidents are also intended to protect our data.
Our cybersecurity safeguards, including those provided by third parties, are designed to monitor for unauthorized access.
−Removed: These services are designed to monitor for both internal and external threats.
+Added: These services are designed to monitor both internal and external threats.
+Added: We engage several third-party consultants in connection with our risk assessment and risk management, and we have established separate processes and procedures to oversee and identify cybersecurity risks associated with third parties.
Finally, we have implemented encrypted virtual private networks for remote connections.
2 unchanged sentences
Impact of Risks from Cybersecurity Threats
−Removed: As of the date of this Report, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company.
+Added: As of the date of this Form 10-K, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company.
However, we acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains.
−Removed: Processes designed to monitor for cybersecurity incidents are also intended to protect our data.
+Added: Our processes designed to monitor cybersecurity incidents are also intended to protect our data.
Our cybersecurity safeguards, including those provided by third parties, are designed to monitor for unauthorized access, extraction, and deletion of certain sensitive data, large quantities of data, and other anomalous network traffic.
−Removed: These services are designed to monitor for both internal and external threats.
+Added: These services are designed to monitor both internal and external threats.
Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cyberattack will not occur.
1 unchanged sentence
While we devote resources to our security measures to protect our systems and information, these measures cannot provide absolute security.
−Removed: See “Risk Factors” for additional information about the risks to our business associated with a breach or compromise to our IT systems.
+Added: Risk Factors for additional information about the risks to our business associated with a breach or compromise to our IT systems.
Board of Directors’ Oversight of Risks from Cybersecurity Threats
9 unchanged sentences
Our CIO and various members of the IT and Security team, meet regularly with members of management to address key security and privacy issues.
−Removed: Our CIO has more than 24 years of infrastructure and cybersecurity experience and holds various relevant certifications.
−Removed: We also have formed a cyber event incident team, composed of our CIO, Chief Financial Officer, Corporate Controller, Chief Legal Officer and vice president of Internal Audit, who upon the occurrence of a cybersecurity incident, would convene to assess the materiality of the event as well as the appropriate remediation and escalation procedures, including escalation to our Chief Executive Officer and the Board of Directors.
+Added: Our CIO has more than 25 years of infrastructure and cybersecurity experience.
+Added: We also have formed a cyber event incident team, composed of our CIO, Chief Financial Officer, Corporate Controller, Chief Legal Officer and vice president of Internal Audit, who, upon the occurrence of a cybersecurity incident, convene to assess the materiality of the event as well as the appropriate remediation and escalation procedures, including escalation to our Chief Executive Officer, the Finance/Risk Management Committee, the Audit Committee and the Board of Directors.
Our internal audit department additionally conducts regular audits to assess management’s processes and controls employed to identify and manage material cybersecurity risks .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.