2 unchanged sentences
Risk management and strategy:
−Removed: Matson’s information security, Internal Audit and risk management teams help to identify and assess cyber and information security threats and vulnerabilities, and establish the appropriate business systems, preventive controls and risk mitigation strategies.
+Added: Matson’s information security, internal audit, business continuity and risk management teams help to identify and assess cyber and information security threats and vulnerabilities, and establish the appropriate business systems, preventive controls and risk mitigation strategies .
The main objectives of Matson’s approach to cyber and information security are to protect confidential information while maintaining data integrity and availability;
11 unchanged sentences
The Board also consults with outside advisors and experts, when appropriate, to anticipate future threats and trends, and their impact on the Company’s risk environment.
−Removed: In addition, the Company utilizes annual third-party audits to test its cybersecurity systems and incident response and remediation plans to help spot vulnerabilities and improve its ability to respond to unexpected events.
+Added: In addition, the Company utilizes third-party audits to test its cybersecurity systems, incident response and remediation plans to help spot vulnerabilities and improve its ability to respond to unexpected events.
For more information on Matson’s ERM program, see “— Governance ” below.
2 unchanged sentences
Additionally, the Company leverages independent, third-party services to monitor the cyber and information security posture of key suppliers and vendors.
−Removed: The Company’s Chief Executive Officer and Chief Financial Officer are briefed on a quarterly basis on the results of these reviews.
+Added: The Company’s quarterly information security update to the Chief Executive Officer and Chief Financial Officer includes an update on the results of these reviews.
Training, education and awareness-building are mechanisms Matson uses to help embed a strong culture of cyber and information security within its workplace.
3 unchanged sentences
The Company also has specific escalation processes and resources in place for employees to raise a concern should they notice anything suspicious.
−Removed: The design of Matson’s vessel and office information technology systems is informed in part by the following third-party frameworks or standards:
+Added: The design of Matson’s information technology systems is informed in part by the following third-party frameworks or standards:
● NIST Cybersecurity Framework
● NIST 800-171
+Added: ● NIST 800-82
● DFARS 252.204-7012
9 unchanged sentences
● Maritime Transportation System Information Sharing and Analysis Center (“MTS-ISAC”)
−Removed: In the last fiscal year, Matson has not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected the Company, but the Company faces certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect the Company.
+Added: Since the beginning of the last fiscal year, Matson has not identified risks from known cybersecurity threats , including as a result of any prior cybersecurity incidents, that have materially affected the Company, but the Company faces certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect the Company.
For more information on the risks and impacts of these matters to Matson, see Part I, Item 1A.
Risk Factors – “ The Company’s information technology systems have in the past and may in the future be exposed to cybersecurity risks and other disruptions that could impair the Company’s ability to operate and adversely affect its business.
−Removed: Matson’s Board of Directors has oversight of the Company’s risk management process, which includes overseeing our process for identifying, assessing and mitigating significant financial, operational, legal, strategic, and other risks that may affect the Company.
+Added: The Board has oversight of the Company’s risk management process, which includes overseeing our process for identifying, assessing and mitigating significant financial, operational, legal, strategic, and other risks that may affect the Company.
These risks include, among other things, risks related to cybersecurity and information security.
2 unchanged sentences
The Audit Committee is responsible for overseeing and reviewing cyber and information security risks, policies and programs and reviews the Company’s risk assessment, risk management and compliance policies twice a year.
−Removed: Senior leaders, including Matson’s Chief Information Officer, review the Company’s cybersecurity program with the Board of Directors at least annually, and the Chief Information Officer meets with the Audit Committee at least twice per year.
−Removed: Matson’s information security efforts are led by its Chief Information Officer, who has over 25 years of experience in enterprise software development, infrastructure and management, including over 17 years with Matson and 7 years at Charles Schwab as Senior Manager of Middleware Security, and Senior Director, Information Security, who is a Certified Information Systems Security Professional, Certified Information Systems Auditor, and is AWS Certified.
−Removed: The Chief Information Officer and Senior Director provide regular briefings to the Chief Executive Officer, the Chief Financial Officer, the Board of Directors, and the Audit Committee.
+Added: Senior leaders, including Matson’s Chief Information Officer, review the Company’s cybersecurity program with the Board at least annually, and the Chief Information Officer meets with the Audit Committee at least twice per year.
+Added: Matson’s information security efforts are led by its Chief Information Officer , who has over 25 years of experience in enterprise software development, infrastructure and management, including over 18 years with Matson and 7 years at Charles Schwab as Senior Manager of Middleware Security, and the Chief Information Security Officer , who is a Certified Information Systems Security Professional, Certified Information Systems Auditor, and is AWS Certified.
+Added: The Chief Information Officer and the Chief Information Security Officer provide regular briefings to the Chief Executive Officer, the Chief Financial Officer, the Board, and the Audit Committee.
In addition, the Corporate Compliance Committee, comprised of business unit leaders, helps oversee cybersecurity initiatives and reports twice per year to the Audit Committee.
1 unchanged sentence
The Audit Committee also oversees Matson’s ERM program, which includes cyber and information security risks.
−Removed: The ERM process, which follows the Committee of Sponsoring Organization Framework, is designed to promote visibility to the Board and management of critical risks and risk mitigation strategies across various time frames, including the
−Removed: short-, medium- and long- term.
+Added: The ERM process, which follows the Committee of Sponsoring Organization Framework, is designed to promote visibility to the Board and management of critical risks and risk mitigation strategies across various time frames, including the short-, medium- and long- term.
Risk mitigation efforts are integrated into strategic plans and budgets.
−Removed: The Chief Financial Officer and Head of Internal Audit review the Company’s risk management activities with the Audit Committee and the Board on a regular basis.
+Added: The Chief Financial Officer and the head of internal a udit review the Company’s risk management activities with the Audit Committee and the Board on a regular basis.
Management also regularly updates the full Board at and between Board meetings on the ERM program and other risk-related matters.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.