2 unchanged sentences
Risk Management, Strategy and Governance
−Removed: The Trust has no employees or internal
−Removed: information systems and is managed by the Sponsor.
−Removed: Thus, the Trust relies on the Sponsor and VanEck, the parent company of the
−Removed: Sponsor, as well as the Bitcoin Custodian and other service providers to protect the Trust’s information from cybersecurity
+Added: The Trust has no employees or internal information
+Added: systems and is managed by the Sponsor.
+Added: Thus, the Trust relies on the Sponsor and VanEck, the parent company of the Sponsor, as well as
+Added: the Bitcoin Custodian and Additional Bitcoin Custodian and other service providers to protect the Trust’s information from cybersecurity
VanEck has policies, standards, and procedures on information security (the “Cybersecurity Documents”).
−Removed: Cybersecurity Documents govern the procurement, use, storage, protection and permissions of data systems, applications and devices.
−Removed: The Cybersecurity Documents outline the correct usage of elements
−Removed: and tasks on the networks/infrastructure
−Removed: to ensure safe operation, high availability, performance, and data accuracy.
−Removed: VanEck has adopted the National Institute
−Removed: of Standards and Technology’s (“NIST”) cybersecurity framework as its security outline.
−Removed: The program is reviewed
+Added: The Cybersecurity
+Added: Documents govern the procurement, use, storage, protection and permissions of data systems, applications and devices.
+Added: The Cybersecurity
+Added: Documents outline the correct usage of elements
+Added: and tasks on the networks/infrastructure to
+Added: ensure safe operation, high availability, performance, and data accuracy.
+Added: VanEck has adopted the National Institute of
+Added: Standards and Technology’s (“NIST”) cybersecurity framework as its security outline.
+Added: The program is reviewed annually.
Using the NIST framework as a guide, VanEck’s cybersecurity program is organized around the following program domains:
−Removed: critical assets, data, systems and capabilities, cybersecurity strategy and governing
−Removed: elements, threats and cybersecurity risks
−Removed: assets (data, systems, networks, personnel, etc.) from external or internal malicious actors and failed practices
−Removed: anomalies and security events through environments monitoring, analysis, remediation, and reporting.
−Removed: Engage outside vendors to
−Removed: periodically test the network infrastructure and software applications against known vulnerabilities and to ensure the use of
−Removed: a best practice security program
−Removed: incidents regardless of source or causality
−Removed: through planning, improvements and communications (external and internal)
−Removed: after-action evaluation to identify what went well, what did not go well and improve VanEck systems on the back of an issue
−Removed: VanEck employs third-party firms to assess
−Removed: its cybersecurity posture, conduct penetration testing, and forensic analysis.
−Removed: VanEck maintains a risk-based approach to
−Removed: identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers, counterparties
−Removed: and clients, as well as the systems of third parties that could significantly and adversely impact VanEck’s business in the
−Removed: event of a cybersecurity incident affecting those third-party systems.
−Removed: Third-party risks are included within VanEck’s NIST
−Removed: framework, and risk identification and mitigation are supported by VanEck’s cybersecurity program.
−Removed: VanEck also performs diligence
−Removed: on certain third parties and monitors cybersecurity threats and risks identified through such diligence.
+Added: ● Identify critical assets, data, systems and capabilities, cybersecurity strategy and governing elements, threats and cybersecurity
+Added: ● Protect assets (data, systems, networks, personnel, etc.) from external or internal malicious actors and failed practices
+Added: ● Detect anomalies and security events through environments monitoring, analysis, remediation, and reporting.
+Added: Engage outside vendors
+Added: to periodically test the network infrastructure and software applications against known vulnerabilities and to ensure the use of a best
+Added: practice security program
+Added: ● Respond to incidents regardless of source or causality
+Added: ● Recover through planning, improvements and communications (external and internal)
+Added: ● Conduct after-action evaluation to identify what went well, what did not go well and improve VanEck systems on the back of an issue
+Added: VanEck employs third-party firms to assess its
+Added: cybersecurity posture, conduct penetration testing, and forensic analysis.
+Added: VanEck maintains a risk-based approach to identifying
+Added: and overseeing cybersecurity risks presented by third parties , including vendors, service providers, counterparties and clients, as well
+Added: as the systems of third parties that could significantly and adversely impact VanEck’s business in the event of a cybersecurity
+Added: incident affecting those third-party systems.
+Added: Third-party risks are included within VanEck’s NIST framework, and risk identification
+Added: and mitigation are supported by VanEck’s cybersecurity program.
+Added: VanEck also performs diligence on certain third parties and monitors
+Added: cybersecurity threats and risks identified through such diligence.
Roles and Responsibilities
−Removed: Roles and responsibilities for cybersecurity
−Removed: have been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of
−Removed: the firm and VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level
+Added: Roles and responsibilities for cybersecurity have
+Added: been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of the firm and
+Added: VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level employees.
Cybersecurity is closely aligned with not only risk management, but also with business continuity planning and response.
−Removed: In addition, the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated
−Removed: to the staff globally.
−Removed: Specifically, VanEck’s Chief Information Security Officer, reporting to the co-chair of the Risk Management
−Removed: Committee, is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations
−Removed: with a special emphasis on proper desktop and email security and conduct.
−Removed: Special training is also given to recently on-boarded
−Removed: VanEck’s Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information
−Removed: Security Officer, are responsible for the day-to-day operations of the firm cybersecurity infrastructure including normal operations
−Removed: as well as any remedial work required in response to an incident.
−Removed: The communication responsibility in the event of an incident
−Removed: is shared by VanEck’s CEO and the General Counsel.
−Removed: Since our commencement of operations, we have not experienced
−Removed: a material information security breach incident and we are not aware of any cybersecurity risks that are reasonably likely to materially
−Removed: affect our business.
+Added: the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated to the staff
+Added: Specifically, VanEck’s Chief Information Security Officer, reporting to the co-chair of the Risk Management Committee,
+Added: is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations with a special
+Added: emphasis on proper desktop and email security and conduct.
+Added: Special training is also given to recently on-boarded staff.
+Added: Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information Security Officer, are responsible
+Added: for the day-to-day operations of the firm cybersecurity infrastructure including normal operations as well as any remedial work required
+Added: in response to an incident.
+Added: The communication responsibility in the event of an incident is shared by VanEck’s CEO and the General
+Added: Since our commencement of operations, we have not
+Added: experienced a material information security breach incident and we are not aware of any cybersecurity risks that are reasonably likely
+Added: to materially affect our business.
However, future incidents could have a material impact on our business strategy, results of
1 unchanged sentence
See “Item 1A.
−Removed: Factors— Other Risks—Due to the increased use of technologies, intentional and unintentional cyber-attacks pose operational
−Removed: and information security risks.”
+Added: Risk Factors—
+Added: Other Risks—Due to the increased use of technologies, intentional and unintentional cyber-attacks pose operational and information
+Added: security risks.”
Not applicable.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.