2 unchanged sentences
Cybersecurity Program
−Removed: We maintain a cybersecurity program that describes required controls for all Company businesses, with day-to-day management and implementation often conducted independently due to our decentralized operating model.
+Added: We maintain a cybersecurity program that implements required controls for all Company businesses, with day-to-day management and implementation often conducted independently due to our decentralized operating model.
While cybersecurity technologies and implementation may differ based on the needs and risk profile of each individual business, we implement standards at the enterprise level and provide centralized oversight work to ensure alignment and consistency.
3 unchanged sentences
Implementing controls and safeguards that allow employees to work securely and with confidence, which are intended to enable the continued delivery of essential business services.
−Removed: Our program follows guidelines from the National Institute of Standards and Technology (NIST), Center for Internet Security (CIS), Cloud Service Alliance (CSA), Payment Card Industry (PCI), HIPAA and applicable privacy regulations.
−Removed: Utilizing both external and internal resources to perform continuous assessments and penetration testing throughout the year on the Company’s key business systems, including an annual review to verify our compliance with the Payment Card Industries Data Security Standards (PCI DSS), We deploy
−Removed: systems, capabilities, and processes designed to detect cybersecurity events as early as possible to ensure the resilience of our systems and our ability to identify threats.
+Added: Our program follows guidelines from the National Institute of Standards and Technology (NIST), Center for Internet Security (CIS), Cloud Service Alliance (CSA), Payment Card Industry (PCI), HIPAA and applicable privacy regulations, and select programs are subject to continuous oversight through ongoing SOC 2 compliance audits.
+Added: Utilizing both external and internal resources to perform continuous assessments and penetration testing throughout the year on the Company’s key business systems, including an annual review to verify our compliance with the Payment Card Industries Data Security Standards (PCI DSS).
+Added: We deploy systems, capabilities, and processes designed to detect cybersecurity events as early as possible to ensure the resilience of our systems and our ability to identify threats.
• Respond & Recover:
Equipping the Company with the necessary capabilities to take immediate and effective action against detected threats.
−Removed: Our incident response plan has a structured escalation process for managing and reporting cybersecurity incidents, starting with initial detection and local management review, escalating to enterprise-level teams, and potentially reaching Audit Committee of the Company's Board of Directors, if the incident is deemed material.
+Added: Our incident response plan has a structured escalation process for managing and reporting cybersecurity incidents, starting with initial detection and local management review, escalating to enterprise-level teams, and potentially reaching the Audit Committee of the Company's Board of Directors, if the incident is deemed material.
Promoting ongoing user awareness and training so that all employees understand their role in managing cybersecurity risks.
9 unchanged sentences
We maintain a cybersecurity insurance policy that provides coverage in connection with cybersecurity incidents.
−Removed: However, costs and damages associated with cybersecurity incidents may not be fully insured under our insurance policy, and (to the extent otherwise covered) are subject to applicable deductibles.
+Added: However, such insurance coverage may exclude certain types of claims or otherwise be insufficient to cover all costs and damages associated with cybersecurity incidents, and (to the extent that costs and damages are otherwise covered) are subject to applicable deductibles .
While the Company’s Board of Directors has the ultimate responsibility for risk management, the Board has designated the Audit Committee as being primarily responsible for certain specific categories of risk oversight matters, including the oversight of the Company's privacy, data and cybersecurity risk exposures, such as the steps management has taken to monitor and mitigate such exposures and protect against threats to the Company’s information systems and security.
1 unchanged sentence
At a management level, the Company’s cybersecurity risk management program is led by our Chief Technology Officer (CTO), who reports to the Company’s President and regularly briefs him on developments that impact the program.
−Removed: Our CTO has an extensive track record of executive leadership in technology and cybersecurity, including overseeing the development and management of enterprise-level cybersecurity programs.
−Removed: With over 30 years of experience in technology, he has held key leadership roles where he successfully implemented IT governance, risk, and compliance frameworks, reducing organizational risk and enhancing operational resilience.
−Removed: Our Senior Vice-President of Technology, Compliance, Security Services (SVP-TCSS) reports to our CTO and leads a team of security professionals.
−Removed: Our SVP-TCSS has expertise in cybersecurity risk management through his more than 20 years of experience in cybersecurity, technology and data privacy roles.
−Removed: In addition, other individuals on our IT security team have cybersecurity experience or certifications relevant to their respective role.
+Added: Our CTO brings over twenty years of executive leadership experience, providing sponsorship for cybersecurity programs and compliance efforts.
+Added: He has worked to promote a culture of strong IT governance and organizational resilience, collaborating with subject matter experts to advance cybersecurity initiatives and compliance.
+Added: His hands-on experience integrating security-focused practices as part of technology governance and risk management ensures we prioritize risk management and robust protection of our digital assets.
+Added: Our Senior Vice President of Technology, Compliance, and Security Services ("SVP-TCSS"), reporting to the CTO, oversees our cybersecurity practices and leads a skilled team of security professionals.
+Added: With over twenty years of experience spanning cybersecurity, technology, and data privacy, our SVP-TCSS collaborates with these dedicated security teams to develop and implement organization-wide cybersecurity strategies.
+Added: Additionally, our IT security team comprises individuals who hold relevant cybersecurity experience and industry certifications aligned to their roles, ensuring a comprehensive approach to risk management and protection.
Our incident response plan outlines controls and procedures for cybersecurity incidents.
3 unchanged sentences
On a quarterly basis, the Company’s CTO reports to the Audit Committee regarding the Company’s cybersecurity program, including the status of ongoing proactive efforts to improve the Company’s cybersecurity risk profile.
−Removed: The CTO also reports to the Audit Committee on a quarterly basis regarding remediation activities, if any, along with related security metrics, in connection with any areas where cybersecurity threats have been identified.
+Added: CTO also reports to the Audit Committee on a quarterly basis regarding remediation activities, if any, along with related security metrics, in connection with any areas where cybersecurity threats have been identified.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.