UNRESOLVED STAFF COMMENTS
−Removed: We have received no written comments regarding our periodic or current reports from the staff of the SEC that were issued 180 days or more preceding the end of fiscal year 2024.
CYBERSECURITY
1 unchanged sentence
We employ a risk-based information security process aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework to identify, prioritize and mitigate cyber risks.
−Removed: The cybersecurity program is part of our broader enterprise risk management program.
Risk Management and Governance
2 unchanged sentences
Our Audit Committee plays a significant role in oversight of risks, including cybersecurity.
−Removed: At least quarterly, the Audit Committee receives an update on cybersecurity matters from the Company’s Senior Vice President of Information Technologies and Engineering and our information security leadership.
+Added: At least quarterly, the Audit Committee receives an update on cybersecurity matters from the Company’s Senior Vice President of Information Technologies and Engineering and our Vice President & Global Chief Information Security Officer (“CISO”).
These updates address a broad spectrum of cybersecurity topics including recent developments, evolving technology practices, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends, cybersecurity considerations arising with respect to the Company’s third-party service providers, and other cybersecurity considerations.
2 unchanged sentences
Cybersecurity incidents determined to be material are reported to the Board of Directors promptly following such determination.
−Removed: 2024 FORM 10-K | 40
−Removed: Our Director of IT Governance and Response, who manages our cybersecurity program, is currently on leave and expects to retire from the Company in January 2025.
−Removed: During this time and until we appoint a new Director of IT Governance and Response, our Vice President - Information Technology ("VP-IT"), who has extensive cybersecurity knowledge and skills gained from 25 years of information technology work experience at the Company and elsewhere, has assumed responsibilities for this role with the assistance of a third party security leadership service.
−Removed: The VP-IT reports directly to our Senior Vice President of Information Technology and Engineering, who provides oversight of cybersecurity risk and mitigation strategies.
−Removed: Our cybersecurity and information technology teams actively maintain a register of risks and mitigation measures under the umbrella of our enterprise risk management program.
+Added: Our CISO has over 20 years of experience in information security and global compliance.
+Added: The CISO reports directly to our Senior Vice President of Information Technology and Engineering, who provides oversight of cybersecurity, risk, mitigation strategies, and governance.
+Added: Our CISO oversees an internal cross-functional information technology governance, risk, and compliance team that actively maintains a register of risks and mitigation measures under the umbrella of our enterprise risk management program.
Our enterprise risk management program is designed to identify and monitor risks to the Company, assess the Company’s risk mitigation plans, and consult on further measures that can be taken to address new and existing risks.
−Removed: Our Enterprise Risk Management Committee, which meets quarterly, is comprised of our executive officers, Senior Vice President of Information Technologies and Engineering, Chief Accounting Officer, Vice President of Internal Audit, Corporate Secretary, and Director – Risk Management & Insurance.
+Added: Our Enterprise Risk Management Committee, which meets quarterly, is comprised of our executive officers, Senior Vice President of Information Technologies and Engineering, CISO, Chief Accounting Officer, Vice President of Internal Audit, Corporate Secretary, and Director – Risk Management & Insurance.
Our Risk Management and Insurance Department is responsible for the implementation of our enterprise risk management program and maintains a register of risks and initiates reviews and assessments.
The Director of Risk Management and Insurance reports to the Audit Committee and full Board on a quarterly basis.
+Added: 2025 FORM 10-K | 36
Cybersecurity Program
13 unchanged sentences
Our CIR Process is a formalized approach following the NIST framework for evaluating cybersecurity incidents and prioritizing response efforts based on established criteria.
−Removed: The key components of the CIR Process includes:
+Added: The key components of the CIR Process include:
• Cybersecurity incident prioritization
2 unchanged sentences
• A formalized methodology for evaluating the impact of cybersecurity incidents
−Removed: 2024 FORM 10-K | 41
The Cyber Review Committee (“Cyber Committee”) is a sub-committee of our Disclosure Committee comprised of our Chief Accounting Officer;
Senior Vice President of Information Technology and Engineering;
−Removed: General Counsel;
+Added: general counsels;
Vice President – Investor Relations;
Director – Risk Management & Insurance;
−Removed: and Director – Global Security & Administration.
+Added: and Vice President – Global Security & Administration.
Pursuant to the CIR Process, cybersecurity incidents classified as high priority are reported to the Cyber Committee.
5 unchanged sentences
• based on materiality analysis, making a recommendation to the Chief Executive Officer and Chief Financial Officer that an incident should be deemed material
+Added: 2025 FORM 10-K | 37
Material Cybersecurity Risks and Threats
−Removed: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition, and we do not believe that such risks are reasonably likely to have such an effect over the long term.
+Added: Risks from cybersecurity threats, including any previous cybersecurity incidents, have not materially affected us , including our business strategy, results of operations or financial condition, and we do not believe that such risks are reasonably likely to have such an effect over the long term.
While we have not experienced any material cybersecurity threats or incidents, there can be no guarantee that we will not be the subject of future successful attacks, threats or incidents.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.