3 unchanged sentences
The Company’s business is highly dependent on the communications and information systems of our Manager, its affiliates and third-party service providers.
−Removed: Our Manager is an affiliate of TPG Inc.
−Removed: (“TPG”), a leading global alternative asset management firm.
+Added: Our Manager is an affiliate of TPG, a leading global alternative asset management firm.
We, in conjunction with our Manager and its affiliates, have adopted processes designed to identify, assess and manage material risks from cybersecurity threats.
−Removed: These processes include responses to and assessments of internal and external threats to the security, confidentiality, integrity and availability of the Company’s data and systems along with other material risks to its operations, at least annually or whenever there are material changes to our systems or operations.
−Removed: As part of the risk management process, TPG engages outside providers to conduct periodic internal and external penetration testing.
−Removed: TPG has informed us that it uses NIST Cybersecurity Framework and CIS Critical Security Controls as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: This does not imply that TPG, its affiliates or we meet any particular technical standards, specifications, or requirements.
−Removed: TPG stores data, including the Company's data, in cloud environments with security that we believe is appropriate for the data involved and has adopted controls around, among other things, vendor risk assessment, access and acceptable use and backup and recovery.
−Removed: The Company utilizes certain third-party service providers to perform a variety of functions in the operation of its business.
−Removed: TPG has processes to oversee and identify material risks associated with the use of third-party service providers, taking into account the nature of the services provided, the sensitivity and quantity of information processed, and the identity of the service provider.
+Added: These processes include assessments of internal and external threats to the confidentiality, integrity and availability of the Company’s data and systems along with other material risks to its operations.
+Added: These risk assessments inform our cybersecurity program and the continued development of a layered set of controls aimed at preventing, detecting, and responding to threats.
+Added: TPG’s administrative, organizational, technical and physical security controls include, but are not limited to, policies and procedures, system hardening vulnerability scanning, and patching, employee training and awareness, third-party risk management processes, backup and recovery processes, access controls, data encryption in transit and at rest, network perimeter controls, and identity verification.
+Added: TPG also has policies and controls in place designed to detect and respond to cybersecurity events, including an incident response plan, an incident response team with dedicated roles and responsibilities for assessing and responding to a cybersecurity event, system logging and ongoing monitoring, and periodic training exercises simulating cybersecurity events that are designed to raise awareness and test the team’s response readiness capabilities.
+Added: T he nature, scope and effectiveness of these controls are regularly reviewed through a series of internal and external processes.
+Added: TPG’s cybersecurity team itself performs both automated monitoring on a continuous basis and manual reviews of key controls.
+Added: TPG has informed us that it also conducts annual assessments of our cybersecurity program using industry standard cybersecurity frameworks, such as the NIST Cybersecurity Framework, as benchmarks to perform its evaluation.
+Added: This does not imply that TPG, its affiliates or we fully meet any particular industry standards, specifications, or requirements.
+Added: In addition, independent reviews of our cybersecurity control effectiveness are conducted by TPG’s internal audit team on a periodic basis.
+Added: We also engage external providers to conduct periodic external assessments , including penetration testing.
As of the date of this report, we are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, which have materially affected or are reasonably likely to materially affect our Company, including our business strategy, results of operations, or financial condition.
5 unchanged sentences
The Board regularly engages in discussions with management regarding the Company's risk assessment and risk management policies.
−Removed: In addition, the Audit Committee of our Board of Directors (the “Audit Committee”) oversees the
−Removed: management of systemic risks, including cybersecurity, in accordance with its charter.
−Removed: The Audit Committee engages in regular discussions with management regarding the Company’s significant financial risk exposures and the measures implemented to monitor and control these risks.
+Added: In addition, the Audit Committee of our Board of Directors (the “Audit Committee”) oversees the management of systemic risks, including cybersecurity, in accordance with its charter.
+Added: The Audit Committee engages in regular
+Added: discussions with management regarding the Company’s significant financial risk exposures and the measures implemented to monitor and control these risks.
Our Board of Directors, including the Audit Committee, is briefed on our Manager’s information security program and cybersecurity risks at least once each year and as needed in connection with any potentially material cybersecurity incidents.
4 unchanged sentences
the ERC includes representatives from relevant functions and is led by TPG’s Chief Executive Officer.
−Removed: TPG has also established an Operational Risk Committee (“ORC”) responsible for applying the policy decisions of the ERC.
−Removed: Operational responsibility for ensuring the adequacy and effectiveness of our Manager's risk management, control and governance processes is assigned to TPG’s Chief Information Security Officer, who periodically reports, among others, potentially material cybersecurity incidents to the ORC and, in coordination with the Chief Information Officer and Head of Operations, reports to the ERC at least annually.
−Removed: The Chief Information Security Officer leads TPG’s cybersecurity team, which includes individuals dedicated to incident detection and response.
−Removed: This team is responsible for identifying threats that can impact the organization, including the Company, and designing controls to mitigate vulnerabilities before they are exploited and to detect and neutralize any threats that do materialize.
−Removed: The Chief Information Security Officer and Chief Information Officer each have more than 20 years of experience in their fields.
−Removed: The Chief Information Security Officer and senior members of the cybersecurity team hold industry standard certifications.
+Added: TPG has also established an Operational Risk Committee (“ORC”) which is responsible for applying the policy decisions of the ERC.
+Added: Operational responsibility for ensuring the adequacy and effectiveness of our Manager's risk management, control and governance processes is assigned to TPG’s Chief Information Security Officer ("CISO"), who periodically reports, among other things, potentially material cybersecurity incidents to the ORC and reports to the ERC at least annually.
+Added: TPG's cybersecurity team also regularly coordinates with other key stakeholders within the organization, including compliance, human resources, internal audit and legal.
+Added: The CISO leads TPG’s cybersecurity team, which is responsible for implementing, maintaining and enforcing our cybersecurity program.
+Added: TPG's CISO previously held various leadership roles within the Technology Risk department of one of the world's largest banking institutions over a 17-year period.
+Added: TPG has informed us that the CISO holds a Bachelor of Science in Electrical Engineering and Mathematics from the University of Texas at Arlington and is a Certified Information Systems Security Professional (CISSP).
+Added: TPG's cybersecurity team possesses a variety of cybersecurity skill sets and extensive expertise obtained through decades of experience, numerous industry certifications, and advanced degrees.
+Added: TPG's cybersecurity team continues to take steps to maintain up-to-date knowledge of evolving cybersecurity threats and countermeasures.
As of December 31, 2024, we did not own any real estate or other physical property materially important to our operations.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.