7 unchanged sentences
During this process, the following factors, among others, are considered:
−Removed: likelihood and severity of
−Removed: risk, impact on the Company and others if a risk materializes, feasibility and cost of controls, and impact of controls on operations and others.
+Added: likelihood and severity of risk, impact on the Company and others if a risk materializes, feasibility and cost of controls, and impact of controls on the Company's operations and others.
Specific controls that are used to some extent by the Company include endpoint threat detection and response (EDR), identity and access management (IAM), privileged access management (PAM), logging and monitoring involving the use of security information and event management (SIEM), multi-factor authentication (MFA), firewalls and intrusion detection and prevention, and vulnerability and patch management.
−Removed: Third-party security firms are used by the Company in different capacities to provide or operate some of these controls and technology systems.
+Added: We incorporate third-party expertise in various aspects of our cybersecurity program.
+Added: One or more third-party security firms are used by the Company in different capacities to provide or operate some of these controls and technology systems.
Third parties are also used to conduct assessments, such as vulnerability scans and penetration testing of the Company and its systems.
The Company uses a variety of processes to address cybersecurity threats related to the use of third-party technology and services.
−Removed: The Company has a written incident response plan ("IRP") and conducts tabletop exercises to enhance incident response preparedness.
−Removed: Business continuity and disaster recovery plans are used to prepare for the potential for a disruption in technology we rely on.
+Added: The Company has a written incident response plan ("IRP") and conducts annual tabletop exercises to enhance incident response preparedness.
+Added: Business continuity and disaster recovery plans are used to prepare for the potential for a disruption in the technology we rely on.
The Company is a member of an industry cybersecurity intelligence and risk sharing organization.
−Removed: Certain employees, including those with access to Company-provided e-mail accounts, undergo security awareness training when hired and annually.
+Added: Certain employees, including those with access to Company-provided e-mail accounts, undergo security awareness training when hired and at least annually thereafter.
The Company has an enterprise risk management committee comprised of key business and functional leaders to address enterprise risks, and cybersecurity is a risk category addressed by that group.
1 unchanged sentence
At least annually, the Company’s executive leadership reviews with the Board of Directors the major risks identified in the enterprise risk management process, as well as the steps identified to mitigate such risks.
−Removed: Each of the business and functional leaders responsible for the management of these identified risks also regularly discuss with the Board changes in assessment of these risks and mitigation plans.
+Added: Each of the business and functional leaders responsible for the management of these identified risks also regularly discusses with the Board changes in assessment of these risks and mitigation plans.
The Company (or third parties it relies on) may not be able to fully, continuously, and effectively implement security controls as intended.
13 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.