5 unchanged sentences
The Company’s senior leadership receives updates from relevant functional heads or other subject matter specialists on these potential material risks as well as the processes or other steps being taken to manage or mitigate the risks.
−Removed: The team includes senior leaders in areas of importance to Company priorities, including the Company’s Chief Privacy Officer, who is also our Vice President of Information Technology and the Chief Legal Officer.
+Added: The team includes senior leaders in areas of importance to Company priorities, including the Company’s Chief Privacy Officer, who is also our Senior Vice President of Information Technology and the Chief Legal Officer .
The Company’s senior leadership assesses and prioritizes risk based on impact to shareholders, operations, and strategic priorities, among other factors.
The Chief Privacy Officer oversees the Company’s information security program and is responsible for the day-to-day information risk management activities through the internal information security team, and outside resources.
−Removed: The VP, Chief Privacy Officer, who has 30 years of IT and IT security experience, 20 of which are at the Company, employs a team of information technology experts, including a dedicated Cyber Security Analyst.
+Added: The SVP, Chief Privacy Officer, who has over 30 years of IT and IT security experience, 21 of which are at the Company, employs a team of information technology experts, including a dedicated Cyber Security Analyst.
The VP, Chief Privacy Officer and the Cyber Security Analyst are further supported by other members of the IT department.
The Company’s processes to assess, identify and manage material risks from cybersecurity threats include, but are not limited to, the following:
−Removed: ● The VP, Chief Privacy Officer, dedicated Cyber Security Analyst, and other key members of the information technology team actively monitor threats to the information technology environment.
+Added: ● The SVP, Chief Privacy Officer, dedicated Cyber Security Analyst, and other key members of the information technology team actively monitor threats to the information technology environment.
They work with a third party to provide additional 24/7 monitoring of cyber threats.
3 unchanged sentences
Such systems are regularly reviewed for adequacy and potential enhancements.
−Removed: ● The Company employs an information security and training program for our employees, including mandatory computer-based training, regular internal communications, and ongoing end-user testing to measure the effectiveness of our information security program.
+Added: ● The Company employs an information security and training program for our employees, including annual mandatory computer-based training, regular internal communications, and ongoing end-user testing throughout the year to measure the effectiveness of our information security program.
● The Company engages external third parties to advise on emerging threats to stay current and strengthen our security capabilities.
6 unchanged sentences
In connection with the Company’s review and approval for potential new vendors, the Company assesses the data types or Personally Identifiable Information that the vendor may maintain, store or access and reviews the adequacy of their cybersecurity procedures and legal protections.
−Removed: Legal counsel and the VP, Chief Privacy Officer review the cyber and contractual protections and consider the overall risk profile considering the type of agreement, data involved, vendor, and jurisdiction, among other factors.
+Added: Legal counsel and the SVP, Chief Privacy Officer review the cyber and contractual protections and consider the overall risk profile considering the type of agreement, data involved, vendor, and jurisdiction, among other factors.
Vendors deemed to have insufficient controls balancing the relevant criteria will not be approved.
1 unchanged sentence
The Audit Committee is responsible for overseeing threats to the Company, including those involving cyber threats, and reviewing the Company’s protocols and procedures to mitigate those threats.
−Removed: On a quarterly basis, the VP, Chief Privacy Officer, presents to the Audit Committee on the Company’s cybersecurity compliance and risk management practices.
+Added: On a quarterly basis, the SVP, Chief Privacy Officer, presents to the Audit Committee on the Company’s cybersecurity compliance and risk management practices.
These presentations address, among other things, the results of audits and reviews of our security information systems and other cybersecurity measures, the current threat environment and cybersecurity trends and best practices.
3 unchanged sentences
To date, the Company has not, to its knowledge, experienced any cybersecurity threats or previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: In the last three years, the Company has not experienced any material cybersecurity incidents and we have not incurred material expenses from cybersecurity incidents (including penalties and settlements, of which there were none).
However, we can give no assurance that we have detected or protected against all cybersecurity incidents or cybersecurity threats.
−Removed: Please refer to the risk factor titled “ Our inability or failure to execute our business continuity and response plan following a major disaster such as a natural disaster, terrorism, social unrest or a cybersecurity incident affecting our corporate facilities could materially adversely affect our business” in “Item 1A, Risk Factors” in this report for additional information about risks related to cybersecurity matters.
+Added: Please refer to “Item 1A, Risk Factors— Risks Related to Information Technology and Data Security” in this Annual Report for additional information about risks related to cybersecurity matters.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.