6 unchanged sentences
We employ a risk quantification model to identify, measure, and prioritize cybersecurity and technology risks, and we implement corresponding security controls and safeguards based on model outputs.
+Added: As part of our focus on the use of AI technology in our business, we developed an AI cybersecurity strategy designed to enable the building of secure and reliable AI systems while also managing ethical, legal, cyber, data privacy, and other technology risks.
+Added: The Company also established an AI Governance Committee, which is composed of leaders across a variety of business, technology, and support functions, to oversee the creation and implementation of risk control and strategic implementation frameworks.
In addition to cybersecurity risks being tracked, managed, and monitored directly by the information security group, cybersecurity risks are also integrated into, and are among the risks evaluated and considered by, our enterprise risk management program.
9 unchanged sentences
We also regularly conduct phishing and social engineering simulations, and host events to increase awareness, including an annual cybersecurity awareness summit and monthly campaigns.
−Removed: Table of Content s
• We have a cybersecurity incident response plan in place which provides a framework for responding to cybersecurity incidents.
18 unchanged sentences
The senior members of the information security group who report to the CISO have extensive experience in technology and security roles from serving with several large public companies and possess cybersecurity certifications, including Certified Information Systems Security Professional, Certified Information Security Manager, and Certified Information Systems Auditor, among others.
−Removed: Oversight responsibility over cybersecurity risk is shared by the Board and the Audit Committee, with the Audit Committee being primarily responsible for overseeing risks related to cybersecurity, data protection, and privacy matters.
+Added: Oversight responsibility over cybersecurity risk is shared by the Board and the Audit Committee, with the Audit Committee being primarily responsible for overseeing risks related to cybersecurity, data protection, privacy, and significant emerging technology.
The Audit Committee regularly reviews metrics about cyber threat response preparedness, program maturity milestones, risk mitigation status, and the current and emerging threat landscape, in addition to the results of third-party reviews and assessments of our security controls.
1 unchanged sentence
We also have protocols by which certain cybersecurity incidents are escalated and, where appropriate, reported to the Audit Committee in a timely manner.
−Removed: Table of Content s
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.