9 unchanged sentences
• Maintaining a defined disaster recovery policy and employing disaster recovery software, where appropriate;
−Removed: • Educating, training and testing our user community on information security practices and identification of potential cybersecurity risks and threats;
+Added: • Educating, training and testing our employees and user community on information security practices and identification of potential cybersecurity risks and threats;
• Reviewing and evaluating new developments in the cyber threat landscape.
4 unchanged sentences
To our knowledge, we have not been subject to cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, the Company, its operations or financial standing.
−Removed: Our cybersecurity risk management program is overseen by management at multiple levels.
−Removed: Our Vice President, Information Technology plays a key role in assessing, monitoring and managing our cybersecurity risks with support from dedicated information technology and security personnel.
−Removed: Our cybersecurity and risk management protocols are led by our Vice President of IT , who has served in this role since 2019.
−Removed: Our Vice President, Information Technology has an MS in Engineering and Technology Management and over 20 years of experience in managing and leading information technology or cybersecurity teams and oversees a team of information technology professionals who identify, assess, and manage cybersecurity threats on an ongoing basis.
+Added: Our cybersecurity and risk management program is led by our Vice President of Information Technology , who has served in executive technology and cybersecurity leadership roles for over 20 years.
+Added: She holds a Master of Science in Telecommunications Engineering & Management and is ITIL certified.
+Added: She oversees enterprise cybersecurity strategy, architecture, and operations across a nationwide organization, directing a team responsible for identifying, assessing, and mitigating cybersecurity risks on an ongoing basis.
+Added: Her experience includes leading incident response efforts, implementing disaster recovery capabilities, modernizing enterprise networks, supporting regulatory audits, and achieving strong third-party penetration testing and phishing resilience results.
+Added: This leadership supports the Company’s commitment to maintaining a secure, resilient, and well-governed technology environment.
+Added: Under her direction, the Company establishes and executes enterprise-wide cybersecurity strategy, governance, and risk management practices designed to protect the confidentiality, integrity, and availability of our systems and data.
+Added: dedicated team responsible for the continuous identification, assessment, and mitigation of cybersecurity threats and oversees incident response, disaster recovery, third-party security testing, and compliance with internal controls and audit requirements.
+Added: Her oversight supports the Company’s efforts to maintain a secure and resilient technology environment aligned with business objectives and regulatory expectations.
Our information technology group monitors the latest developments in cybersecurity, including emerging threats and innovative risk management techniques.
8 unchanged sentences
• Compliance status and efforts with regulatory requirements and industry standards.
−Removed: Furthermore, at the Board meetings at which our Vice President, Information Technology or other members of our information technology group do not provide in-person updates to the Board, our CEO or another executive team member
−Removed: provides current updates to the Board.
+Added: Furthermore, at the Board meetings at which our Vice President, Information Technology or other members of our information technology group do not provide in-person updates to the Board, our CEO or another executive team member typically provides current updates to the Board.
In addition, our information technology group provides updates to the full Board upon request, or timely updates regarding unique developments such as regulatory updates or vulnerability developments.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.