7 unchanged sentences
The Company maintains an ERM program with a governance structure that is designed to identify, assess, prioritize, and mitigate risks across the organization.
−Removed: The ERM Executive Committee, comprised of the Company’s senior leadership team, has the ultimate responsibility for overseeing the identification of the key risks facing the Company and meets regularly to discuss the Company’s approach to mitigating those risks.
+Added: The ERM Executive Committee, comprised of the Company’s senior leadership team, has the ultimate responsibility for managing the identification of the key risks facing the Company and meets regularly to discuss the Company’s approach to mitigating those risks.
Through the ERM process, cybersecurity has been identified as an important risk facing the Company.
2 unchanged sentences
This process includes a governance model and procedures for identifying, categorizing, containing, and responding to cybersecurity incidents.
−Removed: As a component of the cybersecurity incident response process, the Company conducts attack simulations and exercises and has used third parties to support this work.
+Added: As a component of the cybersecurity incident response process, the Company periodically conducts attack simulations and exercises and has used third parties to support this work.
The Company also maintains business continuity and disaster recovery plans to prepare for potential technology disruptions and to better position the Company to recover from any cybersecurity incident.
−Removed: The Company’s Disclosure Committee also includes a member of the ERM Executive Committee, helping to ensure timely analysis of disclosure obligations relating to cybersecurity events.
+Added: The Company’s Disclosure Committee also includes members of the ERM Executive Committee, helping to ensure timely analysis of potential disclosure obligations relating to cybersecurity events.
Cybersecurity Program Components
3 unchanged sentences
• Regular monitoring and updating of the Company’s IT infrastructure, to respond to the dynamic cybersecurity threat environment;
−Removed: • Use of third parties to assess, test, validate, and strengthen the cybersecurity program, including penetration testing and the periodic use of a third party to assess the quality and maturity of the program against the NIST Cybersecurity Framework;
+Added: • Use of internal resources and third parties to assess, test, validate, and strengthen the cybersecurity program, and the periodic use of third parties to perform penetration testing and to assess the quality and maturity of the program against the NIST Cybersecurity Framework ;
• Assessing and managing cybersecurity risks associated with the Company’s relationships with third parties, including technology and service providers, through due diligence efforts and the imposition of contractual obligations.
18 unchanged sentences
For additional commentary on cybersecurity risks, see Part 1, Item 1A.
−Removed: Risk Factors under the heading “The Company may be adversely impacted if the Company is affected by cybersecurity attacks, security breaches, or other IT interruptions, involving its own systems or those with whom it does business.”
+Added: Risk Factors under the heading “The Company may be adversely impacted if the Company is affected by cybersecurity attacks or other security breaches.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.