1 unchanged sentence
Not applicable.
+Added: Table of Cont ents
Cybersecurity
2 unchanged sentences
To protect the company’s information systems from cybersecurity threats, the company uses various security tools that help the company identify, escalate, investigate, resolve, and recover from security incidents in a timely manner.
−Removed: These efforts include but are not limited to, internal reporting, engaging third-party service providers to actively monitor information systems, performing vulnerability testing using external third-party tools and techniques to test security controls, conducting employee training, monitoring emerging trends and regulations related to information security, and implementing appropriate changes, as needed, to our cybersecurity risk management program.
+Added: These efforts include but are not limited to, internal reporting, engaging third-party service providers to actively monitor information systems, performing vulnerability testing using external third-party tools and techniques to test security controls, conducting employee training, monitoring emerging trends and regulations related to cybersecurity, and implementing appropriate changes, as needed, to our cybersecurity risk management program.
The company partners with third parties to assess the effectiveness of our cybersecurity prevention and response systems and processes.
9 unchanged sentences
The company has systems in place designed to securely receive and store that information and to detect, contain, and respond to data security incidents.
−Removed: The company has a robust information security training and compliance program for all new and existing employees.
+Added: The company has a robust cybersecurity training and compliance program for all new and existing employees.
Training is provided at least annually, with a formal communication cadence of additional components of training being provided throughout the year.
Employee cybersecurity proficiency is assessed quarterly, with supplementary training programs tailored to individual needs based on these evaluations.
−Removed: The company has not experienced a material cybersecurity or information security breach in the last three years.
−Removed: The company maintains a program, run by the company’s Vice President of Global Information Technology and Information Security, overseen by the company’s Chief Financial Officer, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information owned by or in the care of the company.
−Removed: The company has implemented a cybersecurity incident response plan that provides controls and procedures to facilitate timely and accurate reporting of any material cybersecurity incident.
+Added: The company has not experienced a material cybersecurity breach in the last three years.
+Added: The company maintains a program, run by the company’s Vice President of Global Information Technology and Cybersecurity, overseen by the company’s Chief Financial Officer, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information owned by or in the care of the company.
+Added: The company maintains a cybersecurity incident response plan that provides controls and procedures to facilitate timely and accurate reporting of any material cybersecurity incident.
The initial impact of each cybersecurity event is evaluated by a designated cybersecurity team using established risk criteria.
−Removed: If a cybersecurity event meets certain of these criteria, it is escalated to an internal cross-functional Cyber Incident Response Team and external incident responders.
+Added: If a cybersecurity event meets defined thresholds, it is escalated to an internal cross-functional Cyber Incident Response Team and external incident responders.
The company has a cyber incident disclosure committee that evaluates and considers whether public disclosure of an event is required.
The plan also contains procedures for escalating cybersecurity incidents to the Board of Directors.
−Removed: The company’s Vice President of Global Information Technology and Information Security is responsible for leading the assessment and management of cybersecurity risks.
−Removed: The current Vice President of Global Information Technology and Information Security has over 10 years of experience in information security and holds CISSP and GIAC credentials.
−Removed: The Vice President of Global Information Technology and Information Security reports to the Audit Committee and management on cybersecurity threats on a regular basis.
−Removed: Oversight responsibility for information security matters is shared by the Board (primarily through the Audit Committee) and senior management.
−Removed: The Audit Committee oversees the company’s cybersecurity and information security program and receives periodic updates from senior management on cybersecurity and information security matters.
−Removed: The Vice President of Global Information Technology and Information Security or key members of the executive leadership team update the Audit Committee periodically on the cybersecurity landscape, including the status of ongoing threats and company initiatives.
+Added: The company’s Vice President of Global Information Technology and Cybersecurity is responsible for leading the assessment and management of cybersecurity risks.
+Added: The current Vice President of Global Information Technology and Cybersecurity has over 10 years of experience in cybersecurity and holds CISSP and GIAC credentials.
+Added: The Vice President of Global Information Technology and Cybersecurity reports to the Audit Committee and management on cybersecurity threats on a regular basis.
+Added: Oversight responsibility for cybersecurity matters is shared by the Board (primarily through the Audit Committee) and senior management.
+Added: The Audit Committee oversees the company’s cybersecurity program and receives periodic updates from senior management on cybersecurity matters.
+Added: The Vice President of Global Information Technology and Cybersecurity or key members of the executive leadership team update the Audit Committee periodically on the cybersecurity landscape, including the status of ongoing threats and company initiatives.
+Added: Table of Cont ents
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.