Unresolved Staff Comments
−Removed: Not Applicable
Cybersecurity
−Removed: Cyberattacks are a growing geopolitical risk,
−Removed: becoming larger, more frequent, more intricate and more relentless.
−Removed: These attacks represent a significant threat to individual organizations
−Removed: and their ability to conduct daily operations.
−Removed: We rely on accounting, financial, and operational management information systems to conduct
−Removed: our operations.
+Added: are a growing geopolitical risk, becoming larger, more frequent, more intricate and more relentless.
+Added: These attacks represent a significant
+Added: threat to individual organizations and their ability to conduct daily operations.
+Added: We rely on accounting, financial, and operational management
+Added: information systems to conduct our operations.
Any disruption in these systems could adversely affect our ability to conduct our business.
−Removed: Furthermore, as part of our
−Removed: normal business activities, we collect and store common confidential information about customers, employees, vendors, and suppliers.
−Removed: information is entitled to protection under a number of regulatory regimes.
−Removed: Any failure to maintain the security of the data,
−Removed: including the penetration of our network security and the misappropriation of confidential and personal information, could result in business
−Removed: disruption, damage to our reputation, financial obligations to third parties, fines, penalties, regulatory proceedings and private litigation
−Removed: with potentially large costs.
−Removed: This scenario may also result in a deterioration of customer confidence in us and potentially other competitive
−Removed: disadvantages.
−Removed: As such, a cyberattack could have a material adverse impact on our financial condition and results of operations.
−Removed: While we devote resources to implement and maintain security measures
−Removed: to protect our systems and data, these measures cannot provide absolute security against a cyberattack.
−Removed: In such an event, the insurance
−Removed: coverage we maintain may be inadequate to cover claims, costs, and liabilities relating to cybersecurity incidents.
−Removed: While we have not been subject to cyberattacks
−Removed: and other cyber incidents, we take cybersecurity preparedness seriously.
−Removed: Our risk management framework considers cybersecurity risk alongside
−Removed: other company risks as part of our overall risk assessment process.
−Removed: We have plans to implement cybersecurity training for all employees
−Removed: upon onboarding, and then annual follow-up training courses to ensure that all employees understand the risk and implications of a cyber
−Removed: We plan to implement a Cybersecurity Committee which will be responsible
−Removed: for the day-to-day management of cybersecurity risks, and which will meet bi-monthly to review our practices related to cyber events and
−Removed: risk management.
−Removed: The Committee will be composed of the Chief Financial Officer, Chief Legal Officer, Controller, and Head of Human Resources.
−Removed: The Committee will develop and implement cybersecurity risk mitigation strategies and activities, including the management of comprehensive
−Removed: incident response plans, oversee the cybersecurity risks posed by third-party vendors, ensure policies and procedures are current and
−Removed: followed, and receive regular updates on cybersecurity-related matters.
−Removed: Further, the Committee will engage subject matter experts such
−Removed: as consultants and auditors to assist us in establishing processes to assess, identify, and manage potential and actual cybersecurity
−Removed: threats, to actively monitor our systems internally using widely accepted digital applications, processes, and controls, and to provide
−Removed: forensic assistance to facilitate system recovery in the case of an incident.
−Removed: The Audit Committee of our Board of Directors oversees our policies
−Removed: and practices with respect to risk assessment and risk management, including the review, in coordination with our management, of our management
−Removed: of cybersecurity.
−Removed: The Audit Committee will receive regular updates from the Cybersecurity Committee on the state of cybersecurity
−Removed: risks we face.
−Removed: This will include briefings on any significant cyber incidents and ongoing risk management efforts.
−Removed: These updates will
−Removed: enable the Audit Committee to provide informed reports on cybersecurity matters to the full Board.
−Removed: As of the date of this Annual Report on Form 10-K,
−Removed: we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect us,
−Removed: our business strategy, results of operations or financial condition.
+Added: Furthermore, as part of our normal business activities, we collect and store common confidential information about customers, employees,
+Added: vendors, and suppliers.
+Added: This information is entitled to protection under a number of regulatory regimes.
+Added: failure to maintain the security of the data, including the penetration of our network security and the misappropriation of confidential
+Added: and personal information, could result in business disruption, damage to our reputation, financial obligations to third parties, fines,
+Added: penalties, regulatory proceedings and private litigation with potentially large costs.
+Added: This scenario may also result in a deterioration
+Added: of customer confidence in us and potentially other competitive disadvantages.
+Added: As such, a cyberattack could have a material adverse impact
+Added: on our financial condition and results of operations.
+Added: we devote resources to implement and maintain security measures to protect our systems and data, these measures cannot provide absolute
+Added: security against a cyberattack.
+Added: In such an event, the insurance coverage we maintain may be inadequate to cover claims, costs, and liabilities
+Added: relating to cybersecurity incidents.
+Added: we have not been subject to cyberattacks and other cyber incidents, we take cybersecurity preparedness seriously.
+Added: Our risk management
+Added: framework considers cybersecurity risk alongside other company risks as part of our overall risk assessment process.
+Added: We have plans to
+Added: implement cybersecurity training for all employees upon onboarding, and then annual follow-up training courses to ensure that all employees
+Added: understand the risk and implications of a cyber event.
+Added: We have implemented a Cybersecurity Committee which met three times
+Added: last year and is now responsible for the day-to-day management of cybersecurity risks, and the review our practices related to cyber events
+Added: and risk management.
+Added: The Committee is composed of the Chief Financial Officer, Chief Legal Officer, Controller, and Head of Human Resources.
+Added: The Committee is responsible for developing and implementing cybersecurity risk mitigation strategies and activities, including the managing
+Added: of comprehensive incident response plans, overseeing the cybersecurity risks posed by third-party vendors, keeping our policies and procedures
+Added: current, assessing compliance with our cybersecurity policies and procedures, and receiving regular updates on cybersecurity-related matters.
+Added: Further, the Committee will, from time to time and as needed, engage subject matter experts such as consultants and auditors to assist
+Added: us in establishing processes to assess, identify, and manage potential and actual cybersecurity threats, to actively monitor our systems
+Added: internally using widely accepted digital applications, processes, and controls, and to provide forensic assistance to facilitate system
+Added: recovery in the case of an incident.
+Added: The Audit Committee of our Board of Directors (the “Audit Committee”)
+Added: oversees our policies and practices with respect to risk assessment and risk management, including the review, in coordination with our
+Added: management, of our management of cybersecurity.
+Added: The Audit Committee receives regular updates from the Cybersecurity Committee on the state
+Added: of cybersecurity risks we face.
+Added: This includes briefings on any significant cyber incidents and ongoing risk management efforts.
+Added: updates enable the Audit Committee to provide informed reports on cybersecurity matters to the full Board.
+Added: of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats that have materially affected
+Added: or are reasonably likely to materially affect us , our business strategy, results of operations or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.