UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
Cybersecurity
−Removed: Risk Management and Strategy
−Removed: We identify and assess
−Removed: material risks from cybersecurity threats to our information systems and the information residing in our information systems by monitoring
−Removed: and evaluating our threat environment on an ongoing basis using various methods including, for example, using manual and automated tools,
−Removed: subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat actors, conducting scans
−Removed: of the threat environment, and conducting risk assessments.
−Removed: We manage material risks
−Removed: from cybersecurity threats to our information systems and the information residing in our information systems through various processes
−Removed: and procedures, including, depending on the environment, risk assessments, incident detection and response, vulnerability management,
−Removed: disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption
−Removed: of data, network security controls, access controls, physical security, asset management, systems monitoring, and employee training.
−Removed: We engage third-party service providers to provide some of the resources used in our information systems and some third-party service
−Removed: providers have access to information residing in our information systems.
−Removed: With respect to such third parties, we seek to engage reliable,
−Removed: reputable service providers that maintain cybersecurity programs.
−Removed: Depending on the nature and extent of the services provided, the sensitivity
−Removed: and quantity of information processed, and the identity of the service provider, our processes may include conducting due diligence on
−Removed: the cybersecurity practices of such provider and contractually imposing cybersecurity related obligations on the provider.
−Removed: We are not aware of
−Removed: any risks from cybersecurity threats, including as a result of any cybersecurity incidents, which have materially affected or are reasonably
−Removed: likely to materially affect AGBA, including our business strategy, results of operations, or financial condition.
−Removed: Refer to “Part
−Removed: I, Item 1A—Risk Factors—Risks Factor Relating to AGBA’s business—Unexpected network interruptions, security breaches,
−Removed: cyberattack or computer virus attacks, and failures in AGBA’s information technology systems, could have a material adverse effect
−Removed: on AGBA’s business, financial condition, and results of operations” in this Form 10-K for additional discussion about cybersecurity-related
+Added: Risk Management
+Added: identify and assess material risks from cybersecurity threats to our information systems and the information residing in our information
+Added: systems by monitoring and evaluating our threat environment on an ongoing basis using various methods including, for example, using manual
+Added: and automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat
+Added: actors, conducting scans of the threat environment, and conducting risk assessments.
+Added: manage material risks from cybersecurity threats to our information systems and the information residing in our information systems through
+Added: various processes and procedures, including, depending on the environment, risk assessments, incident detection and response, vulnerability
+Added: management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions,
+Added: encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, and employee
+Added: We engage third-party service providers to provide some of the resources used in our information systems and some third-party
+Added: service providers have access to information residing in our information systems.
+Added: With respect to such third parties, we seek to engage
+Added: reliable, reputable service providers that maintain cybersecurity programs.
+Added: Depending on the nature and extent of the services provided,
+Added: the sensitivity and quantity of information processed, and the identity of the service provider, our processes may include conducting
+Added: due diligence on the cybersecurity practices of such provider and contractually imposing cybersecurity related obligations on the provider.
+Added: development and operation of Triller’s Technology Platform is subject to physical, technological, security and other risks which
+Added: may result in interruption in service or reduced capacity.
+Added: These risks include physical damage, power loss, telecommunications failure,
+Added: capacity limitation, hardware or software failures or defects and breaches of physical and cybersecurity by computer viruses, system break-ins or
+Added: An increase in the volume of usage of Triller’s Technology Platform could strain the capacity of the software and hardware
+Added: employed to prevent and identify such failures, breaches and attacks, which could result in slower response time or system failures.
+Added: In particular, Triller’s industry has witnessed an increase in the number, intensity and sophistication of cybersecurity incidents
+Added: caused by hackers and other malicious actors such as foreign governments, criminals, hacktivists, terrorists and insider threats.
+Added: and other malicious actors may be able to penetrate Triller’s network security and misappropriate or compromise Triller’s
+Added: confidential, sensitive, personal or proprietary information, or that of third parties, and engage in the unauthorized use or dissemination
+Added: of such information.
+Added: They may be able to create system disruptions, or cause shutdowns.
+Added: Hackers and other malicious actors may be able
+Added: to develop and deploy viruses, worms, ransomware and other malicious software programs that attack Triller’s products or otherwise
+Added: exploit any security vulnerabilities of Triller’s systems.
+Added: In addition, sophisticated hardware and operating system software
+Added: and applications that Triller procures from third parties may contain defects in design or manufacture, including “bugs,”
+Added: cybersecurity vulnerabilities and other problems that could unexpectedly interfere with the operation or security of its systems.
+Added: example, in 2022, as a result of a bug introduced in the application, Triller estimated that potentially 504 accounts may have been compromised.
Cybersecurity
−Removed: Our Board of Directors
−Removed: holds oversight responsibility over AGBA’s risk management and strategy, including material risks related to cybersecurity threats.
+Added: Board of Directors holds oversight responsibility over Triller’s risk management and strategy, including material risks related
+Added: to cybersecurity threats.
This oversight is executed directly by our board of directors and through its committees.
−Removed: Our audit committee oversees the management
−Removed: of AGBA’s major financial risk exposures, the steps management has taken to monitor and control such exposures, and the process
−Removed: by which risk assessment and management is undertaken and handled, which would include cybersecurity risks, in accordance with its charter.
−Removed: The audit committee holds regular meetings and receives periodic reports from management regarding risk management, including major financial
−Removed: risk exposures from cybersecurity threats or incidents.
−Removed: Within management, the
−Removed: Group Chief Information Officer of our business units are primarily responsible for assessing and managing our material risks from cybersecurity
−Removed: threats on a day-to-day basis and keep the senior executive officers informed on a regular basis of the identification, assessment, and
−Removed: management of cybersecurity risks and of any cybersecurity incidents.
−Removed: Such management personnel have prior experience and training in
−Removed: managing information systems and cybersecurity matters and participate in ongoing training programs.
−Removed: As of the date hereof, the Company has not
−Removed: encountered cybersecurity incidents that the Company believes to have been material to the Company taken as a whole.
+Added: Our audit committee
+Added: oversees the management of Triller’s major financial risk exposures, the steps management has taken to monitor and control such
+Added: exposures, and the process by which risk assessment and management is undertaken and handled, which would include cybersecurity risks,
+Added: in accordance with its charter.
+Added: The audit committee holds regular meetings and receives periodic reports from management regarding risk
+Added: management, including major financial risk exposures from cybersecurity threats or incidents.
+Added: management, the Group Chief Information Officer of our business units are primarily responsible for assessing and managing our material
+Added: risks from cybersecurity threats on a day-to-day basis and keep the senior executive officers informed on a regular basis of the identification,
+Added: assessment, and management of cybersecurity risks and of any cybersecurity incidents.
+Added: Such management personnel have prior experience
+Added: and training in managing information systems and cybersecurity matters and participate in ongoing training programs.
+Added: of the date hereof, the Company has not encountered cybersecurity incidents that the Company believes to have been material to the Company
+Added: taken as a whole.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.