8 unchanged sentences
• Annual internal/external penetration testing conducted by a third-party offensive security vendor.
−Removed: A significant cybersecurity incident may result from actions by our employees, suppliers, third-party administrators, or unknown third parties or through cyber-attacks and could affect our data framework or cause a failure to protect the personal information of our customers, suppliers or employees, or sensitive and confidential information regarding our business and
−Removed: could give rise to legal liability and regulatory action under data protection and privacy laws.
+Added: A significant cybersecurity incident may result from actions by our employees, suppliers, third-party administrators, or unknown third parties or through cyber-attacks and could affect our data framework or cause a failure to protect the personal information of our customers, suppliers or employees, or sensitive and confidential information regarding our business and could give rise to legal liability and regulatory action under data protection and privacy laws.
The Company describes whether and how risks from identified cybersecurity threats have materially affected or are reasonably likely to materially affect the Company under the heading “ We rely on technology in our business and any cybersecurity incident, other technology disruption or delay in implementing new technology could negatively affect our business and our relationships with customers ,” in Item 1A of this Annual Report on Form 10-K.
−Removed: To date, there have not been any cybersecurity threats or incidents that have materially affected, or are reasonably likely to materially affect, the Company, including its financial condition, results of operations, or business strategies.
+Added: To date, there have not been any cybersecurity threats or incidents that have materially affected, or
+Added: are reasonably likely to materially affect, the Company, including its financial condition, results of operations, or business strategies.
Our Board of Directors oversees our overall risk management strategy.
−Removed: Our information security program is managed by our Senior Vice President of People and Technology , who has twenty-five years of experience in IT leadership across a variety of industries including manufacturing, distribution, defense, and financial services, whose team is responsible for maintaining our enterprise-wide cybersecurity strategy, policies, standards, architecture and processes.
+Added: Our information security program is managed by our Senior Vice President of People and Technology , who has over twenty-five years of experience in IT leadership across a variety of industries including manufacturing, distribution, defense, and financial services, whose team is responsible for maintaining our enterprise-wide cybersecurity strategy, policies, standards, architecture and processes.
Our program is assessed both internally and externally by third parties, including our virtual Chief Information Security Officer (“vCISO”) partner.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.