10 unchanged sentences
We conduct annual cybersecurity assessments and implement controls around any deficiencies in security that are identified, engaging third-party consultants to assist which include tabletop exercises to ensure that our incident management processes function as intended.
−Removed: This assessment covers entity-level controls, threat
−Removed: management, and reviews of critical third-party security measures.
+Added: This assessment covers entity-level controls, threat management, and reviews of critical third-party security measures.
Materiality of individual cybersecurity incidents is determined by a comprehensive assessment framework considering, but not limited to, the following factors:
15 unchanged sentences
We have partnered with a reputable third-party MDR provider to enhance our threat detection and response capabilities.
−Removed: This service provides continuous monitoring, analysis, and proactive response to potential threats, ensuring timely identification and mitigation of cybersecurity incidents.
+Added: This service provides continuous monitoring,
+Added: analysis, and proactive response to potential threats, ensuring timely identification and mitigation of cybersecurity incidents.
• Metrics and Measurements:
3 unchanged sentences
We require providers to share their security reports (System and Organization Controls (“SOC”) 1 and SOC 2) prior to initial engagement and ongoing on an annual basis.
−Removed: We believe that the review of such reports helps us minimize the risk of data breaches or other problems resulting due to our third-party relationships, especially with software-as-a-service (“SaaS”) providers.
+Added: We believe that the review of such reports helps us minimize the risk of data breaches or other problems resulting due to our third-party relationships, especially with software-as-a-service providers.
We have a communication process for incidents based on their severity as outlined in our incident response plan.
When a major incident is detected, executive leadership is informed within 24 hours.
−Removed: The audit committee and Chief Financial Officer are notified, and a detailed report is submitted, within 24-48 hours.
+Added: The audit committee and Chief Financial Officer (“CFO”) are notified, and a detailed report is submitted, within 24-48 hours.
For moderate incidents, the notification timeframe is 72 hours, and the detailed report is submitted to the audit committee within five to seven days.
1 unchanged sentence
Management and Board of Director Oversight of Cybersecurity Threats
−Removed: The Company’s Chief Financial Officer (“CFO”) and the audit committee of the board of directors of the Company (the “Board”) has responsibility for the oversight of cybersecurity threats and incidents.
+Added: The Company’s CFO and the audit committee of the board of directors of the Company (the “Board”) have responsibility for the oversight of cybersecurity threats and incidents.
The audit committee conducts periodic reviews of the Company’s cybersecurity programs, policies, and risk management strategies to ensure alignment with industry best practices.
1 unchanged sentence
The Board’s oversight is further strengthened by the presence of a director with over 30 years of experience advising global companies on technology and operations, including cybersecurity risk management.
−Removed: Our internal IT team, with over 40 years combined experience in cybersecurity, plays a critical role in implementing security controls, threat monitoring, and incident response.
+Added: Our internal IT team, with over 40 years of combined experience in cybersecurity, plays a critical role in implementing security controls, threat monitoring, and incident response.
This multi-tiered governance structure ensures that cybersecurity remains a top priority at both the executive and operational levels.
+Added: We have not identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: Notwithstanding the approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us.
+Added: While we maintain cybersecurity insurance, the costs related to cybersecurity threats or disruptions may not be fully insured.
+Added: For more information on our cybersecurity related risks, see Item 1A.
+Added: Risk Factors of this Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.