7 unchanged sentences
Following these risk assessments, we re-design, implement, and maintain reasonable safeguards to minimize identified risks, reasonably address any identified gaps in existing safeguards, and regularly monitor the effectiveness of our safeguards.
−Removed: We devote significant resources and designate high-level personnel, including our Chief Information Officer ("CIO") who reports to our Chief Financial Officer, to manage the risk assessment and mitigation process.
+Added: We devote significant resources and designate high-level personnel to manage the risk assessment and mitigation process.
We engage consultants and other third parties in connection with our risk assessment policies and processes.
6 unchanged sentences
Our Board of Directors administers its cybersecurity risk oversight function primarily through the Audit Committee.
−Removed: Our CIO provides periodic briefings to the Audit Committee regarding our cybersecurity risks and activities, including any recent cybersecurity incidents and related responses, cybersecurity policies and procedures, activities of third parties, and the like.
−Removed: Our CIO is primarily responsible to assess and manage our material risks from cybersecurity threats.
−Removed: Our CIO has over 25 years of professional IT experience and has held numerous positions with responsibility for managing network and data security, including in the legal and banking industries.
−Removed: Our CIO oversees our cybersecurity policies and processes, including those described in "Risk Management and Strategy" above.
−Removed: The processes by which our CIO is informed of and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents include log review from IT and operations teams or reports received from network systems and applications if any unusual activity occurs, such as email system notification of items opened that could be malicious.
+Added: Our CFO, who oversees the information technology department as led by our Director of Information Technology, provides periodic briefings to the Audit Committee regarding our cybersecurity risks and activities, including any recent cybersecurity incidents and related responses, cybersecurity policies and procedures, activities of third parties, and the like.
+Added: Our Director of Information Technology and the Information Technology team are primarily responsible for assessing and managing our material risks from cybersecurity threats.
+Added: The collective team has extensive experience in information security and cybersecurity risk management, and they monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents on an ongoing basis using a combination of security tooling, automated systems and manual processes, including information technology log reviews from across teams or reports received from network systems and applications if any unusual activity occurs, such as email system notification of items opened that could be malicious.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.