5 unchanged sentences
Our cybersecurity risk management program leverages the National Institute of Standards and Technology (“NIST”) 800-37 framework as a foundation, customized to align with our entity size, risk profile, and industry best practices.
−Removed: We believe that
−Removed: leveraging the NIST framework as a foundation ensures a balanced approach for mitigating vulnerabilities while maintaining operational efficiency.
+Added: We believe that leveraging the NIST framework as a foundation ensures a balanced approach for mitigating vulnerabilities while maintaining operational efficiency.
We maintain a comprehensive incident response plan with clearly defined roles and responsibilities.
1 unchanged sentence
We also conduct annual reviews to ensure the plan’s effectiveness.
−Removed: We are currently conducting our annual cybersecurity assessment with the help of third-party specialists, which is expected to be completed in the first quarter of 2024.
−Removed: This assessment covers entity-level controls, threat management, and reviews of critical third-party security measures.
+Added: We conduct annual cybersecurity assessments and implement controls around any deficiencies in security that are identified, engaging third-party consultants to assist which include tabletop exercises to ensure that our incident management processes function as intended.
+Added: This assessment covers entity-level controls, threat
+Added: management, and reviews of critical third-party security measures.
Materiality of individual cybersecurity incidents is determined by a comprehensive assessment framework considering, but not limited to, the following factors:
28 unchanged sentences
Management and Board of Director Oversight of Cybersecurity Threats
−Removed: The Company's Chief Financial Officer and the audit committee of the Board has responsibility for the oversight of cybersecurity threats and incidents and reviews the Company’s programs and policies on an annual basis.
−Removed: The Company’s Chief Financial Officer has prior management experience in overseeing technology infrastructure and cybersecurity.
+Added: The Company’s Chief Financial Officer (“CFO”) and the audit committee of the board of directors of the Company (the “Board”) has responsibility for the oversight of cybersecurity threats and incidents.
+Added: The audit committee conducts periodic reviews of the Company’s cybersecurity programs, policies, and risk management strategies to ensure alignment with industry best practices.
+Added: Additionally, our CFO, leveraging extensive experience in managing technology infrastructure and cybersecurity risk, performs internal reviews with operational teams to assess cybersecurity readiness and enhance incident response strategies.
+Added: The Board’s oversight is further strengthened by the presence of a director with over 30 years of experience advising global companies on technology and operations, including cybersecurity risk management.
+Added: Our internal IT team, with over 40 years combined experience in cybersecurity, plays a critical role in implementing security controls, threat monitoring, and incident response.
+Added: This multi-tiered governance structure ensures that cybersecurity remains a top priority at both the executive and operational levels.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.