2 unchanged sentences
Description of Processes for Assessing, Identifying and Managing Cybersecurity Risks
−Removed: In the ordinary course of business, our information systems on which we run our business operations and store confidential or proprietary data, such as PII about our customers and our employees, are subject to potential cyber-attack.
+Added: In the ordinary course of business, our IT on which we run our business operations and store confidential or proprietary data, such as PII about our customers and our employees, are subject to potential cyber-attack.
The techniques used by cyber attackers change frequently and may be difficult to detect for long periods of time.
1 unchanged sentence
We have implemented security measures that are designed to detect and protect against cyberattacks .
−Removed: Our processes and procedures align with the National Institute of Standards and Technology Cybersecurity Framework.
−Removed: I n particular, we seek to assess, identify and manage cybersecurity risks through the processes described below:
+Added: We endeavor to align our processes and procedures with the National Institute of Standards and Technology Cybersecurity Framework.
+Added: In particular, we seek to assess, identify and manage cybersecurity risks through the processes described below:
Risk Assessment
4 unchanged sentences
Incident Identification and Response
−Removed: A security information and event management process (“SIEM”) has been implemented to help promptly identify cybersecurity incidents.
+Added: A security information and event management process (“SIEM”) has been implemented to help identify cybersecurity incidents.
In the event of any breach or cybersecurity incident, we have an incident response plan within our SIEM that is designed to provide for action to contain the incident, mitigate the impact and restore normal operations efficiently.
−Removed: We conduct annual reviews of our cyber incident response plan.
+Added: Our IT and Security team manages our incident response plan, which establishes a comprehensive system and process for tracking and logging cybersecurity occurrences, reviewing the occurrences to determine whether remediation or escalation is appropriate, and escalating certain occurrences to the Company’s Chief Information Officer (the “CIO”) for further review and assessment.
+Added: We conduct annual exercises and reviews of our cyber incident response plan.
Cybersecurity Training and Awareness
−Removed: Cybersecurity awareness among our employees is promoted with regular training and awareness programs.
−Removed: Employees who access our systems are required to undergo annual cybersecurity training and, each year, employees are required to test their understanding of our cybersecurity policies.
−Removed: Further, our employees that handle PII are required to undergo training, including phishing exercises and awareness programs on the appropriate management, use and protection of that information.
+Added: Cybersecurity awareness among our employees is promoted with regular training and phishing awareness programs.
+Added: Employees who access our systems are required to undergo cybersecurity training and, each year, employees are required to test their understanding of our cybersecurity policies.
+Added: Further, our employees that handle PII are required to undergo specialized training on the appropriate management, use and protection of that information.
Access Controls
11 unchanged sentences
Similarly, we have sought to manage encryption keys with use of a secure key management system and rotation of keys after use.
−Removed: We have implemented secure protocols, including, e.g., hypertext transfer protocol secure for web traffic and secure file transfer protocol for file transfers.
−Removed: Processes designed to monitor cybersecurity incidents are also intended to protect our data.
+Added: We have implemented secure protocols, including, e.g., HTTP secure for web traffic, secure file transfer protocol for file transfers and application programming interfaces.
+Added: Additionally, we have sought to implement processes designed to monitor cybersecurity and protect our data.
Our cybersecurity safeguards, including those provided by third parties, are designed to monitor for unauthorized access.
1 unchanged sentence
We engage several third-party consultants in connection with our risk assessment and risk management, and we have established separate processes and procedures to oversee and identify cybersecurity risks associated with third parties.
−Removed: Finally, we have implemented encrypted virtual private networks for remote connections.
The above cybersecurity risk management processes are integrated into the Company’s overall enterprise risk management program.
1 unchanged sentence
Impact of Risks from Cybersecurity Threats
−Removed: As of the date of this Form 10-K, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company.
+Added: As of the date of this Form 10-K, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, and financial condition.
However, we acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains.
8 unchanged sentences
The Board of Directors oversees risks from cybersecurity threats.
−Removed: The Board of Directors delegates oversight of our operations risk, including quarterly reviews of cybersecurity and data protection, to the Finance/Risk Management Committee, and delegates compliance with cybersecurity policies to the Audit Committee.
+Added: The Board of Directors delegates oversight of our enterprises’ operational risks, including quarterly reviews of cybersecurity and data protection, to the Finance/Risk Management Committee, and delegates compliance with cybersecurity policies to the Audit Committee.
Both the Finance/Risk Management Committee and the Audit Committee report to the full Board of Directors on cybersecurity matters.
1 unchanged sentence
The Finance/Risk Management Committee oversees the formal process to identify risks company-wide, allocate them to the appropriate committee of the Board of Directors, and ensure that risk mitigation activities are being followed.
−Removed: At each of its meetings, the Finance/Risk Management Committee receives presentations from our Chief Information Officer (the “CIO”) on cybersecurity and information security risk, as well as our cybersecurity initiatives.
+Added: At each of its meetings, the Finance/Risk Management Committee receives presentations from our CIO on cybersecurity and information security risk, as well as our cybersecurity initiatives.
The Audit Committee oversees compliance with cybersecurity policies with guidance from members of management, including the Vice President of Internal Audit, who informs the Audit Committee on the audit results of cybersecurity controls.
Management’s Role in Assessing and Managing Cybersecurity Threats
−Removed: Our IT and Security team, which is headed by our CIO , is responsible for our efforts to comply with cybersecurity standards, establish industry-recognized protocols and protect the integrity, confidentiality and availability of our IT infrastructure.
−Removed: Our CIO and various members of the IT and Security team, meet regularly with members of management to address key security and privacy issues.
−Removed: Our CIO has more than 25 years of infrastructure and cybersecurity experience.
−Removed: We also have formed a cyber event incident team, composed of our CIO, Chief Financial Officer, Corporate Controller, Chief Legal Officer and vice president of Internal Audit, who, upon the occurrence of a cybersecurity incident, convene to assess the materiality of the event as well as the appropriate remediation and escalation procedures, including escalation to our Chief Executive Officer, the Finance/Risk Management Committee, the Audit Committee and the Board of Directors.
+Added: Our CIO is responsible for assessing and managing the Company’s material risks from cybersecurity threats, including our efforts to comply with cybersecurity standards, establish industry-recognized protocols and protect the integrity, confidentiality and availability of our IT infrastructure.
+Added: The CIO is supported by the IT and Security team.
+Added: Our CIO and various members of the IT and Security team meet regularly to address key security and privacy issues.
+Added: Our CIO reports to our Chief Financial Officer and has more than 26 years of infrastructure and cybersecurity experience, having served in various technology leadership roles at the Company since joining in 1999.
+Added: The Company has an established review and escalation process for assessing cybersecurity occurrences, and if necessary, escalating cybersecurity incidents to members of our senior management team and Board of Directors.
Our internal audit department additionally conducts regular audits to assess management’s processes and controls employed to identify and manage material cybersecurity risks .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.