2 unchanged sentences
CYBERSECURITY
−Removed: In support of our commitment to cybersecurity,
−Removed: we employ a comprehensive strategy which is intended to protect our digital infrastructure, which strategy is supported by both management
−Removed: and our Board of Directors.
−Removed: Our Board of Directors is responsible for overseeing our risk management activities in general, and certain
−Removed: of our Board committees assists the Board of Directors in the role of risk oversight.
−Removed: The full Board of Directors receives an update on
−Removed: the Company’s risk management process and the risk trends related to cybersecurity at least annually.
−Removed: At the management level, leading our efforts is
−Removed: a cybersecurity team that reports directly to our Senior Vice President.
−Removed: This team conducts manual and automated testing on our systems,
−Removed: with the goal of identifying vulnerabilities and proactively strengthening our defenses.
−Removed: We believe that embracing a multi-layered defense
−Removed: approach, will help us recognize and address the dynamic nature of cyber threats.
+Added: At IPM, cybersecurity is at the core of our business operations and
+Added: an integral part of our commitment to delivering secure, compliant, and resilient technology solutions to customers operating in highly
+Added: regulated industries.
+Added: Prior to the Transactions, the Company employed a comprehensive strategy with respect to cybersecurity, which was
+Added: supported by both management and our Board.
+Added: Historically, our Board was responsible for overseeing our risk management activities in general,
+Added: and certain of our Board committees assisted the Board in the role of risk oversight.
+Added: The operations team prior to the Transactions conducted
+Added: manual and automated testing of our systems, with the goal of identifying vulnerabilities and proactively strengthening our defenses.
+Added: Following the Transactions,
+Added: in order to support our comprehensive range of IT-related services and digital infrastructure, we have embraced a multi-layered defense
+Added: approach, which helps us recognize and address the dynamic nature of cyber threats.
By integrating diverse security measures, we aim to
−Removed: fortify our infrastructure against a spectrum of potential risks, adapting to the ever-evolving cybersecurity landscape.
−Removed: Our cybersecurity team performs tests, encompassing
−Removed: vulnerability assessments, penetration testing, and threat simulations.
−Removed: The results derived from these assessments are prioritized and
−Removed: integrated into the workflow of our development and operations teams to ensure that identified vulnerabilities and insights gleaned from
−Removed: the tests are promptly addressed.
−Removed: We also have an established process led by our Senior Vice President governing our assessment, response
−Removed: and notifications internally and externally upon the occurrence of a cybersecurity incident.
−Removed: Depending on the nature and severity of
−Removed: an incident, this process provides for escalating notification to our Chief Executive Officer and the Board of Directors.
−Removed: To enhance our defense mechanisms, we leverage
−Removed: third-party edge security tools.
−Removed: These tools play a crucial role in actively monitoring and mitigating potential threats to our sites
−Removed: and products, which we believe contributes to our security infrastructure.
−Removed: Our development teams also use proactive measures such as
−Removed: “Security as Code” to make sure that vulnerabilities are protected against at a deeper level, in addition to cloud-based
−Removed: security tools.
−Removed: Recognizing the pivotal role of our personnel
−Removed: in cybersecurity, we also conduct proactive training sessions covering essential topics such as data handling practices and email phishing
−Removed: These initiatives are designed to empower our workforce to serve as a human firewall, augmenting our overall security posture.
−Removed: Additionally, we also think about data handling from a code and infrastructure level, incorporating encryption measures in transit and
−Removed: at rest to safeguard both internal and customer data.
−Removed: We further employ a proactive backup strategy, ensuring rapid system restoration
−Removed: in the event of disruptions.
−Removed: This measure minimizes downtime and underscores our commitment to business continuity and customer service
−Removed: An integral part of our cybersecurity readiness
−Removed: is an annual external IT audit that evaluates various aspects of our cybersecurity framework.
−Removed: This measure ensures that our defenses
−Removed: align with industry best practices and facilitates continuous improvement.
−Removed: The results of this audit are reviewed by the audit committee
−Removed: of the Board of Directors, allowing such committee to assist in and make recommendations on our management’s cybersecurity controls.
+Added: fortify our infrastructure against a spectrum of potential risks and adapt to the ever-evolving cybersecurity landscape.
+Added: Our cybersecurity strategy is proactively designed
+Added: to protect our digital infrastructure, customer environments, and business continuity.
+Added: This approach is supported by our management and
+Added: Board, with structured oversight to ensure compliance with evolving regulatory, risk, and industry best practices.
+Added: Proactive Security Measures and Threat Management
+Added: We employ a multi-layered defense strategy, leveraging
+Added: advanced threat intelligence, automation, and security analytics to proactively detect, prevent, and respond to cyber threats.
+Added: security practices include:
+Added: threat monitoring and response utilizing real-time security operations centers and next-generation endpoint detection and response to
+Added: rapidly identify and neutralize threats;
+Added: vulnerability assessments and penetration testing conducted through automated and manual assessments with prioritized remediation workflows
+Added: to enhance security across infrastructure, applications, and client environments;
+Added: trust security architecture, which implements strict identity verification, least privilege access and network segmentation to reduce
+Added: attack surfaces and prevent lateral movement of threats;
+Added: ● partnerships
+Added: with leading cybersecurity firms for independent security audits, risk assessments, and compliance rev iews as described below.
+Added: Recognizing that human factors play a critical
+Added: role in cybersecurity, our workforce and compliance training includes comprehensive security awareness program.
+Added: All employees undergo
+Added: quarterly security training, covering data protection, insider threat mitigation, phishing awareness, and compliance best practices.
+Added: Additionally,
+Added: we implement strict enforcement of multi-factor authentication, just-in-time access controls, and continuous user behavior monitoring.
+Added: Incident Response and Business Continuity
+Added: Our incident response framework follows a structured
+Added: escalation and notification process focused on rapid containment, mitigation, and recovery from cybersecurity incidents.
+Added: protocols include:
+Added: detection and response workflows to leverage rapid assessment detection technology to detect
+Added: breaches in real time;
+Added: of critical incidents to our Chief Executive Officer, President, and Chief Operating Officer
+Added: and the Board based on severity and regulatory reporting requirements;
+Added: backup and disaster recovery, which implement immutable backups, air-gapped storage, and
+Added: rapid failover solutions to protect data integrity and minimize downtime in case of cyber
+Added: Both management and the Board are actively involved
+Added: in the oversight of risks from cybersecurity threats.
+Added: Our information security program is designed to ensure that management and the Board
+Added: are adequately informed about, and provided with the tools necessary to monitor, (i) material risks from cybersecurity threats and (ii)
+Added: our efforts related to the prevention, detection, mitigation, and remediation of cybersecurity incidents.
+Added: Role of the Board
+Added: Our Board oversees cybersecurity risk as part
+Added: of our enterprise risk management strategy.
+Added: The Board receives comprehensive cybersecurity updates from our President at least quarterly
+Added: to inform our directors of evolving threats and regulatory developments.
+Added: We undergo regular independent audits, cybersecurity risk assessments,
+Added: and compliance reviews to validate our security posture, and our Audit Committee receives annual reports regarding our ongoing security
+Added: Role of Management
+Added: At the management level, our Chief Information
+Added: Security Officer (“CISO”) leads cybersecurity initiatives and reports regularly to the President on security posture, risk
+Added: trends, and key incidents.
+Added: Our President is a seasoned technology and business leader with over 20 years of experience in managed IT services
+Added: and global scale multi-site private cloud datacenter operations.
+Added: His background and experience provide him with expertise regarding data
+Added: privacy and security, vulnerability management, security operations, and application security.
+Added: In addition, our Chief Operating Officer
+Added: has many years of experience with managed IT cyber application delivery.
We face risks from cybersecurity threats that
could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation.
−Removed: we have not experienced any cyber incidents that have had an adverse material effect on our business, financial condition, results of
−Removed: operations, or cash flows.
−Removed: See “Risk Factors – Risks Related to Our Business – Security breaches, computer viruses
−Removed: and cybersecurity incidents could harm our business, results of operations or financial condition.”
−Removed: Our principal executive office is located at
−Removed: 30 Jericho Executive Plaza in Jericho, New York 11753.
−Removed: The lease for the 30 Jericho Executive Plaza office space expires on November
−Removed: We currently do not own any real property.
+Added: have not experienced any risks from cybersecurity threats that have materially affected, or are reasonably likely to materially affect,
+Added: our business strategy, financial condition, results of operations, or cash flows.
+Added: See “ Risk Factors – Risks Related to
+Added: Our Business – We could be adversely affected by information security breaches or cyber security attacks .”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.