5 unchanged sentences
Our cybersecurity policies, standards, processes and practices are based on recognized frameworks established by the National Institute of Standards and Technology and other applicable industry standards.
−Removed: In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on identifying, assessing, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
+Added: We take a comprehensive, cross-functional approach to cybersecurity that focuses on identifying, detecting and protecting against threats, and effectively responding to and recovering from incidents when they occur.
Risk Management and Strategy
Our cybersecurity program is focused on the following key areas:
−Removed: As discussed in more detail under the heading “Governance” below, the Board of Directors’ oversight of cybersecurity risk management is supported by the Audit Committee, the Risk Committee, our Chief Information Officer (“CIO”), other members of management and management’s Cybersecurity Committee.
+Added: As discussed in more detail under the heading “Governance” below, the Board of Directors’ oversight of cybersecurity risk management is supported by the Audit Committee, the Risk Committee, our Chief Technology Officer (“CTO”), other members of management and management’s Cybersecurity Committee.
Technical Safeguards:
15 unchanged sentences
The Audit Committee and the Board of Directors also receive timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been resolved.
−Removed: The CIO , who acts as our chief information security officer, leads our Cybersecurity Committee.
+Added: The CTO , who acts as our chief information security officer, leads our Cybersecurity Committee.
The Cybersecurity Committee is a multidisciplinary team of corporate and operational leaders who work collaboratively to implement a program designed to protect our information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with our incident response plan.
−Removed: The Cybersecurity Committee reports to our Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”), Chief Operating Officer (“COO”), Senior Vice President,
−Removed: Human Resources ("SVP HR") and Senior Vice President and General Counsel.
−Removed: The CIO, working together with a team of cybersecurity professionals and third-party consultants, monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents, and reports such threats and incidents to the senior leadership team when appropriate.
−Removed: Our CIO has served in various roles in information technology and information security for over 25 years, including serving as the Head of Cybersecurity for public and private companies.
−Removed: Our CIO holds an undergraduate degree in computer science and has attained a professional certification in Cybersecurity Governance.
−Removed: The Cybersecurity team (including the CIO) has extensive cybersecurity experience and hold multiple certifications across the cybersecurity landscape.
−Removed: Our CEO, CFO, COO, SVP HR and Senior Vice President and General Counsel each hold undergraduate degrees, graduate degrees or professional certifications in their respective fields, and each have significant experience managing risk.
+Added: The Cybersecurity Committee reports to our CEO, Chief Financial Officer, Chief Human Resources Officer and Chief Legal Officer.
+Added: The CTO, working together with a team of cybersecurity professionals and third-party consultants, monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents, and reports such threats and incidents to the senior leadership team when appropriate.
+Added: Our CTO has served in various roles in information technology and information security for over 25 years, including serving as the Head of Cybersecurity for public and private companies.
+Added: Our CTO holds an undergraduate degree in computer science and has attained a professional certification in Cybersecurity Governance.
+Added: The Cybersecurity team (including the CTO) has extensive cybersecurity experience and hold multiple certifications across the cybersecurity landscape.
+Added: Our CEO, Chief Financial Officer, Chief Human Resources Officer and Chief Legal Officer each hold undergraduate degrees, graduate degrees or professional certifications in their respective fields, and each have significant experience managing risk.
Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected, and we do not believe are reasonably likely to materially affect, us, including our business strategy, results of operations or financial condition.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.