8 unchanged sentences
and (c) reporting in accordance with the service level agreement and support commitment adherence data to Lightbridge via MSP’s Service Delivery Team.
−Removed: vCIO services also include the following:
−Removed: Providing operational oversight of IT functions
+Added: vCIO will also:
+Added: Provide operational oversight of IT functions;
Identify and help plan for improvements to Lightbridge’s overall infrastructure;
9 unchanged sentences
Vulnerability Scanning
−Removed: Next-Generation Anti-Virus ("NGAV")
−Removed: We and our MSP/MSSP also utilize processes designed to reduce cybersecurity risk from a third-party vendor and technology.
+Added: Next-Generation Anti-Virus
+Added: We and our MSP/MSSP also utilize processes designed to reduce cybersecurity risk from third-party vendors and technology.
For example, we may conduct upfront diligence of the third-party’s cybersecurity, employ contracts that address cybersecurity risk, and monitor vendors’ compliance with their representations regarding cybersecurity.
2 unchanged sentences
The vCIO reports to our CFO.
−Removed: This vCIO is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from other professionals in the industry, many of whom hold cybersecurity certifications, and through the use of technological tools and software and results from third-party audits.
+Added: The vCIO (and support team) has appropriate experience and training in cybersecurity and is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from other professionals in the industry, many of whom hold cybersecurity certifications, and through the use of technological tools and software and results from third-party audits.
The vCIO issues quarterly reports and reports to the CFO, as appropriate, to provide updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the emerging threat landscape.
−Removed: The Company requires its employees and applicable contractors to take a yearly cyber training courses and its employees and applicable contractors are also required to sign confidentiality agreements for purposes including ensuring cybersecurity.
+Added: The Company requires its employees and applicable contractors to take yearly cyber training and its employees and applicable contractors are also required to sign confidentiality agreements for purposes including ensuring cybersecurity.
We and our MSP/MSSP have established an incident response plan to assist with responding to cybersecurity incidents.
The incident response plan includes our approach to identification, escalation, and restoration from incidents, such as engaging or informing third-party experts, law enforcement, and members of the Board of Directors, as appropriate.
−Removed: The Board of Directors is acutely aware of the critical nature of managing risks associated with cybersecurity threats.
−Removed: The Board has established robust oversight mechanisms to promote effective governance in managing risks associated with cybersecurity threats because Lightbridge recognizes the significance of these threats to our operational integrity and stakeholder confidence.
−Removed: Furthermore, significant cybersecurity matters such as significant cybersecurity incidents, and strategic risk management decisions are designed to be escalated to the Board of Directors, so that they have appropriate oversight and can provide guidance.
+Added: The Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats.
+Added: The Board has established oversight mechanisms to promote effective governance in managing risks associated with cybersecurity threats because Lightbridge recognizes the significance of these threats to our operational integrity and stakeholder confidence.
+Added: Furthermore, significant cybersecurity matters such as cybersecurity incidents that meet defined thresholds, and strategic risk management decisions are designed to be escalated to the Board of Directors, so that they have appropriate oversight and can provide guidance.
Board of Directors Oversight
1 unchanged sentence
The Audit Committee is composed of board members with diverse expertise including risk management, technology, and finance that helps equip them to oversee cybersecurity risks effectively.
−Removed: The Audit Committee conducts an annual review of the company’s cybersecurity posture and the effectiveness of its risk management strategies.
−Removed: This review helps in identifying areas for improvement and aligning cybersecurity efforts with the overall risk management framework.
+Added: The Audit Committee at least annually reviews information regarding the company’s cybersecurity posture and the effectiveness of its risk management strategies.
+Added: This review helps with oversight of areas for improvement and aligning cybersecurity efforts with the overall risk management framework.
The CFO reports to the Audit Committee regarding cybersecurity risks and provides a comprehensive briefing to the Audit Committee on a regular basis as needed, with a minimum frequency of once per year.
−Removed: The CFO also maintains an ongoing dialogue with the Audit Committee regarding emerging or potential cybersecurity risks and cybersecurity incidents.
−Removed: The Audit Committee evaluates the materiality of cybersecurity incidents to determine if they require disclosure, such as an 8-K filing.
+Added: The CFO also maintains an ongoing dialogue with the Audit Committee regarding potential cybersecurity risks and cybersecurity incidents.
+Added: The vCIO is also available to address the Audit Committee, if requested.
+Added: If applicable, the Audit Committee has a process to evaluate the materiality of cybersecurity incidents to determine if the incident may require disclosure, such as a Form 8-K filing.
This includes assessing the potential impact of cybersecurity risks or incidents on the company’s financial position, operations, and reputation.
Risks from Cybersecurity Threats
−Removed: As of the date of this report, while we are not aware of any material risks from cybersecurity threats, including cybersecurity incident, that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial condition, there can be no guarantee that there will not be a future cybersecurity incident that will have a material impact.
+Added: As of the date of this Annual Report on Form 10-K, during the past three years, we have not experienced any cybersecurity incidents that have resulted in material disruption to operations, loss of data, or financial impact.
+Added: There can be no guarantee that there will not be a future cybersecurity incident that will have a material impact.
In the event of a cybersecurity incident, our insurance coverage may be inadequate to compensate us for any related losses we incur and, in some cases, our insurance coverage may not cover the cybersecurity incident at all.
−Removed: Additional information on cybersecurity risks we face can be found in Part I, Item 1A.
−Removed: Risk Factors – “We are exposed to risks related to cybersecurity and protection of confidential information” of this Annual Report on Form 10-K.
+Added: Additional information on cybersecurity risks we face can be found in Part I.
+Added: Risk Factors —”Risks Related to Our Business and to the Commercialization of Lightbridge Fuel™—The occurrence of cybersecurity incidents, or a deficiency in our cybersecurity or the cybersecurity of our service providers, could negatively impact our business by causing disruptions to our operations, a compromise or corruption of our confidential information, regulatory enforcement and other legal proceedings, and/or damage to our business, all of which could negatively impact our financial results” of this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.