5 unchanged sentences
As part of this process, we engage with industry-leading managed security service providers to supplement our efforts in preventing, identifying and responding to cybersecurity threats.
−Removed: Our information technology operations, information security processes and CIRP are generally aligned with the National Institute of Standards and Technology’s framework.
+Added: Our information technology operations, information security processes and CIRP are informed by the National Institute of Standards and Technology Cybersecurity Framework.
We have adopted a cloud-first strategy which is a foundational element to our overall cybersecurity posture.
13 unchanged sentences
● We deploy endpoint detection and monitoring technologies to identify potential cybersecurity incidents, which have capabilities to automatically isolate and terminate vulnerabilities.
−Removed: ● We utilize industry leading tools and controls for user management, authentication, and privileged access management.
+Added: ● We utilize industry-standard tools and controls for user management, authentication, and privileged access management.
● We back up our systems and data to mitigate the impact of a cybersecurity event that would impact our ability to operate or result in the loss of data.
4 unchanged sentences
Notwithstanding the steps we take to address cybersecurity, we may not be successful in preventing or mitigating all cybersecurity incidents or threats.
−Removed: Our Chief Information & Technology Officer along with our Vice President of Cybersecurity & Cloud Infrastructure provide principal oversight and guidance of our cybersecurity risk management strategy, programs and processes.
+Added: Our Chief Information & Technology Officer provides oversight and guidance of our cybersecurity risk management strategy, programs and processes.
The Chief Information & Technology Officer has over 20 years of experience in information technology in the real estate sector, leading organizations through strategic technology and process improvement initiatives.
−Removed: The Vice President of Cybersecurity & Cloud Infrastructure has over 15 years of extensive experience in cybersecurity and information technology.
−Removed: They are supported in their efforts by a team of technical experts who have had formal training and possess relevant industry related experience in addition to managed cybersecurity service providers who specialize in preventing, identifying, and responding to cybersecurity threats.
+Added: He is supported in his efforts by a team of technical experts who have had formal training and possess relevant industry related experience in addition to managed cybersecurity service providers who specialize in preventing, identifying and responding to cybersecurity threats.
The Audit Committee of our Board of Trustees provides board-level governance and oversight regarding cybersecurity matters.
Management meets with the Audit Committee periodically to discuss cybersecurity strategy, risk, trends, and internal personnel and qualifications.
−Removed: As part of our annual enterprise risk assessment, technology and cyber risks are standing risk factors which are ranked and reviewed by management.
−Removed: In the event of a cyberattack, we engage our CIRP, which provides a framework of processes and procedures related to identifying, categorizing, responding, containing, analyzing, and eradicating cybersecurity threats to mitigate downtime and promptly restore systems and services.
−Removed: Management has responsibility for reporting cybersecurity incidents to the Audit Committee as they occur, if consistent with our CIRP.
+Added: As part of our annual enterprise risk assessment, technology and cyber risks are risk factors which are ranked and reviewed by management.
+Added: In the event of a cybersecurity incident, we engage our CIRP, which provides a framework of processes and procedures related to identifying, categorizing, responding, containing, analyzing, and eradicating cybersecurity threats to mitigate downtime and promptly restore systems and services.
+Added: Management has responsibility for reporting cybersecurity incidents to the Audit Committee in a timely manner, if consistent with our CIRP.
The CIRP also addresses management's responsibility, with Audit Committee oversight, with respect to any reporting or disclosure determinations related to a given cybersecurity incident and provides for Audit Committee and Board of Trustee briefings as appropriate.
Risks, Threats and Material Incidents
−Removed: As of December 31, 2024, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition.
−Removed: However, we and our third-party providers have been the target of cybersecurity threats and expect them to continue.
+Added: We and our third-party providers have experienced cybersecurity threats and incidents in the past and we expect them to continue.
+Added: However, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us , including our business strategy, results of operations or financial condition within the last three years.
Notwithstanding the extensive approach we take to address cybersecurity, there can be no assurance that our cybersecurity efforts and measures will be effective or that attempted cybersecurity incidents or disruptions would not be successful or damaging.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.