2 unchanged sentences
Risk Management, Strategy and Governance
−Removed: The Trust has no employees or internal information
−Removed: systems and is managed by the Sponsor.
−Removed: Thus, the Trust relies on the Sponsor and VanEck, the parent company of the Sponsor, as well as
−Removed: the Bitcoin Custodian and Additional Bitcoin Custodian and other service providers to protect the Trust’s information from cybersecurity
−Removed: VanEck has policies, standards, and procedures on information security (the “Cybersecurity Documents”).
−Removed: The Cybersecurity
−Removed: Documents govern the procurement, use, storage, protection and permissions of data systems, applications and devices.
−Removed: The Cybersecurity
−Removed: Documents outline the correct usage of elements
−Removed: and tasks on the networks/infrastructure to
−Removed: ensure safe operation, high availability, performance, and data accuracy.
−Removed: VanEck has adopted the National Institute of
−Removed: Standards and Technology’s (“NIST”) cybersecurity framework as its security outline.
+Added: has no employees or internal information systems and is managed by the Sponsor.
+Added: Thus, the Trust relies on the Sponsor and VanEck,
+Added: the parent company of the Sponsor, as well as the Bitcoin Custodian and Additional Bitcoin Custodian and other service providers
+Added: to protect the Trust’s information from cybersecurity threats.
+Added: VanEck has policies, standards, and procedures on information
+Added: security (the “Cybersecurity Documents”).
+Added: The Cybersecurity Documents govern the procurement, use, storage, protection
+Added: and permissions of data systems, applications and devices.
+Added: The Cybersecurity Documents outline the correct usage of elements
+Added: and tasks on the networks/infrastructure to ensure safe operation,
+Added: high availability, performance, and data accuracy.
+Added: VanEck has adopted the National Institute of Standards and Technology’s
+Added: (“NIST”) cybersecurity framework as its security outline.
The program is reviewed annually.
−Removed: Using the NIST framework as a guide, VanEck’s cybersecurity program is organized around the following program domains:
+Added: Using the NIST framework
+Added: as a guide, VanEck’s cybersecurity program is organized around the following program domains:
● Identify critical assets, data, systems and capabilities, cybersecurity strategy and governing elements, threats and cybersecurity
1 unchanged sentence
● Detect anomalies and security events through environments monitoring, analysis, remediation, and reporting.
−Removed: Engage outside vendors
−Removed: to periodically test the network infrastructure and software applications against known vulnerabilities and to ensure the use of a best
−Removed: practice security program
+Added: Engage outside
+Added: vendors to periodically test the network infrastructure and software applications against known vulnerabilities and to ensure the
+Added: use of a best practice security program
● Respond to incidents regardless of source or causality
● Recover through planning, improvements and communications (external and internal)
−Removed: ● Conduct after-action evaluation to identify what went well, what did not go well and improve VanEck systems on the back of an issue
−Removed: VanEck employs third-party firms to assess its
−Removed: cybersecurity posture, conduct penetration testing, and forensic analysis.
−Removed: VanEck maintains a risk-based approach to identifying
−Removed: and overseeing cybersecurity risks presented by third parties , including vendors, service providers, counterparties and clients, as well
−Removed: as the systems of third parties that could significantly and adversely impact VanEck’s business in the event of a cybersecurity
−Removed: incident affecting those third-party systems.
−Removed: Third-party risks are included within VanEck’s NIST framework, and risk identification
−Removed: and mitigation are supported by VanEck’s cybersecurity program.
−Removed: VanEck also performs diligence on certain third parties and monitors
−Removed: cybersecurity threats and risks identified through such diligence.
+Added: ● Conduct after-action evaluation to identify what went well, what did not go well and improve VanEck systems on the back of
+Added: VanEck employs third-party firms to assess
+Added: its cybersecurity posture, conduct penetration testing, and forensic analysis.
+Added: VanEck maintains a risk-based approach to
+Added: identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers, counterparties
+Added: and clients, as well as the systems of third parties that could significantly and adversely impact VanEck’s business in the
+Added: event of a cybersecurity incident affecting those third-party systems.
+Added: Third-party risks are included within VanEck’s NIST
+Added: framework, and risk identification and mitigation are supported by VanEck’s cybersecurity program.
+Added: VanEck also performs diligence
+Added: on certain third parties and monitors cybersecurity threats and risks identified through such diligence.
Roles and Responsibilities
−Removed: Roles and responsibilities for cybersecurity have
−Removed: been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of the firm and
−Removed: VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level employees.
+Added: Roles and responsibilities for cybersecurity
+Added: have been established first by VanEck’s cybersecurity policy and secondly by its connection to the governance structure of
+Added: the firm and VanEck’s risk management committee (the “Risk Management Committee”), which is comprised of senior-level
Cybersecurity is closely aligned with not only risk management, but also with business continuity planning and response.
−Removed: the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated to the staff
−Removed: Specifically, VanEck’s Chief Information Security Officer, reporting to the co-chair of the Risk Management Committee,
−Removed: is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations with a special
−Removed: emphasis on proper desktop and email security and conduct.
−Removed: Special training is also given to recently on-boarded staff.
−Removed: Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information Security Officer, are responsible
−Removed: for the day-to-day operations of the firm cybersecurity infrastructure including normal operations as well as any remedial work required
−Removed: in response to an incident.
−Removed: The communication responsibility in the event of an incident is shared by VanEck’s CEO and the General
−Removed: Since our commencement of operations, we have not
−Removed: experienced a material information security breach incident and we are not aware of any cybersecurity risks that are reasonably likely
−Removed: to materially affect our business.
−Removed: However, future incidents could have a material impact on our business strategy, results of
−Removed: operations, or financial condition.
+Added: In addition, the importance of cybersecurity protection and its practice at the manager and employee level is frequently communicated
+Added: to the staff globally.
+Added: Specifically, VanEck’s Chief Information Security Officer , reporting to the co-chair of the Risk Management
+Added: Committee, is responsible for conducting the firm’s cybersecurity risk assessment, as well as providing regular staff educations
+Added: with a special emphasis on proper desktop
+Added: and email security and conduct.
+Added: Special training is also given to recently on-boarded
+Added: VanEck’s Chief Administrative Officer and Chief Technology Officer, together with VanEck’s Chief Information
+Added: Security Officer, are responsible for the day-to-day operations of the firm cybersecurity infrastructure including normal operations
+Added: as well as any remedial work required in response to an incident.
+Added: The communication responsibility in the event of an incident
+Added: is shared by VanEck’s CEO and the General Counsel.
+Added: our commencement of operations, we have not experienced a material information security breach incident and we are not aware of
+Added: any cybersecurity risks that are reasonably likely to materially affect our business.
+Added: However, future incidents could have a material
+Added: impact on our business strategy, results of operations,
+Added: or financial condition.
See “Item 1A.
−Removed: Risk Factors—
−Removed: Other Risks—Due to the increased use of technologies, intentional and unintentional cyber-attacks pose operational and information
−Removed: security risks.”
+Added: Risk Factors— Other Risks—Due to the increased use of technologies,
+Added: intentional and unintentional cyber-attacks pose operational and information security risks.”
Not applicable.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.