21 unchanged sentences
The company has not experienced a material cybersecurity or information security breach in the last three years.
−Removed: The company maintains a program, run by the company’s Director of Information Technology, overseen by the company’s Chief Financial Officer, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information owned by or in the care of the company.
+Added: The company maintains a program, run by the company’s Vice President of Global Information Technology and Information Security, overseen by the company’s Chief Financial Officer, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information owned by or in the care of the company.
The company has implemented a cybersecurity incident response plan that provides controls and procedures to facilitate timely and accurate reporting of any material cybersecurity incident.
3 unchanged sentences
The plan also contains procedures for escalating cybersecurity incidents to the Board of Directors.
−Removed: The company’s Director of Global Information Technology is responsible for leading the assessment and management of cybersecurity risks.
−Removed: The current Director of Global Information Technology has over 10 years of experience in information security and holds CISSP and GIAC credentials.
−Removed: The Director of Global Information Technology reports to the Audit Committee and management on cybersecurity threats on a regular basis.
+Added: The company’s Vice President of Global Information Technology and Information Security is responsible for leading the assessment and management of cybersecurity risks.
+Added: The current Vice President of Global Information Technology and Information Security has over 10 years of experience in information security and holds CISSP and GIAC credentials.
+Added: The Vice President of Global Information Technology and Information Security reports to the Audit Committee and management on cybersecurity threats on a regular basis.
Oversight responsibility for information security matters is shared by the Board (primarily through the Audit Committee) and senior management.
The Audit Committee oversees the company’s cybersecurity and information security program and receives periodic updates from senior management on cybersecurity and information security matters.
−Removed: The Director of Global Information Technology or key members of the executive leadership team update the Audit Committee periodically on the cybersecurity landscape, including the status of ongoing threats and company initiatives.
+Added: The Vice President of Global Information Technology and Information Security or key members of the executive leadership team update the Audit Committee periodically on the cybersecurity landscape, including the status of ongoing threats and company initiatives.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.