5 unchanged sentences
As part of the Program:
−Removed: • We have implemented and maintain documented policies and comprehensive technical controls (including multifactor authentication and end-to-end encryption) designed using the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework and mapped to the specifications of International Organization for Standardization (“ISO”) 27001.
+Added: • We have implemented and maintain documented policies and comprehensive technical controls (including multifactor authentication and end-to-end encryption) designed using the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework and mapped to the specifications of the International Organization for Standardization (“ISO”) 27001 information security standard.
The Program is regularly reviewed and updated on an annual basis, with a comprehensive annual review cycle.
4 unchanged sentences
Our Program also undergoes annual external audits by independent auditors as part of our ISO 27001 certification process.
−Removed: Critical vulnerabilities identified through these processes are remediated according to defined timelines based on severity and other relevant factors.
+Added: Vulnerabilities identified through these processes are remediated according to defined timelines based on the severity of the risk and other relevant factors.
• We maintain, and we require our third-party service providers to maintain reasonable security controls designed to protect the confidentiality, integrity, and availability of our information systems and the sensitive data we process or that is processed on our behalf.
We address potential risks posed by the use of such third-party service providers via established vendor risk assessments, due diligence, and contract review by our cybersecurity team.
−Removed: • We require our employees to complete security awareness training upon hiring and on a regular basis, with modules covering applicable Company policies and emerging threats.
−Removed: Our training program includes practical exercises such as simulated phishing campaigns.
+Added: • We require our employees to complete security awareness training upon hiring and on a regular basis thereafter, with modules covering applicable Company policies and emerging threats.
+Added: Our training program also includes practical exercises such as simulated phishing campaigns.
We also work with third-party cybersecurity and data privacy professionals as part of the design and implementation of our program, including accountants, independent assessors, external legal counsel, and other consultants.
−Removed: Our incident reporting and escalation process is designed to detect and analyze cyber incidents in real time, to assess their impact, to escalate the incident to our CISO and the Company’s Information Security Management Committee (which consists of our CEO, CFO, General Counsel, CISO, and EVP and President – Global Platform Group), as appropriate and consistent with our Incident Response Plan, and to determine and effectuate the appropriate response and reporting actions, including evaluating the impact and materiality of such incidents to our financial condition and operations.
+Added: Our incident reporting and escalation process is designed to detect and analyze cyber incidents in real time, to (i) assess their impact, (ii) escalate the incident to our CISO and the Company’s Information Security Management Committee (which consists of our CEO, CFO, General Counsel, CISO, and EVP and President – Global Platform Group), as appropriate and consistent with our written Incident Response Plan, and (iii) determine and effectuate the appropriate response and reporting actions, including evaluating the impact and materiality of such incidents to our financial condition and operations.
All cybersecurity threats are documented by our Security Incident Response Team, with incidents exceeding a certain threshold escalated to our CISO.
3 unchanged sentences
Our board of directors maintains active oversight of cybersecurity risks through a structured governance framework:
−Removed: • The full boar d of directors receives comprehensive cybersecurity briefings at least annually, supplemented by sessions focused on emerging threats and program strategy.
+Added: • The full board of directors receives comprehensive cybersecurity briefings at least annually, supplemented by sessions focused on emerging threats and Program strategy.
• The Audit Committee receives regular updates (typically quarterly) that cover, among other topics, performance against operational metrics and results of recent audits and assessments.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.