18 unchanged sentences
Our cybersecurity risk management program includes:
−Removed: · risk assessments designed to help identify material cybersecurity risks to
−Removed: our critical systems, information, products, services and our broader IT environment;
−Removed: · evaluations of our readiness to assess, respond and, as applicable, recover
−Removed: from potential cybersecurity incidents;
−Removed: · periodic tabletop exercises to simulate a response to a cybersecurity incident
−Removed: and use the findings to improve our processes, technologies and incident response plan;
−Removed: · the use of external service providers, where appropriate, to assess, test,
−Removed: or otherwise assist with the aspects of our security controls;
−Removed: · cybersecurity training to educate our employees, consultants and other users
−Removed: about their individual responsibilities regarding our IT systems and data;
+Added: risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services and our broader IT environment;
+Added: evaluations of our readiness to assess, respond and, as applicable, recover from potential cybersecurity incidents;
+Added: periodic tabletop exercises to simulate a response to a cybersecurity incident and use the findings to improve our processes, technologies and incident response plan;
+Added: the use of external service providers, where appropriate, to assess, test, or otherwise assist with the aspects of our security controls;
+Added: cybersecurity training to educate our employees, consultants and other users about their individual responsibilities regarding our IT systems and data;
weekly briefings on cybersecurity incidents, threats, and related matters;
−Removed: · a third-party risk management process for service providers, suppliers and
−Removed: vendors who have access to our critical systems and information;
−Removed: · cybersecurity risk insurance that provides protection against certain potential
−Removed: costs and losses arising from a cybersecurity incident.
+Added: a third-party risk management process for service providers, suppliers and vendors who have access to our critical systems and information;
+Added: cybersecurity risk insurance that provides protection against certain potential costs and losses arising from a cybersecurity incident.
As of the date of this report, we do not believe that known risks from
12 unchanged sentences
cybersecurity incidents, as well as any incidents with lesser impact potential.
−Removed: While the Board reviews and oversees the Company’s information
−Removed: security efforts, our executive officers, including our Chief Financial Officer, Vice President of Business Operations, and Vice President
−Removed: of Business Affairs are responsible for the day-to-day management of cybersecurity risk and the design and implementation of policies,
−Removed: processes and procedures to identify and mitigate this risk.
−Removed: Our Director of IT, in coordination with the executive officers named above,
−Removed: is responsible for assessing and managing material risks from cybersecurity threats, as well as managing and responding to material cybersecurity
−Removed: incidents if any occur.
−Removed: Our Director of IT has over 27 years of experience in various information technology roles, which includes over
−Removed: 10 years of management of cybersecurity matters.
−Removed: Our Director of IT provides weekly briefings to the Chief Financial
−Removed: Officer, Vice President of Business Operations, Vice President of Business Affairs and other members of our cross-functional incident
−Removed: response team.
−Removed: The weekly briefings are focused on our cybersecurity risks and activities, including cybersecurity incidents and responses,
−Removed: cybersecurity systems testing, third-party activities and related topics.
−Removed: In the event threats and incidents are identified as potentially
−Removed: significant, the Chief Financial Officer, Vice President of Business Operations or Vice President of Business Affairs will promptly report
−Removed: to our Board.
+Added: While the Board reviews and oversees the Company’s information security
+Added: efforts, our Director of IT, under the oversight of our executive officers, is responsible for the day-to-day management of cybersecurity
+Added: risk and the design and implementation of policies, processes and procedures to identify and mitigate this risk.
+Added: Our Director of IT, in
+Added: coordination with the executive officers, is responsible for assessing and managing material risks from cybersecurity threats, as well
+Added: as managing and responding to material cybersecurity incidents if any occur.
+Added: Our Director of IT has over 28 years of experience in various
+Added: information technology roles, which includes over 10 years of management of cybersecurity matters.
+Added: Our Director of IT provides weekly briefings to the Chief Financial Officer,
+Added: General Counsel and other members of our cross-functional incident response team.
+Added: The weekly briefings are focused on our cybersecurity
+Added: risks and activities, including cybersecurity incidents and responses, cybersecurity systems testing, third-party activities and related
+Added: In the event that threats and incidents are identified as potentially significant, the Chief Financial Officer and General Counsel
+Added: promptly report to our Board.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.