2 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: Cybersecurity is a critical risk to our business.
+Added: Cybersecurity risks are critical to our business and our process for identifying and managing material risks from cybersecurity threats have been integrated into our overall risk management system and processes.
We rely on complex information technology systems and networks to conduct business, including communicating with employees and our distribution centers, ordering and managing materials from suppliers, selling and shipping products and analyzing and reporting results of operations, as well as for storing sensitive, personal and other confidential information.
−Removed: While we employ resources to monitor and protect our technology infrastructure and sensitive information, these security measures or those of our third-party vendors may not prevent all attempted security breaches or cyber-attacks.
+Added: While we employ resources to
+Added: monitor and protect our technology infrastructure and sensitive information, these security measures or those of our third-party vendors may not prevent all attempted data security breaches or cyber-attacks.
If our or our third-party vendors’ information technology systems are damaged or cease to be available or function properly for an extended period of time, whether as a result of a significant cyber incident or otherwise, our ability to communicate internally as well as with our customers could be significantly impaired, which may adversely impact our business.
1 unchanged sentence
Addressing cybersecurity risks requires ongoing monitoring and vigilance, and the Company is making enhancements to its cybersecurity policies, procedures and practices to safeguard sensitive information as well as information from our partners, customers and employees.
−Removed: We employ a risk-based strategy focused on safeguarding critical assets by implementing controls around access, data, and infrastructure security to protect the confidentiality, integrity, and availability of our data.
−Removed: Maturation and refinement of the Company's cybersecurity risk management strategy and related procedures is a continuous
−Removed: activity to ensure appropriate identification, assessment, and response to risks from cybersecurity threats that may adversely impact our operations.
−Removed: Our employee training and awareness programs are in place to improve cybersecurity awareness throughout the organization and we are committed to educating our employees on best practices for data protection and phishing awareness.
−Removed: We also engage with third-party cybersecurity assessors, consultants, and auditors that provide independent assessments of our systems and processes, contributing to our efforts to strengthen our cybersecurity posture and enhance our defenses.
−Removed: On January 31, 2022, certain of our computer systems related to the Aurora acquisition that had not yet been integrated into our main systems were the victim of a cybersecurity attack.
+Added: We employ a risk-based strategy, aligned with the National Institute of Standards and Technology Cybersecurity framework, focused on safeguarding critical assets by implementing controls around access, data, and infrastructure security to protect the confidentiality, integrity, and availability of our data.
+Added: Maturation and refinement of the Company's cybersecurity risk management strategy and related procedures is a continuous activity to ensure appropriate identification, assessment, and response to risks from cybersecurity threats that may adversely impact our operations.
+Added: Our employee training and awareness programs are in place to improve cybersecurity awareness throughout the organization and we are committed to educating our employees on best practices for data protection, phishing awareness, and incident response.
+Added: We also engage with third-party cybersecurity assessors, consultants, and auditors that provide independent assessments of our systems and processes, as well as those of certain third-party service providers, contributing to our efforts to strengthen our cybersecurity posture and enhance our defenses.
+Added: On January 31, 2022, certain computer systems related to the Aurora acquisition that had not yet been integrated into our main systems were the victim of a cybersecurity attack.
We immediately took steps to isolate those systems and implemented measures to prevent the spread of the attack, including taking systems offline in an abundance of caution.
1 unchanged sentence
There was no evidence that the attack extended beyond the Aurora acquisition’s systems, and it was determined that no critical data was accessed.
−Removed: We have subsequently taken steps to integrate the acquisition’s systems with our main systems, which we expect to complete in the first half of 2024.
−Removed: We have not encountered cybersecurity incidents or identified risks from cybersecurity threats that have materially impaired our operations or financial standing.
+Added: We have subsequently integrated the acquisition’s systems with our main systems, which we completed in 2024.
+Added: As of December 31, 2024, we are not aware of any cybersecurity incidents or identified risks from cybersecurity threats that have materially affected, or are reasonably likely to affect, our business strategy, results of operations or financial condition.
+Added: There is no guarantee that cybersecurity incidents or risks from cybersecurity incidents may not be material in the future.
We maintain cyber insurance coverage to supplement our cybersecurity program given the complex and evolving nature of global cyber threats;
3 unchanged sentences
Cybersecurity Governance
−Removed: Our Board of Directors oversees the cybersecurity risk management program and is regularly informed of cybersecurity risks through periodic updates provided by the Director of Information Technology ("IT"), to address our cybersecurity processes and risk mitigation efforts.
−Removed: Certain Board of Directors have cybersecurity risk certification credentials and experience with, and exposure to, cyber risk oversight.
−Removed: The periodic updates provided by management to the Board of Directors generally encompass emerging cyber threats, the Company’s security posture changes, significant cybersecurity incidents, progress of risk mitigation efforts, and cybersecurity strategies and investments.
−Removed: The frequency of these updates allows for timely decision-making and ensures that our Board is fully informed of our cybersecurity risks.
+Added: Our board of directors oversees the cybersecurity risk management program and is regularly informed of cybersecurity risks through periodic updates provided by the Director of Information Technology ("IT") and Information Security team, to address our cybersecurity processes and risk mitigation efforts.
+Added: Certain members of the board of directors have cybersecurity risk certification credentials and experience with, and exposure to, cyber risk oversight.
+Added: The periodic updates provided by the Director of IT and Information Security team to the board of directors generally encompass emerging cyber threats, the Company’s security posture changes, significant cybersecurity incidents, progress of risk mitigation efforts, and cybersecurity strategies and investments.
+Added: The frequency of these updates allows for timely decision-making and ensures that our board of directors is fully informed of our cybersecurity risks.
Our Director of IT is responsible for identifying, assessing, and mitigating cybersecurity risks across the Company.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.