14 unchanged sentences
At least annually, we conduct a cybersecurity risk assessment that takes into account information from internal stakeholders, known information security vulnerabilities, and information from external sources, including reported security incidents that have impacted other companies, industry trends, and evaluations by third parties and consultants.
−Removed: The results of the assessment are used to develop initiatives to enhance our security controls, make recommendations to improve processes, and inform a broader Company-wide risk assessment that are then reported to our Board, Audit Committee and members of management.
+Added: The results of the assessment are used to develop initiatives to enhance our security controls, make recommendations to improve processes, and inform a broader Company-wide risk assessment that are then reported to our Board of Directors, Audit Committee and members of management.
Technical Safeguards :
12 unchanged sentences
Our policies require each of our employees to contribute to our data security efforts.
−Removed: We regularly remind employees of the importance of handling and protecting data, including through annual privacy and security training to enhance employee awareness of how to detect and respond to cybersecurity threats.
+Added: We regularly remind employees of the importance of handling and protecting data, including through annual privacy and
+Added: security training to enhance employee awareness of how to detect and respond to cybersecurity threats.
In this regard, the Company has implemented policies and procedures for all employees including:
−Removed: (i) information security/cybersecurity policies, which are internally available for all employees, (ii) information security/cybersecurity
−Removed: awareness training;
+Added: (i) information security/cybersecurity policies, which are internally available for all employees, (ii) information security/cybersecurity awareness training;
(iii) a clear escalation process which employees can follow in the event an employee notices something suspicious;
2 unchanged sentences
Board Oversight :
−Removed: The Board of Directors, in coordination with the Audit Committee of the Board, has responsibility for managing the overall risk strategy for the Company, including cyber security risk.
+Added: The Board of Directors, in coordination with the Audit Committee of the Board of Directors, has responsibility for managing the overall risk strategy for the Company, including cyber security risk.
Both the Board of Directors and the Audit Committee receive regular reports from management about the prevention, detection, mitigation, and remediation of cybersecurity incidents, including material security risks and information security vulnerabilities.
11 unchanged sentences
Chief Information Security Officer :
−Removed: Our CISO has led the Company’s security team for more than seven years, overseeing the implementation of multiple new technologies and processes to help protect the organization.
+Added: Our CISO has led the Company’s security team for more than eight years, overseeing the implementation of multiple new technologies and processes to help protect the organization.
Prior to joining the Company, he served as a Subject Mater Expert for Threat Prevention at a cyber security firm, consulted for local government, held other security and technology roles in higher education, and served in the U.S.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.