2 unchanged sentences
Risk Management and Strategy
−Removed: We promote a company-wide culture of cybersecurity risk management to ensure that cybersecurity risk considerations are an integral part of decision-making at every level.
−Removed: We have implemented cyber defenses to safeguard our information systems and protect the confidentiality, integrity and availability of our data.
−Removed: Our information technology (IT) department continuously evaluates whether our cybersecurity risk management is aligned with our business objectives and operational needs.
−Removed: Our cybersecurity program is comprehensive in scope and covers the systems supporting our various lines of business.
−Removed: Our cybersecurity program follows the National Institute of Standards and Technology, as well as the Cybersecurity and Infrastructure Security Agency frameworks.
−Removed: Additionally, we follow federal and state statutory and regulatory guidance and have adopted internal policies and standards in alignment with these federal and state requirements.
+Added: We promote a company-wide culture of cybersecurity risk management to ensure that cybersecurity risk considerations are an integral part of decision-making at all organizational levels.
+Added: To protect the confidentiality, integrity and availability of our data and information systems, we have implemented cyber defenses and continuously enhance them to address evolving threats.
+Added: Our information technology (IT) department actively monitors and evaluates our cybersecurity practices to ensure alignment with our business objectives and operational needs.
+Added: Our cybersecurity program is comprehensive in scope and covers the systems supporting all our business operations.
+Added: Our program is built on industry-standard frameworks, including the National Institute of Standards and Technology, and the Cybersecurity and Infrastructure Security Agency.
+Added: We also follow applicable federal and state statutory and regulatory guidance and have adopted internal policies and standards in alignment with these federal and state requirements.
Furthermore, we collaborate with external experts, consultants and auditors in routinely evaluating and testing our information systems controls.
−Removed: We also perform an annual cyber table-top exercise with a regulatory agency to help us test and continue to develop our Cyber Incident Response Plan.
−Removed: Our cybersecurity program includes a well-documented process for oversight of cybersecurity risks associated with our third-party service providers.
−Removed: We evaluate our third parties prior to any engagements.
−Removed: We also request System and Organization Controls reports from our third-party vendors to obtain reasonable assurance that their controls are present and functioning.
−Removed: Our IT policies communicate our expectations of employees and contractors to maintain the security of our IT systems.
−Removed: We perform annual cyber security training to remind our employees about the importance of keeping our systems safe, and perform regular third-party phishing campaigns.
+Added: We also perform an annual pen-testing, cyber table-top exercise to help us test and refine our formal Cyber Incident Response Plan.
+Added: We maintain a well-documented process to oversee cybersecurity risks associated with our third-party service providers.
+Added: We evaluate our third parties prior to any engagements and review their System and Organization Controls reports to obtain reasonable assurance that their controls meet our security standards.
+Added: Our IT policies communicate our expectations for employees and contractors regarding the security of our IT systems.
+Added: We perform annual cyber security and technology processes training programs and regular third-party phishing campaigns to raise awareness of potential threats.
The Audit Committee of the Board of Directors has oversight of management's efforts with respect to IT systems and cybersecurity.
−Removed: As part of this oversight, the company's IT leadership meets on a quarterly basis with the Audit Committee and on an annual basis with the company's Board of Directors.
−Removed: During these update meetings, IT leadership provides the Audit Committee and Board of Directors updates regarding any changes around our cyber defenses, ongoing IT initiatives, and emerging threats and plans to pro-actively encounter these threats.
+Added: As part of this oversight, the company's IT leader meets on a quarterly basis with the Audit Committee and on an annual basis with the company's Board of Directors.
+Added: During these update meetings, IT provides the Audit Committee and
+Added: Board of Directors updates regarding any changes around our cyber defenses, ongoing IT initiatives, and emerging threats and plans to pro-actively counter these threats.
Management continuously monitors the effectiveness of our cybersecurity defenses.
We invest in regular and ongoing cybersecurity training for our IT department and company overall.
−Removed: Our Senior Vice President Business Technology has certain IT industry certifications and brings 30 years of IT background spanning all facets of technology, including applications, infrastructure and cybersecurity.
+Added: Our Senior Vice President Business Technology has IT industry certifications and brings over 30 years of IT background spanning all facets of technology, including applications, infrastructure and cybersecurity.
Our Director of IT Security has over 20 years of experience in cybersecurity, including duties as an Information Security Officer in the United States Air Force.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.