1 unchanged sentence
Cybersecurity.
−Removed: Assessment, Identification and Management of Material Risks from Cybersecurity Threats
−Removed: We rely on the cybersecurity strategy and policies implemented by Ares Management, the parent company of our Sponsor.
−Removed: Ares Management’s cybersecurity strategy prioritizes the detection and analysis of, and response to, known, anticipated or unexpected threats, effective management of security risks and resilience against cyber incidents.
−Removed: Ares Management’s enterprise-wide cybersecurity program is aligned to the National Institute of Standards and Technology Cybersecurity Framework.
−Removed: Ares Management’s cybersecurity risk management processes include technical security controls, policy enforcement mechanisms, monitoring systems, tools and related services, which include tools and services from third-party providers, and management oversight to assess, identify and manage risks from cybersecurity threats.
−Removed: Ares Management has implemented and continues to implement risk-based controls designed to prevent, detect and respond to information security threats, and we rely on those controls to help us protect our information, our information systems, and the information of our investors, and other third parties who entrust us with their sensitive information.
−Removed: Ares Management’s cybersecurity program includes physical, administrative and technical safeguards, as well as plans and procedures designed to help Ares Management prevent and timely and effectively respond to cybersecurity threats and incidents, including threats or incidents that may impact us, our Sponsor or Ares Management.
−Removed: Ares Management’s cybersecurity risk management process seeks to monitor cybersecurity vulnerabilities and potential attack vectors, evaluate the potential operational and financial effects of any threat and mitigate such threats.
−Removed: The assessment of cybersecurity threats, including those which may impact us, our Sponsor or Ares Management, is integrated into Ares Management’s Enterprise Risk Management program, which is overseen by the Ares Enterprise Risk Committee (the “Ares Management ERC”), as discussed below.
−Removed: In addition, Ares Management periodically engages with third-party consultants and engages with key vendors to assist it in assessing, enhancing, implementing, and monitoring its cybersecurity risk management programs and responding to incidents.
−Removed: The Ares Management cybersecurity risk management and awareness programs include periodic identification and testing of vulnerabilities, regular phishing simulations and annual general cybersecurity awareness and data protection training.
−Removed: Ares Management’s cybersecurity training programs also include annual certification requirements for employees of Ares Management with respect to certain policies supporting the cybersecurity program including information security and electronic communications, data protection and privacy.
−Removed: Ares Management undertakes periodic internal security reviews of its information systems and related controls, including systems affecting personal data and the cybersecurity risks of Ares Management’s and our critical third-party service providers and other partners.
−Removed: Ares Management also completes periodic external reviews of its cybersecurity program and practices, which include assessments of relevant data protection practices and targeted attack simulations.
−Removed: In the event of a cybersecurity incident impacting us, our Sponsor or Ares Management, Ares Management has developed an incident response plan that provides guidelines for responding to an incident and facilitates coordination across multiple operational functions of Ares Management.
−Removed: The incident response plan includes notification to the applicable members of cybersecurity leadership, including Ares Management’s Chief Information Security Officer (“CISO”), and, as appropriate, escalation to the full Ares Management ERC and/or an internal ad-hoc group of senior employees, tasked with helping to manage the cybersecurity incident.
−Removed: Depending on their nature, incidents may also be reported to the audit committee or full board of directors of Ares Management, as well as to the audit committee of our board of directors and to our full board of directors, if appropriate.
−Removed: Material Impact of Risks from Cybersecurity Threats
−Removed: We have not experienced an information security breach incident that has materially affected our business strategy, results of operations or financial condition and have not incurred any expenses from information security breach incidents.
−Removed: We are not aware of any cybersecurity risks that are reasonably likely to materially affect our business.
−Removed: However, future incidents could have a material impact on our business strategy, results of operations, or financial condition.
−Removed: For additional discussion of the risks posed by cybersecurity threats, see “Item 1A.
−Removed: Risk Factors— General Risk Factors— Security incidents or cyber-attacks could adversely affect our business by causing a disruption to our operations, a compromise or corruption of our confidential, personal or other sensitive information and/or damage to our business relationships or reputation, any of which could negatively impact our business, financial condition and operating results.”
−Removed: Oversight of Cybersecurity Risks
−Removed: Our cybersecurity program is managed by Ares Management’s dedicated internal cybersecurity team, which is responsible for enterprise-wide cybersecurity strategy, policies, standards, engineering, architecture and processes.
−Removed: The team is led by Ares Management’s CISO who has a Master’s degree in Cybersecurity from Brown University and over 25 years of experience advising on, and managing risks from cybersecurity threats as well as developing and implementing cybersecurity policies and procedures.
−Removed: The Ares Management’s CISO reports cybersecurity updates to the Ares Management ERC.
−Removed: The Ares Management ERC is a committee that governs and oversees the Ares Management Enterprise Risk Program, including cybersecurity.
−Removed: The Ares Management ERC includes members of Ares Management’s senior executive management, including its Chief Executive Officer, Co-Presidents, Chief Financial Officer, General Counsel, Global Chief Compliance Officer and Head of Enterprise Risk, who acts as chairperson of the Ares Management ERC.
−Removed: The Ares Management ERC, through regular consultation with the Ares Management internal cybersecurity team, assesses, discusses, and prioritizes Ares Management’s approach to high-level risks, mitigating controls, and ongoing cybersecurity efforts.
−Removed: Our audit committee has primary responsibility for oversight with respect to risk assessment and risk management.
−Removed: As a company with no operations, we rely on the cybersecurity program and policies implemented by Ares Management.
−Removed: In the event of a cybersecurity incident impacting us or our Sponsor, the Ares Management CISO will report to our audit committee and provide updates on Ares Management’s incident response plan for addressing and mitigating any risks associated with such an incident.
+Added: Risk Management and Strategy
+Added: We have implemented a comprehensive cybersecurity risk management program designed to identify, assess, and mitigate material risks from cybersecurity threats to our technology stack, products, and confidential information.
+Added: Integrated with our overall enterprise risk management system, this program employs a risk-based approach designed to protect the confidentiality, integrity, and availability of our information systems.
+Added: Our Cybersecurity Incident Response Plan (“CSIRP”) defines roles and responsibilities for incident handling and functions as an integral component within our broader program, which combines proactive risk identification and mitigation with responsive threat management.
+Added: Cybersecurity is one of Kodiak’s six critical safety pillars.
+Added: Management is committed to minimize defects regarding IT infrastructure and maintains an active culture of excellence designed to reduce risks that could harm individuals or the Company’s finances and reputation.
+Added: Our strategy includes:
+Added: • Identification and Detection :
+Added: Active monitoring of systems and networks to identify unauthorized access, misuse, or compromise of protected information, including personal data.
+Added: • Third-Party Risk Management :
+Added: We engage external assessors and consultants to independently evaluate our information security program, conduct penetration testing, and assist in the identification of material risks.
+Added: addition, our Chief Legal and Policy Officer oversees the engagement of third-party forensics vendors to assist in investigations under attorney-client privilege when necessary.
+Added: • Incident Containment :
+Added: Standard protocols include isolating affected systems, blocking malicious domains, applying security patches, and rotating private keys or application secrets.
+Added: Risks from Threats and Incidents
+Added: We are subject to risks from cybersecurity threats that could lead to unauthorized access to, disruptions of, and other cybersecurity incidents impacting our technology stack, including products, or the compromise of personal information, which includes data capable of being associated with natural persons.
+Added: As of the date of this report, we are not aware of any security incidents that have materially affected our business strategy, results of operations, or financial condition.
+Added: However, for a detailed discussion of these risks, please refer to Item 1A, “Risk Factors.”
+Added: Our Board , primarily through its Audit Committee, oversees the Company's cybersecurity risk management program as an integrated part of overall enterprise risk oversight.
+Added: The Audit Committee is responsible for assisting the Board in overseeing the integrity of internal controls and major financial risk exposures.
+Added: Our cybersecurity management is led by our Chief Information Security Officer (“CISO”) , who brings over 25 years of industry experience leading information security teams at renowned technology companies.
+Added: Management’s responsibilities include:
+Added: • Incident Response Team :
+Added: A cross-functional team including representatives from security, IT, engineering, legal, and, external affairs is authorized to act quickly in the event of a security incident.
+Added: • Reporting and Communication :
+Added: The incident response team provides progress updates to management at least hourly during system outages.
+Added: Only the Chief Legal Officer is authorized to declare a security incident as a data breach under applicable law.
+Added: Our CISO provides briefings to the Audit Committee regarding our cybersecurity risk management program.
+Added: Our Audit Committee updates our Board on such reports.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.