6 unchanged sentences
In addition to our data privacy policy, the WISP policy defines how sensitive and private data is protected.
−Removed: Under our procedures, we perform an annual risk assessment to identify and prioritize key cybersecurity risks, and we update this assessment when we receive information about material new cybersecurity risks.
+Added: Under our procedures, we review the scope of the security measures in the WISP at least annually, or whenever there is a material change in our business practices or we receive information about material new cybersecurity threats or risks, that may implicate the security or integrity of records.
Once we identify material cybersecurity risks, we seek to identify and implement prevention measures.
11 unchanged sentences
Our Information Security Officer (“ISO”) is responsible for implementing, supervising and maintaining the WISP, including the implementation of prevention measures.
−Removed: The ISO reports directly to the VP Network Systems/Services Engineering, who is also our Chief Information Security Officer (“CISO”).
−Removed: The CISO establishes the company-wide system security plan and defines the parameters of users’ access privileges.
−Removed: The CISO has over 30 years in the network, security systems engineering fields and has been with KVH for 15 years.
−Removed: Before KVH, the CISO worked in the telecom and ISP spaces covering transport, design and implementations.
−Removed: In these roles, the CISO was responsible for all network-oriented security and developed in-depth experience on core security platforms.
−Removed: At KVH, the CISO has been lead on security as a service for customer implementations.
+Added: The ISO reports directly to the Chief Executive Officer.
+Added: The ISO has over 30 years of experience in the information technology field, including experience in healthcare system information technology, which included cybersecurity responsibilities, and then in project management office leadership for information technology managed services providers.
+Added: The ISO is supported by our former Chief Information Security Officer, who remains with KVH in an individual contributor capacity through mid-2026 and continues to provide cybersecurity expertise to the program.
We have also implemented an Incident Response Plan (“IRP”), which provides a set of guidelines on the appropriate responsive actions to take in the event of a cybersecurity incident, depending on the particular facts and circumstances of the incident.
1 unchanged sentence
Both the Board of Directors and the audit committee receive regular reports regarding material cybersecurity developments.
−Removed: In the case of a security incident, the ISO will report the incident directly to the Chief Executive Officer, Chief Financial Officer, CISO and Senior Vice President, General Counsel & Compliance Officer.
+Added: The discussion of cybersecurity issues is on the agenda of each quarterly Board of Directors' meeting.
+Added: In the case of a security incident, the ISO will report the incident directly to the Chief Executive Officer, Chief Financial Officer and Senior Vice President, General Counsel & Compliance Officer.
The breach will then be communicated to the audit committee dependent on the materiality of the incident .
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.