2 unchanged sentences
Risk management and strategy
−Removed: The Company’s risk management process includes assessing, identifying and managing material risks from various sources, including those related to cybersecurity.
−Removed: The Company uses information from incident history, industry publications and analysis centers, public news, government information sharing and recognized information security frameworks to inform its risk management program.
−Removed: Management employs a suite of detective and preventative cybersecurity measures including, but not limited to
+Added: The Company’s risk management process includes the identification, assessment and management of material risks from various sources, including risks related to cybersecurity and information technology.
+Added: The Company uses information from multiple sources, including internal incident history, industry publications and analysis centers, public reporting, government and industry information sharing organizations and recognized information security frameworks to inform its risk management program.
+Added: Management employs a combination of preventative and detective cybersecurity measures designed to protect the confidentiality, integrity and availability of the Company's information systems and data, including, but not limited to
• Maintaining a vulnerability management program,
1 unchanged sentence
• maintaining an enterprise-wide security awareness program and
−Removed: • administering periodic trainings.
−Removed: The Company engages multiple vendors with subject matter and technological expertise in various aspects of cybersecurity management, including continuous threat detection and response coverage, endpoint detection, anti-malware, penetration testing and suspicious activity alerting, among others.
−Removed: When the Company engages third parties, management retains responsibility for the security and resiliency of its information assets.
−Removed: The Company maintains an incident response plan that includes escalation criteria and preliminary materiality assessments to guide business continuity and disclosure objectives.
−Removed: We describe risks related to cybersecurity threats that could materially impact our business strategy, results of operations or financial condition under the heading “Risk Factors.” Material impacts could include loss of access to systems and data, financial costs and reputational harm, among others.
+Added: • administering periodic cybersecurity trainings.
+Added: The Company engages third-party vendors with specialized expertise to support various aspects of its cybersecurity program, including continuous threat detection and response coverage, endpoint detection, anti-malware, penetration testing and suspicious activity alerting, among others.
+Added: While the Company leverages third party service providers, management retains responsibility for the security and resiliency of the Company's information assets.
+Added: The Company maintains an incident response plan designed to enable timely detection, escalation, containment and remediation of cybersecurity incidents that includes escalation criteria and preliminary materiality assessment considerations to guide business continuity and disclosure objectives.
+Added: We describe cybersecurity-related risks that could materially impact our business strategy, results of operations or financial condition under the heading “Risk Factors.” Potential material impacts of a cybersecurity incident may include, among other things, loss of access to systems and data, financial costs, operational disruption, regulatory scrutiny, litigation and reputational harm.
Our Chief Executive Officer ("CEO") is responsible for assessing and managing overall material risks to the Company.
−Removed: With respect to cybersecurity risks, our CEO leverages the collective expertise of the Company’s information security function which reports to our CEO through the Company’s Chief Information Officer.
−Removed: The information security function is staffed with individuals with extensive information security employment experience, including in the financial services sector, educational experience and relevant credentials.
−Removed: The Audit Committee of the Board of Directors (the "Audit Committee") is responsible for receiving periodic updates on cybersecurity and information security risks, reviewing and discussing with management the quality and effectiveness of the Company’s efforts to mitigate such risks and reporting such findings to the Board of Directors.
−Removed: Management informs the Audit Committee about prevention, detection, mitigation and remediation of cybersecurity incidents at least semi-annually and monitors such matters continuously.
−Removed: In 2025, the oversight over the Company's cybersecurity risk will transition from the Audit Committee to the Board of Directors ("the Board") to align with the Board's oversight of operational risks.
+Added: With respect to cybersecurity risks, our CEO oversees and leverages the collective expertise of the Company’s information security function which reports to our CEO through the Company’s Chief Information Officer.
+Added: The information security function is staffed with individuals with relevant information security professional experience, including in the financial services sector, as well as educational experience and industry-recognized credentials.
+Added: The Company's Board of Directors ("the Board") is responsible for receiving periodic updates on cybersecurity and information security risks and reviewing and discussing with management the quality and effectiveness of the Company’s efforts to mitigate such risks.
+Added: Management informs the Board about the Company's cybersecurity risk posture, including prevention, detection, mitigation and remediation activities no less frequently than semi-annually and provides updates as appropriate in connection with material developments, while management continues to monitor such matters on an ongoing basis.
We own our executive and insurance offices located in Richmond, Virginia, and we currently occupy approximately 199,000 square feet of the 262,000 square feet of available office space.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.