12 unchanged sentences
The Company requires all employees to complete cybersecurity training semi-annually and periodically facilitates penetration tests on the Company's systems.
−Removed: The Company’s Chief Technology Officer reports to the Executive Vice President – Operations.
+Added: The Company’s Chief Technology Officer reports to the Company’s Executive Vice President and Chief Administrative Officer.
In addition, as discussed in more detail below, any cybersecurity incident is reported to the Company’s legal department.
−Removed: Company’s Executive Vice President – Operations and the members of its legal department do not have a technology services background, we believe that the Company’s Chief Technology Officer and technology services team possess the requisite background and experience to effectively manage the Company’s cybersecurity needs.
+Added: Although the Company’s Executive Vice President and Chief Administrative Officer and the members of its legal department do not have a technology services background, we believe that the Company’s Chief Technology Officer and technology services team possess the requisite background and experience to effectively manage the Company’s cybersecurity needs.
+Added: The Company's Chief Technology Officer has extensive information technology and program management experience from service in the government and private and public Fortune 100 companies.
+Added: He has expanded the Company's cybersecurity program over the last several years resulting in a robust enterprise security posture focused on preventing cybersecurity incidents, while simultaneously increasing the Company's system resilience in an effort to minimize the business impact if an incident should occur.
The Company also engages with third parties on an as-needed basis to advise and assist in managing cybersecurity risks.
2 unchanged sentences
Procedures for addressing cybersecurity incidents include reporting incidents up to senior management, including the Company’s legal department for analysis.
−Removed: If a cybersecurity incident were determined to be material, the Company’s disclosure committee would address appropriate public disclosures.
+Added: If a cybersecurity incident were determined to be material by the Company's legal department, the Company’s Audit Committee would be informed promptly and the Company’s disclosure committee would address appropriate public disclosures.
As noted above, management regularly reports to the Audit Committee regarding the current cyber threat environment and the controls and procedures meant to address such risks.
−Removed: If a cybersecurity incident were determined to be material, the Audit Committee would be informed promptly.
The Company carries cyber risk insurance, but there can be no assurance that losses from a cybersecurity incident would not exceed the insurance coverage.
−Removed: The Company is subject to risks associated with cybersecurity threats.
Although the Company has not experienced a cybersecurity incident that materially affected or, to the Company’s knowledge, is reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition, the Company has, from time to time, experienced threats to and breaches of its data and systems.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.