Unresolved Staff Comments
−Removed: HHH 2024 FORM 10-K | 24
Cybersecurity
−Removed: Index to Financial Statements
−Removed: Cybersecurity
Risk Management and Strategy The HHH cybersecurity program is an enterprise-wide, risk-based program that is designed to support the security, confidentiality, integrity, and availability of our systems and information.
20 unchanged sentences
He is also responsible for maintaining and, in the event of an actual or suspected security incident, executing the Company’s incident response plan.
−Removed: The Board of Directors’ Technology Committee governs and oversees HHH’s cybersecurity program.
+Added: The Board of Directors’ Audit Committee governs and oversees HHH’s cybersecurity program.
This includes reviewing the cybersecurity program’s strategy and effectiveness, the cybersecurity landscape and emerging threats, and reports from any cybersecurity events.
−Removed: The Technology Committee also oversees cybersecurity and digital strategy and, whenever necessary, will communicate with, or advise management to consult with, the Audit Committee regarding technology, digital, and other innovation-related matters that relate to or affect the Company’s internal control systems.
−Removed: The Technology Committee will actively participate in strategic cybersecurity decisions and will be responsible for approving major initiatives.
−Removed: Management will provide updates to the Technology Committee on a quarterly basis and will continue to provide updates to the full Board of Directors on an annual basis.
−Removed: When appropriate, the Technology Committee will inform the Board of Directors on important matters.
+Added: The Audit Committee also oversees cybersecurity and digital strategy and other innovation-related matters that relate to or affect the Company’s internal control systems.
+Added: Management provides updates to the Audit Committee on a quarterly basis.
+Added: When appropriate, the Audit Committee will inform the Board of Directors on important matters.
Furthermore, the Board of Directors would be notified in accordance with the Company’s incident response plan, of any suspected cyber incidents that may have at least a moderate business impact on the Company.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.