4 unchanged sentences
To mitigate cybersecurity risks we have adopted a process of continuous improvement and adaptation to the ever-changing threat landscape.
−Removed: As part of this process, we engage with industry-leading managed security service provider(s) to supplement our efforts in preventing, identifying and responding to cybersecurity threats.
+Added: As part of this process, we engage with industry-leading managed security service providers to supplement our efforts in preventing, identifying and responding to cybersecurity threats.
Our information technology operations, information security processes and CIRP are generally aligned with the National Institute of Standards and Technology’s framework.
13 unchanged sentences
● When practical and necessary, we patch vulnerabilities that are identified.
−Removed: ● We deploy endpoint detection and monitoring technologies to identify potential cybersecurity incidents.
+Added: ● We deploy endpoint detection and monitoring technologies to identify potential cybersecurity incidents, which have capabilities to automatically isolate and terminate vulnerabilities.
+Added: ● We utilize industry leading tools and controls for user management, authentication, and privileged access management.
● We back up our systems and data to mitigate the impact of a cybersecurity event that would impact our ability to operate or result in the loss of data.
● We partner with strategic managed cybersecurity service providers to supplement the capabilities of our internal team.
−Removed: ● We update and refine our CIRP in response to identified risks.
+Added: ● We periodically test, evaluate and refine our CIRP in response to identified risks.
● To manage the third-party cybersecurity risk introduced by our cloud-first strategy, we have implemented a due diligence process for new software partners as well as an annual review process for essential SaaS system partners.
1 unchanged sentence
Notwithstanding the steps we take to address cybersecurity, we may not be successful in preventing or mitigating all cybersecurity incidents or threats.
−Removed: Risk Factors - Risks Related to Our Business and Operations – The occurrence of cyber incidents, or a deficiency in our cybersecurity, or the cybersecurity of our service providers, could negatively impact our business by causing a disruption to our operations, a compromise or corruption of our confidential information, regulatory enforcement and other legal proceedings, and/or damage to our business relationships, all of which could negatively impact our financial results – for a discussion of cybersecurity risks .
−Removed: To date, we have not experienced any material cybersecurity incidents.
Our Chief Information & Technology Officer along with our Vice President of Cybersecurity & Cloud Infrastructure provide principal oversight and guidance of our cybersecurity risk management strategy, programs and processes.
8 unchanged sentences
The CIRP also addresses management's responsibility, with Audit Committee oversight, with respect to any reporting or disclosure determinations related to a given cybersecurity incident and provides for Audit Committee and Board of Trustee briefings as appropriate.
+Added: Risks, Threats and Material Incidents
+Added: As of December 31, 2024, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition.
+Added: However, we and our third-party providers have been the target of cybersecurity threats and expect them to continue.
+Added: Notwithstanding the extensive approach we take to address cybersecurity, there can be no assurance that our cybersecurity efforts and measures will be effective or that attempted cybersecurity incidents or disruptions would not be successful or damaging.
+Added: See Item 1A “Risk Factors” - Risks Related to Our Business and Operations - The occurrence of cyber incidents, or a deficiency in our cybersecurity, or the cybersecurity of our service providers, could negatively impact our business by causing a disruption to our operations, a compromise or corruption of our confidential information, regulatory enforcement and other legal proceedings, and/or damage to our business relationships, all of which could negatively impact our financial results.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.