2 unchanged sentences
Risk Management and Strategy
−Removed: We take a layered approach to cybersecurity leveraging multiple levels of controls designed to mitigate and minimize cybersecurity risks and protect the confidentiality, integrity, and availability of our critical systems and information.
−Removed: We have established and implemented policies and processes designed to assess, identify, and manage risks from cyber security threats, including product and SaaS security, and have integrated these into our operating model and enterprise risk management processes.
−Removed: We monitor for, and assess, material risks from cyber security threats such as unauthorized occurrences or events on or conducted through our information systems that may result in adverse effects to the confidentiality, integrity, or availability of our information systems or information, including personal information, proprietary information and intellectual property.
+Added: We take a layered approach to cybersecurity and leverage multiple levels of controls designed to mitigate and minimize cybersecurity risks and protect the confidentiality, integrity, and availability of our critical systems and information.
+Added: We have established and implemented policies and processes designed to assess, identify, and manage risks from cybersecurity threats, including those related to our products and SaaS security, and have integrated these activities into our operating model and enterprise risk management processes.
+Added: We monitor for, and assess, material risks from cybersecurity threats such as unauthorized occurrences or events on or conducted through our information systems that may result in adverse effects to the confidentiality, integrity, or availability of our information systems or information, including personal information, proprietary information, and intellectual property.
Identification and Assessment
−Removed: To identify and assess risk, we maintain a cybersecurity risk register which is reviewed regularly and updated as appropriate.
−Removed: These risk assessments include identification of reasonably foreseeable internal and external risks, the likelihood and potential damages that could result from such risks (to the extent known), and the potential sufficiency of existing mitigating policies, procedures, systems, and safeguards.
+Added: To identify and assess risk, we maintain a cybersecurity risk register that is reviewed regularly and updated as appropriate.
+Added: These risk assessments include identification of reasonably foreseeable internal and external risks, consideration of our use of third-party service providers and vendors, the likelihood and potential damages that could result from such risks (to the extent known), and the potential sufficiency of existing mitigating policies, procedures, systems, and safeguards.
Risk is scored based on the potential impact to the business (inherent risk) and re-scored based on mitigations in place (residual risk).
−Removed: Following this assessment, we determine opportunities for further mitigating identified risks.
+Added: Following this assessment, we determine opportunities to further mitigate identified risks, including potential changes to controls and processes.
Risk Mitigation
−Removed: We implement and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats, including product and SaaS security.
−Removed: These measures vary depending on the environment and threat.
−Removed: For example, we monitor our information systems, networks, and devices for potential threats, utilizing multiple mechanisms.
−Removed: We maintain Network Security Operations (NSO) and Site Reliability Engineering (SRE) teams to respond to potential threats or anomalies.
−Removed: We update vendor-provided tools (e.g.
−Removed: data management systems, financial reporting systems and infrastructure systems) in an effort to address identified vulnerabilities or threat vectors arising through vendor-provided products and services.
−Removed: We have adopted policies and standards aimed at implementing product security, including:
−Removed: conducting third-party penetration testing of our SaaS solutions;
−Removed: developing code based on a Security Software Development Lifecycle (SSDLC) process;
−Removed: and using automated tools for static code analysis and open-source scanning.
−Removed: Changes to material systems are governed by our change management processes.
−Removed: Certain systems are scanned for static and dynamic vulnerabilities.
−Removed: Automatic and manual penetration tests of certain environments are performed frequently and often through third-party testing groups.
−Removed: We have processes in place designed to control access to material systems and such processes are reviewed and updated as appropriate.
−Removed: We utilize certain controls such as two-factor authentication, intelligent anomaly detection and centralized identity and access management tools, designed to mitigate the risk of inappropriate access to internal user accounts.
−Removed: We use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example dynamic vulnerability testing, third party library vulnerability scanning, end-point management, enterprise monitoring tool, Attack Surface Management, web application firewall (WAF)/distributed denial-of-service (DDoS)/constant delivery network (CDN)/domain name server (DNS) protection, and backups and recovery.
−Removed: We also utilize service providers to assist with cybersecurity risk assessments.
+Added: We implement and maintain various technical, physical, and organizational measures, processes, standards, and policies designed to manage and mitigate material risks from cybersecurity threats, including those related to our products and SaaS security.
+Added: These measures include monitoring our information systems, networks, and devices for potential threats, managing vulnerabilities, and updating systems and tools to address identified risks or emerging threat vectors.
+Added: Changes to material systems are governed by our change management processes, and we evaluate certain systems for potential vulnerabilities on a periodic basis.
+Added: We also maintain processes designed to control access to material systems, which are reviewed and updated as appropriate.
+Added: We also use third-party service providers, some of which incorporate machine-learning or AI capabilities, to assist in detecting anomalous activity and identifying potential cybersecurity threats.
+Added: As part of our product development and operational practices, we incorporate security reviews intended to identify and mitigate potential risks in our products and services.
+Added: These reviews may include penetration testing, secure development practices, and the use of automated tools to help identify potential vulnerabilities.
Vendor Management
−Removed: In providing our products and services, we make extensive use of third-party vendors and applications.
−Removed: We onboard material vendors through a vendor review process, which includes a security assessment and a determination of what is required (for example, policies, procedures, technical controls, or physical controls) in an effort to securely configure any interaction with them.
−Removed: Vendors providing certain services may be subject to greater scrutiny, including reviews of any relevant certifications and/or independent testing of their products or systems.
−Removed: Certain vendors are reviewed annually in an effort to assess continued compliance with their obligations to us, and as relevant, the risk that they pose to our cybersecurity posture.
−Removed: Such reviews typically depend on the nature of the data and/or systems that these vendors may have access to or with which they otherwise interact.
+Added: In providing our products and services, we use third-party vendors and applications extensively.
+Added: We onboard material vendors through a vendor review process, which includes a security assessment, and evaluate certifications and testing as relevant.
+Added: Vendors are reviewed periodically to assess compliance and related cybersecurity risk.
Additional Information
−Removed: For additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this annual report on Form 10-K, including the risk factors entitled “Risk Factors—Risks Related to Privacy and Cybersecurity.”
+Added: For additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to “Item 1A.
+Added: Risk Factors” in this annual report on Form 10-K.
+Added: To date, we have not identified cybersecurity incidents that have materially affected our business strategy, results of operations, or financial condition.
+Added: However, cybersecurity threats continue to evolve and future incidents could be material.
+Added: Threat actors are also increasingly leveraging AI to enhance phishing, social engineering, and attack automation.
Responsibilities of the Board of Directors
Our Board provides oversight of our risk management process, including risks from cybersecurity threats.
−Removed: Our Board is responsible for monitoring and assessing strategic risk exposure and the mitigation and remediation of cybersecurity incidents, and our executive officers (including our Chief Executive Officer, Chief Financial Officer, and Chief Operating Officer) are responsible for the day-to-day management of the material risks we face, including cybersecurity risks.
+Added: Our Board is responsible for monitoring and assessing strategic risk exposure and the mitigation and remediation of cybersecurity incidents, and our executive officers (including our Chief Executive Officer and Chief Financial Officer) are responsible for the day-to-day management of the material risks we face, including cybersecurity risks.
Our Board administers its cybersecurity risk oversight function as a whole, as well as through the Audit Committee (“AC”).
−Removed: Our corporate security team informs the Board and AC of certain cybersecurity risks and threats during quarterly meetings and provide materials shared in connection with such meetings, as well as ad hoc updates when there are material developments or changes that may impact cybersecurity risk to the company.
+Added: Our corporate information security team informs the Board and AC of certain cybersecurity risks and threats during quarterly meetings and provides materials shared in connection with such meetings, as well as ad hoc updates when there are material developments or changes that may impact cybersecurity risk to the company.
Refer to “Item 10.
1 unchanged sentence
Responsibilities of Management
−Removed: Our corporate security team consists of the Chief Information Security Officer, the Manager of Security Engineering, a Senior Security Engineer, a Senior SRE, and a Security Engineering Contractor.
−Removed: The corporate security team is primarily responsible for assessing and managing material risks from cyber security threats, defining and overseeing our corporate security program, reviewing technical designs and vendors for security risks, and managing our security tools and infrastructure.
−Removed: Our corporate security team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us;
−Removed: and alerts and reports produced by security tools deployed in the information technology systems environment, including those described in “Risk Management and Strategy.” The corporate security team reports to the Senior Manager of Information Technology, who reports to the Senior Director of Engineering Operations which maintains responsibility for our cyber security program.
−Removed: The corporate security team has a combined professional experience of several decades in cybersecurity and related fields, including software and hardware engineering, information technology systems, devops, and security program management.
−Removed: They hold a range of certifications in security and technology, such as in LCSPC, ISO/IEC 27001:2013, OSCP, SANS SEC, CSSLP and AWS.
−Removed: Several team members participate in groups that focus on information security such as OWASP, Open Security Summit and other professional organizations and projects.
−Removed: Our Chief Information Security Officer provides frequent briefings to management regarding the Company’s cyber security risks and risk-mitigation efforts, which may include recent incidents and related responses, newly identified risks, changes to the security program, and activities of third parties and vendors, as appropriate.
+Added: Our corporate information security team, reporting to our Chief Technology Officer , is primarily responsible for assessing and managing material risks from cybersecurity threats, defining and overseeing our corporate security program, reviewing technical designs and vendors for security risks, and managing our security tools and infrastructure.
+Added: The team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include threat intelligence and other information obtained from governmental, public, or private sources, including external consultants engaged by us;
+Added: and alerts and reports produced by security tools deployed in the information technology systems environment, including those described in “Item 1C.
+Added: Cybersecurity — Risk Management and Strategy.”
+Added: Our corporate information security team provides frequent briefings to management regarding the Company’s cyber security risks and risk-mitigation efforts, which may include recent incidents and related responses, newly identified risks, changes to the security program, and activities of third parties and vendors, as appropriate.
Management provides cybersecurity updates to executive management and the Board through meetings and materials shared in connection with those meetings, as well as ad hoc updates when there are material developments or changes.
Incident Response Procedures
−Removed: Our cybersecurity incident response procedures are designed to escalate certain cyber security incidents to our executive officers and the Board as appropriate.
−Removed: Upon initial discovery of a potential incident, a member of the corporate security team leads the initial potential incident response efforts.
−Removed: Potential incidents are scored based on impact (including potential impact), and if certain criteria are met, the technical response team is broadened to include a representative from the Company’s legal team and other relevant stakeholders (such as executive management) as appropriate.
−Removed: Our incident response team or its designee, provides relevant updates to the Chief Executive Officer or other Company senior management and the Board, as appropriate.
+Added: We maintain cybersecurity incident response procedures designed to identify, assess, escalate, and remediate cybersecurity incidents.
+Added: These procedures include processes for evaluating the nature and potential impact of an incident, determining whether disclosure or regulatory reporting is required, and coordinating response efforts across relevant internal teams and external specialists, as appropriate.
+Added: Significant cybersecurity incidents are reported to senior management and, when appropriate, to the Board of Directors or the AC.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.