7 unchanged sentences
LivePerson maintains a security risk management program that is tasked with determining the cybersecurity threats that pose the greatest risk to the Company.
−Removed: This program is managed by the Security Risk Committee, chaired by the Chief Security Officer (“CSO”), as well as representative members from security, operations, and internal audit leadership.
+Added: This program is managed by the Security Risk Committee, chaired by the Head of Security (“HOS”), as well as representative members from security, operations, and internal audit leadership.
The committee meets at least twice annually.
18 unchanged sentences
• penetration testing;
−Removed: • continuous proactive threat hunting;
−Removed: • cyber threat intelligence services including dark web monitoring;
• audits against industry standards including Systems and Organization Controls 2 (“SOC 2”), ISO 27001, PCI, and the HITRUST CST.
8 unchanged sentences
Risk Factors – Risks Related to Security Vulnerabilities and Service Reliability .
−Removed: Our information security team is led by our CSO .
−Removed: Friedman has held the position of CSO at organizations across multiple industries, including financial services, for over 13 years and holds industry security certifications including Certified
−Removed: Information Systems Security Professional (“CISSP”), Certified Information Systems Auditor (“CISA”), Certified Information Security Manager, and Certified in Risk and Information Systems Control.
+Added: Our information security team is led by our HOS.
+Added: Tinwala has over 15 years of information security experience at organizations across multiple industries, including financial services, and holds industry security certifications including Certified Information Systems Security Professional (“CISSP”) and Certified Information Systems Auditor (“CISA”).
Many members of the information security team also hold CISSP, CISA and other security related certifications.
7 unchanged sentences
Our Board of Directors takes an active role in overseeing the management of cybersecurity risks to the Company.
−Removed: The information security team provides periodic reports to the Cybersecurity and Technology Committee of the Board, as well as to the full Board, the Company’s Chief Executive Officer and other members of senior management, as appropriate.
+Added: The information security team provides periodic reports to the Board, the Company’s Chief Executive Officer and other members of senior management, as appropriate.
These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen its information security systems, assessments of the cybersecurity program and the emerging threat landscape.
−Removed: The cybersecurity program is periodically evaluated by internal and external experts with the results of those reviews reported to senior management and the Board of Directors.
+Added: cybersecurity program is periodically evaluated by internal and external experts with the results of those reviews reported to senior management and the Board of Directors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.