3 unchanged sentences
To mitigate the threat to our business, we take a comprehensive approach to cybersecurity risk management.
−Removed: Our Board and our management actively oversee our risk management program, including the management of cybersecurity risks.
−Removed: We have established policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats, including those discussed in our Risk Factors.
+Added: Our Board of Directors and our management actively oversee our risk management program, including the management of cybersecurity risks.
+Added: We have established policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats, including those discussed in Item 1A, Risk Factors .
We have devoted significant financial and personnel resources to implement and maintain security measures to meet regulatory requirements and stakeholder expectations, and we intend to continue to make significant investments to maintain the security of our data and cybersecurity infrastructure.
2 unchanged sentences
Risk Management and Strategy
−Removed: At a high level, the key objectives for the Company’s cybersecurity program are to implement and sustain effective security controls to stop intrusion attempts and to maintain and continuously improve its ability to respond to
−Removed: attacks and incidents.
+Added: At a high level, the key objectives for the Company’s cybersecurity program are to implement and sustain effective security controls to stop intrusion attempts and to maintain and continuously improve its ability to respond to attacks and incidents.
Success in achieving these objectives relies upon using quality technology solutions, cultivating and maintaining a team of skilled professionals, and improving processes continuously.
19 unchanged sentences
In this regard, the Company has implemented policies and procedures for all employees including:
−Removed: (i) information security/cybersecurity policies, which are internally available for all employees, (ii) information security/cybersecurity awareness training;
+Added: (i) information security/cybersecurity policies, which are internally available for all employees, (ii) information security/cybersecurity
+Added: awareness training;
(iii) a clear escalation process which employees can follow in the event an employee notices something suspicious;
2 unchanged sentences
Board Oversight :
−Removed: The Board, in coordination with the Audit Committee of the Board, has responsibility for managing the overall risk strategy for the Company, including cyber security risk.
−Removed: They receive regular reports from management about the prevention, detection, mitigation, and remediation of cybersecurity incidents, including material security risks and information security vulnerabilities.
+Added: The Board of Directors, in coordination with the Audit Committee of the Board, has responsibility for managing the overall risk strategy for the Company, including cyber security risk.
+Added: Both the Board of Directors and the Audit Committee receive regular reports from management about the prevention, detection, mitigation, and remediation of cybersecurity incidents, including material security risks and information security vulnerabilities.
Our Audit Committee directly oversees our cybersecurity program.
−Removed: The Audit Committee receives regular updates from management on cybersecurity risk resulting from risk assessments, progress of risk reduction initiatives, external auditor feedback, control maturity assessments, and relevant internal and industry cybersecurity incidents.
+Added: The Audit Committee additionally receives regular updates from management on cybersecurity risk resulting from risk assessments, progress of risk reduction initiatives, external auditor feedback, control maturity assessments, and relevant internal and industry cybersecurity incidents.
Management’s Role :
The Company employs a dedicated Chief Information Security Officer (“CISO”) who has primary responsibility for assessing and managing material cybersecurity risks .
−Removed: Our CISO reports to the Audit Committee of the Board quarterly, to provide updates on any new developments and about the effectiveness of the security program.
+Added: Our CISO reports to the Audit Committee quarterly, to provide updates on any new developments and about the effectiveness of the security program.
On behalf of the Audit Committee, the CISO administers a robust risk management program carried out by the Governance, Risk, and Compliance (GRC) team, which is integrated as part of the procurement process when making technology purchases, and also makes recommendations on security policies and procedures, security requirements, and risk mitigation strategies.
−Removed: Our CISO is supported by a highly skilled team of information security
−Removed: professionals, many of whom have advanced certifications and/or graduate degrees relevant to their job requirements.
−Removed: Our team has participated in multiple national and international cyber security exercises, including Cyber Storm, the national training exercise run by the US Department of Homeland Security in conjunction the US Cybersecurity and Infrastructure Security Agency.
+Added: Our CISO is supported by a highly skilled team of information security professionals, many of whom have advanced certifications and/or graduate degrees relevant to their job requirements.
+Added: Our team has participated in multiple national and international cyber security exercises, including Cyber Storm, the national training exercise run by the U.S.
+Added: Department of Homeland Security in conjunction the U.S.
+Added: Cybersecurity and Infrastructure Security Agency.
Our CISO works closely with our Chief Risk Officer to provide risk reporting and ensure security and compliance.
Chief Information Security Officer :
−Removed: Our CISO has led the Company’s security team for almost seven years, overseeing the implementation of multiple new technologies and processes to help protect the organization.
−Removed: Prior to joining the Company, he served as a Subject Mater Expert for Threat Prevention at a cyber security firm, consulted for local government, held other security and technology roles in higher education, and served in the US Navy.
+Added: Our CISO has led the Company’s security team for more than seven years, overseeing the implementation of multiple new technologies and processes to help protect the organization.
+Added: Prior to joining the Company, he served as a Subject Mater Expert for Threat Prevention at a cyber security firm, consulted for local government, held other security and technology roles in higher education, and served in the U.S.
He is also a co-author/contributor for the joint book project, Understanding New Security Threats published by Routledge in 2019, and has published articles and made conference keynote and podcast appearances over the years on cybersecurity topics.
−Removed: For more information regarding the risks we face from cybersecurity threats, please see “Risk Factors.”
+Added: For more information regarding the risks we face from cybersecurity threats, please see “Item 1A, Risk Factors .”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.