3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: We are regularly subject to attempted cyberattacks and other cyber incidents and, therefore, cybersecurity is an important element of our business and our overall enterprise risk management program.
−Removed: Like other global companies, we have experienced cyber threats and incidents, although none to date have been material or had a material adverse effect on our business or financial condition.
−Removed: We have a multilayered approach for assessing, identifying, preventing, evaluating, managing and monitoring cybersecurity risks, that is designed to help prevent such attacks and protect our information, systems, assets and operations from internal and external cyber threats and to help mitigate risks of cyber incidents.
−Removed: Our board of directors delegated authority to the risk oversight and sustainability committee to assist in fulfilling its oversight responsibilities with respect to management’s identification, prevention, evaluation, management, and monitoring of our critical enterprise risks.
−Removed: The risk oversight and sustainability committee is briefed by our Head of Global IT or counsel on a quarterly basis regarding cybersecurity risks and mitigation strategies.
−Removed: We continually invest in efforts to protect, monitor, and mitigate cybersecurity risks, including through our robust information security function, training and compliance programs, and regular employee training.
−Removed: We devote significant resources to protecting the security of our computer systems, software, networks and other technology assets, and our cybersecurity risk management processes include physical, procedural and technical safeguards.
−Removed: Our cybersecurity policies, standards and procedures include incident response plans designed to help coordinate our response to cybersecurity incidents, and includes processes to triage, assess the severity of, escalate, contain, investigate, and remediate incidents.
−Removed: We seek to enhance our policies and practices to better protect our platform, adapt to changes in regulations, identify potential and emerging security risks and develop mitigations for those risks, including conducting cyber incident tabletop exercises with our management team.
+Added: Cybersecurity is an important element of our overall enterprise risk management program.
+Added: Like other global companies, we have experienced cybersecurity threats and incidents, although none to date have been material or had a material adverse effect on our business, results of operations or financial condition.
+Added: We have a multilayered approach for assessing, identifying, evaluating, managing and monitoring risks related to cybersecurity threats, that is designed to help protect our information, systems, assets and operations from internal and external cybersecurity threats and help mitigate risks of cybersecurity incidents.
+Added: We invest in efforts to protect, monitor, and mitigate risks from cybersecurity threats, including through our information security function, training and compliance programs, and regular employee training.
+Added: As part of our enterprise risk management program, we devote significant resources to protecting the security of our computer systems, software, networks and other technology assets, and our cybersecurity risk management processes include
+Added: physical, procedural and technical safeguards.
+Added: Our cybersecurity policies, standards and procedures include incident response plans designed to help coordinate our response to cybersecurity incidents.
+Added: We seek to enhance our policies and practices, as appropriate, to adapt to changes in regulations and evolving cybersecurity risks, including by conducting cybersecurity incident tabletop exercises with our management team.
We engage external parties, including consultants, network security firms and other experts, to help us assess and enhance our cybersecurity oversight.
−Removed: For example, we have hired an external security vendor to conduct penetration and vulnerability testing on our networks and receive regular updates about industry cyber risks.
−Removed: In order to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers, we perform third-party risk assessments designed to help protect against the misuse of IT by third parties and business partners and generally request that third-party service providers provide us information about their security policies and procedures.
−Removed: We monitor security incidents involving our third-party providers and adjust our procedures as necessary.
−Removed: We do not believe that there have been or are currently any known risks from cybersecurity threats that are reasonably likely to materially affect us or our business strategy, results of operations or financial condition.
+Added: For example, we have hired an external security vendor to conduct penetration and vulnerability testing on our networks and receive regular updates about cybersecurity risks in the industry.
+Added: In order to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers, we perform third-party risk assessments designed to help protect against the misuse of IT by third parties and business partners and request that material third-party service providers provide us information about their security policies and procedures.
+Added: We monitor cybersecurity incidents involving our third-party providers and adjust our procedures, as appropriate.
+Added: In an effort to deter and detect cybersecurity threats, we require all employees who use an official company email account to conduct business to complete regular data protection and cybersecurity trainings, which cover timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use and mobile security, and educates employees on the importance of reporting potential incidents immediately.
+Added: We also use technology-based tools to mitigate risks from cybersecurity threats.
+Added: As of the date of this filing, we do not believe that there currently are or have been any cybersecurity incidents, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us or our business strategy, results of operations or financial condition.
+Added: For more information on risks related to cybersecurity threats, please see Part I, Item 1A, "Risk Factors."
Cybersecurity Governance and Oversight
−Removed: Our board of directors has delegated oversight of cybersecurity to the risk oversight and sustainability committee.
−Removed: The risk oversight and sustainability committee receives quarterly updates from management and provides feedback regarding cybersecurity, including updates regarding recent incidents in the industry and the cyber threat landscape, and is notified
−Removed: between such updates regarding significant new cybersecurity threats or incidents as necessary.
+Added: Our cybersecurity program is integrated with the enterprise risk management framework and governance processes utilized by management and our board to oversee enterprise risk.
+Added: Our board of directors has delegated oversight of cybersecurity risk to the risk oversight and sustainability committee to assist in fulfilling its oversight responsibilities with respect to management's identification, prevention, evaluation, management, and monitoring of our critical enterprise risks.
+Added: The risk oversight and sustainability committee receives quarterly updates from our Head of Global IT or counsel regarding cybersecurity, including updates regarding recent cybersecurity incidents in the industry and the cybersecurity threat landscape, and is notified between such updates regarding significant new cybersecurity incidents, as appropriate.
The board of directors receives regular reports from the risk oversight and sustainability committee.
−Removed: We have a Head of Global IT whose global information security team (IT Security Team) is responsible for leading organization-wide cybersecurity strategy, policy, standards and processes and works across relevant operating entities to assess and prepare us to address cybersecurity risks.
−Removed: Our Head of Global IT and IT Security Team perform due diligence on the IT security systems and processes of all potential acquisition targets, and newly acquired companies are not permitted access into our IT networks or systems until they have met the necessary security standards.
−Removed: The Head of Global IT's cybersecurity experience includes managing the network, infrastructure security and a cyber security team of a global consumer products company with a heavy online presence and with sales of services and goods to the U.S.
+Added: Our cybersecurity program is overseen by our Head of Global IT, who is responsible for identifying and managing material cybersecurity risks.
+Added: Our Head of Global IT oversees our global information security team ( IT Security Team ), which is responsible for leading organization-wide cybersecurity strategy, policy, standards and processes and works across relevant operating entities to assess and manage risks from cybersecurity threats.
+Added: Our Head of Global IT and IT Security Team perform due diligence on the IT security systems and processes of all potential acquisition targets and have processes in place to manage post-acquisition network integration, including requiring all newly acquired companies to meet necessary security standards before they are permitted access into our IT networks or systems.
+Added: The Head of Global IT's cybersecurity experience includes managing the network, infrastructure security and a cybersecurity team of a global consumer products company with a heavy online presence and with sales of services and goods to the U.S.
In addition, our IT Security Team consists of employees that have security certifications from reputable cybersecurity training organizations, including CompTIA, and over 20 years of combined infrastructure architecture experience, including PCI, SOC1 and SOC2 level compliance.
1 unchanged sentence
The board of directors will be notified if the CIRT has been activated and provided periodic updates concerning the incident.
−Removed: In an effort to deter and detect cyber threats, we require all employees who use an official company email account to conduct business to complete regular trainings on data protection, cybersecurity, incident response and prevention, which covers timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use and mobile security, and educates employees on the importance of reporting all incidents immediately.
−Removed: We also use technology-based tools to mitigate cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.