5 unchanged sentences
We have utilized the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF) as a baseline for the WISP procedures in addition to General Data Protection Regulation (GDPR) standards.
−Removed: In addition to our data privacy policy, the WISP policy defines how sensitive and private data are protected.
+Added: In addition to our data privacy policy, the WISP policy defines how sensitive and private data is protected.
Under our procedures, we perform an annual risk assessment to identify and prioritize key cybersecurity risks, and we update this assessment when we receive information about material new cybersecurity risks.
Once we identify material cybersecurity risks, we seek to identify and implement prevention measures.
−Removed: Current prevention measures include, among other things, to the extent we determine to be appropriate for our information systems in light of our financial, personnel and other resources, restricted physical access, restricted systems access, multi-factor authentication, software solutions such as intrusion detection systems, anti-virus, anti-malware, e-mail filtering and quarantining programs, routine system maintenance and updates, backup and recovery systems, routine employee cybersecurity training and testing, and quarterly internal audits.
+Added: Current prevention measures include, among other things, to the extent we determine to be appropriate for our information systems in light of our financial, personnel and other resources, restricted physical access, restricted systems access, multi-factor authentication, software solutions such as intrusion detection systems, anti-virus, anti-malware, email filtering and quarantining programs, routine system maintenance and updates, backup and recovery systems, routine employee cybersecurity training and testing, and quarterly internal audits.
The measures we take may be inadequate to protect us from cybersecurity risks.
4 unchanged sentences
In addition, we employ contractual provisions to require our third-party information service providers to implement and maintain appropriate security measures over the information we entrust to them.
−Removed: Because of the relatively small size of our information
−Removed: technology workforce, we have limited internal cybersecurity expertise and monitoring capabilities;
+Added: Because of the relatively small size of our information technology workforce, we have limited internal cybersecurity expertise and monitoring capabilities;
accordingly, we seek to augment our internal capabilities by engaging larger, well-known third-party service providers with significantly greater cybersecurity capabilities than we possess.
−Removed: Because we rely on their greater expertise, our ability to identify and remediate weaknesses or vulnerabilities in the services they provide is necessarily limited.
+Added: Because we rely on their greater expertise, our ability to identify and remediate weaknesses or vulnerabilities in the services they provide is limited.
We have not engaged third parties to assess our cybersecurity defenses or to audit our cybersecurity program, nor have we conducted direct or indirect technical evaluations of the information systems that our third-party service providers use.
Our Information Security Officer (“ISO”) is responsible for implementing, supervising and maintaining the WISP, including the implementation of prevention measures.
−Removed: The ISO reports directly to the Chief Technology Officer, who is also our Chief Information Security Officer (“CISO”).
+Added: The ISO reports directly to the VP Network Systems/Services Engineering, who is also our Chief Information Security Officer (“CISO”).
The CISO establishes the company-wide system security plan and defines the parameters of users’ access privileges.
−Removed: The CISO has worked in information technology and communications services for over 30 years, starting as a contractor at the Defense Advanced Research Projects Agency of the Department of Defense, managing the design and operation of the DARPA IT network, as the Network Operations Manager.
−Removed: At DARPA, the CISO oversaw the desktop computers, servers, local area networks, and Internet access, including edge security from 1992 to 1998.
−Removed: Since then, the CISO has managed customer network integrations for commercial satellite services at Hughes and at KVH.
−Removed: The CISO also developed a managed security service offering at KVH based on Fortinet technology.
+Added: The CISO has over 30 years in the network, security systems engineering fields and has been with KVH for 15 years.
+Added: Before KVH, the CISO worked in the telecom and ISP spaces covering transport, design and implementations.
+Added: In these roles, the CISO was responsible for all network-oriented security and developed in-depth experience on core security platforms.
+Added: At KVH, the CISO has been lead on security as a service for customer implementations.
We have also implemented an Incident Response Plan (“IRP”), which provides a set of guidelines on the appropriate responsive actions to take in the event of a cybersecurity incident, depending on the particular facts and circumstances of the incident.
1 unchanged sentence
Both the Board of Directors and the audit committee receive regular reports regarding material cybersecurity developments.
−Removed: In the case of a security incident, the ISO will report the incident directly to the Chief Executive Officer, Chief Technology Officer, Chief Financial Officer and Senior Vice President, General Counsel & Compliance Officer.
+Added: In the case of a security incident, the ISO will report the incident directly to the Chief Executive Officer, Chief Financial Officer, CISO and Senior Vice President, General Counsel & Compliance Officer.
The breach will then be communicated to the audit committee dependent on the materiality of the incident .
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.