4 unchanged sentences
We take a multi-faceted approach to identifying and mitigating information security risks.
−Removed: This includes but is not limited to penetration tests of our external network, the utilization of third-party scanning tools to monitor our network, maintenance of software and implementing applicable updates timely, training employees to recognize security risks and encouraging employees to report suspicious activity.
−Removed: Annual cybersecurity awareness training is provided to onshore and offshore users.
−Removed: The training seeks to demonstrate to users the risks in using technology and how to effectively defend against cyber threats.
+Added: This includes, among other things, regular penetration tests of our external network and use of third-party scanning tools to monitor our network;
+Added: maintaining robust patch management protocols to ensure software updates are implemented on a timely basis;
+Added: comprehensive employee awareness programs designed to facilitate recognition of security risks and encourage proactive reporting of suspicious activity.
We assess, identify and manage material risks from cybersecurity threats and vulnerabilities according to our Cybersecurity Incident Response Plan (the “IRP”).
−Removed: The IRP uses the six-stage model of the National Institute of Standards and Technology Cybersecurity Framework (Preparation, Detection, Containment, Investigation, Remediation, and Recovery) to outline steps for reporting, responding, and mitigating various aspects of a cybersecurity incident.
−Removed: Execution of the IRP’s incident response activities are coordinated by the Cybersecurity Incident Response Team, and communications planning via the Helix Crisis Assistance Team and the Cybersecurity Incident Communication Group.
+Added: The IRP uses the six-stage model of the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (Preparation, Detection, Containment, Investigation, Remediation, and Recovery) to outline steps for reporting, responding, and mitigating various aspects of a cybersecurity incident.
+Added: The Cybersecurity Incident Response Team coordinates the execution of activities under the IRP, while communications planning is managed cross-functionally through the Helix Crisis Assistance Team and the Cybersecurity Incident Communication Group.
There are also separate processes in place for the effective management of cyber incidents involving our offshore assets and certain regional business units.
−Removed: We engage external parties to aid in processing and managing cybersecurity incidents as needed, including utilization of the services and expertise of local law enforcement and government entities, partnering financial institutions, a third-party security operations center (“SOC”), and managed service providers.
+Added: To enhance our cybersecurity posture, we engage a range of external specialists and partners to assist in the identification and management of threats .
+Added: This includes leveraging a third-party Security Operations Center (“SOC”) for continuous network monitoring, as well as collaborating with managed service providers, financial institutions, and government and law enforcement entities to share threat intelligence and coordinate incident response efforts.
In addition, we collaborate with our internal auditors to ensure our processes are documented and followed appropriately.
−Removed: In connection with our external SOC and managed service providers, we have implemented change control measures that allow for the continual oversight and assessment of the services provided and threats identified.
+Added: We have processes in place to identify and mitigate cybersecurity risks associated with our use of third-party service providers .
+Added: Our policy requires that each third-party service provider go through a mandatory IT and Information Security Governance processes review and obtain formal approval from our IT and Information Security Governance groups before it can be used.
Notifications and remediation of cyber threats are tracked, reviewed, and archived.
5 unchanged sentences
Risks relating to cybersecurity are overseen by the Audit Committee .
−Removed: Certain members of our management, including the Executive Vice President and Chief Financial Officer (the “CFO”), the Chief Accounting Officer and Corporate Controller (the “CAO”) and the Vice President of Internal Audit, report to the Audit Committee regarding cybersecurity risks.
+Added: Certain members of our management, including the Executive Vice President and Chief Financial Officer (the “CFO”), the Vice President – Finance and Accounting and Chief Accounting Officer (the “CAO”) and the Vice President of Internal Audit, report to the Audit Committee regarding cybersecurity risks.
IT management presents an annual update of cybersecurity related activities to the Audit Committee.
Interim updates are provided to the Audit Committee by the CFO on an as needed basis should an incident warrant immediate notification or escalation.
−Removed: Within Helix’s IT department, several IT management positions are responsible for assessing and managing cybersecurity risk, including the Chief Information Officer, Director of Information Technology and Manager of Information Technology.
−Removed: Each of the IT department’s management personnel has over 20 years of IT experience.
−Removed: The Director of Information Technology and the Manager of Information Technology positions are tasked with the daily and per incident assessment and management of cybersecurity risks, while the Chief Information Officer is tasked with oversight.
−Removed: Helix’s IT department keeps management involved and informed throughout the entire process of any cybersecurity incident from initial monitoring and discovery through the remediation and restoration, all in accordance with the processes outlined in our IRP.
−Removed: Initial notification regarding a cybersecurity incident may come through our third-party SOC or managed service providers, or from employees reporting internally to our IT helpdesk.
−Removed: Investigations are then performed to determine the appropriate actions per the IRP guidelines.
−Removed: Incidents that warrant further escalation are promptly shared with the CFO and continually updated, as appropriate, until remediation and restoration is achieved.
−Removed: Helix’s IT department holds regular quarterly meetings with the CFO, CAO, and Vice President of Internal Audit to recap cybersecurity risks and incidents and to determine any actions required as a result.
+Added: Within Helix’s IT department, several IT management positions are responsible for assessing and managing cybersecurity risk, including the Chief Information Officer, Director of Information Technology and Cybersecurity Manager.
+Added: Each of the IT department’s management personnel has over 20 years of IT and information security experience.
+Added: The Director of Information Technology and the Cybersecurity Manager positions are tasked with the daily and per incident assessment and management of cybersecurity risks, while the Chief Information Officer is tasked with oversight.
+Added: Helix’s IT leadership ensures that senior management is apprised of significant cybersecurity incidents throughout the lifecycle of the event (from initial detection and discovery through remediation and restoration) consistent with the escalation protocols defined in our IRP.
+Added: Helix’s IT department holds regular quarterly meetings with the CFO, CAO, and Vice President of Internal Audit to recap cybersecurity risks and incidents to determine any actions required as a result.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.