7 unchanged sentences
(iii) protecting the Company’s intellectual property;
−Removed: (iv) maintaining the confidence of our customers, suppliers and other third parties;
+Added: (iv) maintaining the confidence of our employees, patients, HCPs, suppliers, and other third parties;
and (v) providing appropriate public disclosure of cybersecurity risks and incidents when required.
+Added: Our cybersecurity program is developed using industry standards and best practices as a guide, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.
+Added: The NIST framework provides us with a common language and structure for identifying, assessing, and managing cybersecurity risks across our organization.
Cyber Security Risk Management and Strategy
11 unchanged sentences
A part of our strategy for managing risks from cybersecurity threats is assessment and testing of the effectiveness of our cybersecurity measures.
−Removed: We engage third parties to perform assessments on our cybersecurity measures, and we adjust our cybersecurity measures as necessary based on the information provided by the assessments.
+Added: We engage third parties to perform assessments on our cybersecurity measures, including annual penetration testing, and we adjust our cybersecurity measures as necessary based on the information provided by the assessments.
The Board oversees the management of risks from cybersecurity threats.
The Board receives regular presentations and reports on cybersecurity, which address a wide range of topics and also receives prompt and timely information regarding any cybersecurity incident that is or may become material, as well as ongoing updates regarding such incident until it has been addressed.
−Removed: At least once each year, the Board discusses the Company’s approach to cybersecurity risk management with the Company’s Senior Director of Cyber Securit y , who is the member of management that is principally responsible for overseeing cybersecurity at the Company, in partnership with other business leaders across the Company, including our Chief Executive Officer, Chief Accounting Officer, General Counsel, and Human Resources leader.
+Added: At least once each year, the Board discusses the Company’s approach to cybersecurity risk management with the Company’s Executive Director of Information Technology Operations and Information Security, who is the member of management that is principally responsible for overseeing cybersecurity at the Company, in partnership with other business leaders across the Company, including our Chief Executive Officer, Chief Accounting Officer, General Counsel, and Human Resources leader.
Our Senior Director of Cyber Security has served in various roles in information technology and information security for over 20 years, including serving as Information Security Officer for a global medical device manufacturer.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.