7 unchanged sentences
We regularly assess the threat landscape and take a holistic view of cybersecurity risks, with a layered cybersecurity strategy based on prevention, detection and mitigation, and investments in a partnership with a third-party vendor whose experts further advise our processes.
−Removed: Our executive team, which includes the VP of IT, reviews enterprise risk management-level cybersecurity risks annually, along with other key risks to the organization.
+Added: Our executive team, which includes VPs of IT, review enterprise risk management-level cybersecurity risks annually, along with other key risks to the organization.
In addition, we have a set of Company-wide policies and procedures concerning cybersecurity matters, which include an IT security policy as well as other policies that directly or indirectly relate to cybersecurity, such as policies related to encryption standards, malware protection, remote access, multifactor authentication, confidential information and the use of the internet, social media, email and wireless devices.
These policies go through an internal review process and are approved by appropriate members of management.
−Removed: The VP of IT is responsible for developing and implementing our information security program and reporting on cybersecurity matters to the Board.
−Removed: Our VP of IT has over two decades of experience leading cybersecurity oversight.
+Added: The VPs of IT are responsible for developing and implementing our information security program and reporting on cybersecurity matters to the Board.
+Added: Our VPs of IT have extensive experience leading cybersecurity oversight.
Others on our IT security team have cybersecurity experience or certifications that support these efforts.
−Removed: We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises at a management level and incorporate external resources and advisors as needed.
+Added: We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises at a management level and incorporate external
+Added: resources and advisors as needed.
All employees are required to complete cybersecurity trainings at least annually and have access to more frequent cybersecurity trainings through online trainings.
16 unchanged sentences
In addition, the Board receives regular cybersecurity updates, which include a review of key performance indicators, test results and related remediation, and recent threats and how the Company is managing those threats.
−Removed: Further, at least annually, the Board receives updates on the Company’s Business Continuity Plan, which covers, among other
−Removed: things, potential cybersecurity incidents, and potential impacts to data privacy and compliance.
+Added: Further, at least annually, the Board receives updates on the Company’s Business Continuity Plan, which covers, among other things, potential cybersecurity incidents, and potential impacts to data privacy and compliance.
To aid the Board with its cybersecurity and data privacy oversight responsibilities, the Board periodically hosts experts for presentations on these topics.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.