44 unchanged sentences
Our Audit Committee reviews the Company’s cybersecurity risk profile and risk management strategies at regular intervals.
−Removed: Our CFO reviews with the Audit Committee categories of risk the Company faces, including cybersecurity risks, as well as the likelihood of the occurrence of cybersecurity risks, the potential impact of those risks and the steps management has taken to monitor, mitigate and control such risks.
+Added: Management reviews with the Audit Committee categories of risk the Company faces, including cybersecurity risks, as well as the likelihood of the occurrence of cybersecurity risks, the potential impact of those risks and the steps management has taken to monitor, mitigate and control such risks.
In addition, our CISO reports at least annually to the Board, and at least quarterly to the Board’s Audit Committee, with respect to cybersecurity risks, including those identified through review of our business, of rising threats in the industry, and of the current state of Lazard’s cybersecurity program.
4 unchanged sentences
Our disclosure controls and procedures provide for the CSIHT to report high severity cybersecurity incidents to an Assessment Committee, consisting of our CFO, CISO and General Counsel, among others, for an assessment of materiality.
−Removed: The Assessment Committee in consultation with third-party experts, as warranted, makes the incident materiality determination consistent with SEC guidance and by considering relevant quantitative and qualitative factors, including without limitation:
−Removed: • the probability of an adverse outcome;
−Removed: • the potential impact on financial results;
−Removed: • the likelihood of litigation or regulatory investigations;
−Removed: • the potential impact on the Company’s reputation and competitiveness.
+Added: The Assessment Committee in consultation with third-party experts, as warranted, makes the incident materiality determination consistent with SEC guidance.
A determination that a cybersecurity incident has, or is reasonably likely to have, a material impact on the Company is reported by the Assessment Committee to the CEO and the Board’s Audit Committee without delay.
The Assessment Committee also provides a summary of all incidents that are determined to be immaterial to the Board’s Audit Committee at the next scheduled meeting.
−Removed: For additional information regarding how cybersecurity threats or incidents are reasonably likely to materially affect our business strategy, results of operations or financial condition, see “ Risk Factors—A failure in or breach of our information systems or infrastructure, or those of third parties with which we do business, including as a result of cybersecurity incidents or threats, could disrupt our businesses, lead to reputational harm and legal liability or otherwise impact our ability to operate our business ” and “ Risk Factors—Other operational risks may disrupt our businesses, result in regulatory action against us or limit our growth .”
+Added: For additional information regarding how cybersecurity threats or incidents are reasonably likely to materially affect our business strategy, results of operations or financial condition, see “ Risk Factors—A failure in or breach of our information systems or infrastructure, or those of third parties with which we do business, including as a result of cybersecurity incidents or threats, could disrupt our businesses, lead to reputational harm and legal liability or otherwise
+Added: impact our ability to operate our business ” and “ Risk Factors—Other operational risks may disrupt our businesses, result in regulatory action against us or limit our growth .”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.