4 unchanged sentences
The Audit Committee of the Company’s Board of Directors has oversight in the management of risks associated with cybersecurity.
−Removed: The Audit Committee is briefed regularly on cybersecurity matters, including meeting with the Company’s Chief Technology Officer at least annually and receiving a memorandum quarterly regarding cybersecurity.
+Added: The Audit Committee is briefed regularly on cybersecurity matters, including meeting with the Company’s head of technology at least annually and receiving a memorandum quarterly regarding cybersecurity.
In addition, the Audit Committee discusses cybersecurity with other members of management and the internal audit staff at each quarterly meeting.
1 unchanged sentence
Management of the Company plays an integral role in assessing and managing risks from cybersecurity threats.
−Removed: The Company has a dedicated technology services department, led by the Company’s Chief Technology Officer.
+Added: The Company has a dedicated technology services department, led by the Company’s head of technology.
The Company also has an in-house internal audit staff that is involved in risk management of cybersecurity threats.
1 unchanged sentence
The Company requires all employees to complete cybersecurity training semi-annually and periodically facilitates penetration tests on the Company's systems.
−Removed: The Company’s Chief Technology Officer reports to the Company’s Executive Vice President and Chief Administrative Officer.
+Added: The Company’s head of technology reports to the Company’s Executive Vice President and Chief Operating Officer.
In addition, as discussed in more detail below, any cybersecurity incident is reported to the Company’s legal department.
−Removed: Although the Company’s Executive Vice President and Chief Administrative Officer and the members of its legal department do not have a technology services background, we believe that the Company’s Chief Technology Officer and technology services team possess the requisite background and experience to effectively manage the Company’s cybersecurity needs.
−Removed: The Company's Chief Technology Officer has extensive information technology and program management experience from service in the government and private and public Fortune 100 companies.
−Removed: He has expanded the Company's cybersecurity program over the last several years resulting in a robust enterprise security posture focused on preventing cybersecurity incidents, while simultaneously increasing the Company's system resilience in an effort to minimize the business impact if an incident should occur.
+Added: Although the Company’s Executive Vice President and Chief Operating Officer and the members of its legal department do not have a technology services background, we believe that the Company’s head of technology and technology services team possess the requisite background and experience to effectively manage the Company’s cybersecurity needs.
The Company also engages with third parties on an as-needed basis to advise and assist in managing cybersecurity risks.
17 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.