15 unchanged sentences
We maintain a Cybersecurity Policy, which includes an Incident Response Plan in the event of a significant cybersecurity incident.
−Removed: In the event of a significant cybersecurity incident, our IT Director will chair an incident response team to handle the incident.
+Added: In the event of a significant cybersecurity incident, our IT Systems Administrator will chair an incident response team to handle the incident.
Such incident response team will include members of IT, finance (if applicable), legal, communications, human resources and any affected unit or department.
1 unchanged sentence
Management Oversight
−Removed: The controls and processes employed to assess, identify and manage material risks from cybersecurity threats are implemented and overseen by our IT Director.
−Removed: Our IT Director has over 10 years of experience addressing cybersecurity risks.
−Removed: Our IT Director is responsible for the day-to-day management of the cybersecurity program, including the prevention, detection, investigation, response to, and recovery from cybersecurity threats and incidents, and is regularly engaged to help ensure the cybersecurity program functions effectively in the face of evolving cybersecurity threats.
−Removed: Our Chief Technology Officer oversees the IT Director and briefs our board of directors on cybersecurity matters, including the nature and design of our cybersecurity program, and threats, events, and program enhancements.
+Added: The controls and processes employed to assess, identify and manage material risks from cybersecurity threats are implemented and overseen by our IT Systems Administrator .
+Added: Our IT Systems Administrator has 15 years in total network and system administration experiences, 8 of which are experience addressing cybersecurity risks.
+Added: Our IT Systems Administrator is responsible for the day-to-day management of the cybersecurity program, including the prevention, detection, investigation, response to, and recovery from cybersecurity threats and incidents, and is regularly engaged to help ensure the cybersecurity program functions effectively in the face of evolving cybersecurity threats.
+Added: Our Vice President of Corporate Development & Administration oversees the IT Systems Administrator and briefs our board of directors on cybersecurity matters, including the nature and design of our cybersecurity program, and threats, events, and program enhancements.
Board Oversight
−Removed: In its oversight role, our board of directors is expected to specifically consider risks, including with respect to privacy, information technology and cybersecurity and threats to technology infrastructure.
−Removed: On a regular basis, our IT Director will report to our board of directors on cybersecurity matters, including key risks, the potential impact of those exposures on our business, financial condition, results of operations, cash flows, reputation and prospects, and the programs and steps implemented by our management team to monitor and mitigate risks.
+Added: In its oversight role, our board of directors considers risks, including with respect to privacy, information technology and cybersecurity and threats to technology infrastructure.
+Added: On a regular basis, our Vice President of Corporate Development & Administration will report to o ur board of directors on cybersecurity matters, including key risks, the potential impact of those exposures on our business, financial condition, results of operations, cash flows, reputation and prospects, and the programs and steps implemented by our management team to monitor and mitigate risks.
Cybersecurity Risks
Our cybersecurity risk management processes are integrated into our overall approach to risk management.
−Removed: Given our nature and size, we do not have a dedicated enterprise risk function, but our management team regularly considers and evaluates risks.
+Added: Given our nature and size, we do not have a dedicated enterprise risk function, but our management team regularly considers and evaluates the cybersecurity risks.
As part of that risk management process, our management team identifies, assesses and evaluates risks impacting our operations, including those risks related to cybersecurity, and raise them for internal discussion, and where it is determined to be appropriate, issues are also raised to our board of directors for consideration.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.