3 unchanged sentences
We recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.
−Removed: Our Board of Directors has delegated its responsibility for oversight of cybersecurity risks to our Audit Committee.
−Removed: In accordance with its charter, our Audit Committee is responsible for governing management’s review and assessment of our cybersecurity and other information technology risks, controls and procedures.
−Removed: Management's Business Information Services team provides the Audit Committee with quarterly updates on our cybersecurity program, detailing our monitoring and mitigation efforts.
−Removed: Mesa’s Audit Committee has two members with prior work experience overseeing or assessing a cybersecurity function.
−Removed: The Audit Committee informs the full Board of pertinent cybersecurity matters regularly.
−Removed: We have established policies and procedures to keep management and the Audit Committee informed about security incidents that could significantly impact our business.
−Removed: Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience, and who in turn reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry.
−Removed: The Information Security Manager regularly meets with our Business Information Services team, and as applicable, appropriate executives and directors, to review our cybersecurity posture, the broader cybersecurity landscape, any identified cybersecurity incidents, our monitoring of cybersecurity risks through continuous mitigation efforts, and any anticipated enhancements to our policies, procedures and controls.
+Added: Our Board of Directors has delegated oversight of cybersecurity risks to our Audit Committee.
+Added: In accordance with its charter, our Audit Committee is responsible for overseeing management’s review and assessment of our cybersecurity and other information technology risks, controls and procedures.
+Added: Management's Business Information Services team provides the Audit Committee with quarterly updates on our cybersecurity program, including monitoring activities and mitigation efforts.
+Added: The Audit Committee has two members with prior work experience overseeing or assessing cybersecurity functions, and the Audit Committee informs the full Board of pertinent cybersecurity matters regularly.
+Added: We have established policies and procedures to keep management and the Audit Committee informed about cybersecurity incidents that could significantly impact our business.
+Added: Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience and reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry.
+Added: The Information Security Manager regularly meets with our Business Information Services team, and as appropriate, with other executives and directors to review our cybersecurity posture, developments in the cybersecurity landscape, any identified cybersecurity incidents, continuous risk mitigation activities, and any anticipated enhancements to our policies, procedures and controls.
Cybersecurity Risk Management and Strategy
Our cybersecurity program, guided by industry standards, encompasses processes for the identification, assessment, and management of cybersecurity risks.
−Removed: We carry out regular risk assessments, supported by external vendors, to evaluate our cybersecurity program, pinpoint areas for enhancement and devise strategies to mitigate cybersecurity risks.
−Removed: We perform ongoing security testing and have implemented a vulnerability management process to address identified security risks based on severity.
−Removed: An external vendor provides us with quarterly vulnerability scans, annual penetration tests, security tabletops, and an enterprise-wide annual security assessment to assess and validate our physical, technical, external, and administrative controls.
+Added: Cybersecurity risks are considered as part of our enterprise risk management processes and are evaluated alongside other operational and strategic risks.
+Added: We conduct regular risk assessments, supported by external vendors, to evaluate our cybersecurity program, identify areas for enhancement and develop strategies to mitigate cybersecurity risks.
+Added: Internally, we perform ongoing security testing and maintain a vulnerability management process to address identified security risks based on severity.
+Added: An external vendor provides us with periodic vulnerability scans, annual penetration tests, security tabletop exercises, and an enterprise-wide annual security assessment to evaluate and validate our physical, technical, external, and administrative controls.
+Added: We rely on third parties to provide, host, or support certain information technology systems.
+Added: Cybersecurity considerations are incorporated into Mesa’s processes for selecting and onboarding third‑party vendors that access our information systems or data, and such vendors may be required to maintain information security measures appropriate to the nature of the services they provide.
+Added: However, we do not control the security practices of third parties, and their failure to maintain adequate security could adversely affect us.
Third parties that access, process, store or transmit our information or that have access to our systems may have and be subject to additional cybersecurity controls.
−Removed: We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness expectations, and event and incident management.
+Added: We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness, and incident management.
Consistent with our position that cybersecurity is the responsibility of every Mesa team member, we regularly educate and share best practices to raise awareness of cybersecurity threats.
−Removed: Every year, associates in applicable job categories are required to take information security and protection training, and we conduct ongoing simulated testing to educate employees on phishing.
+Added: Employees in applicable job categories are required to complete annual information security and data protection training, and we conduct ongoing simulated phishing exercises to reinforce awareness for all employees.
Our Information Security Manager and Business Information Services team oversee the day-to-day prevention, detection, mitigation, and resolution of cybersecurity risks, utilizing third -party security software and services.
−Removed: We also deploy processes and technologies to monitor security alerts from both internal and external sources, including information security research.
−Removed: In case of a confirmed security incident, we have a full incident response plan that includes engaging an incident handling team, guidance for determining materiality, and steps to respond, remediate, and recover from the security incident.
−Removed: To date, risks from cybersecurity threats have not materially affected our business strategy, results of operations or financial condition.
−Removed: We can provide no assurance that there will not be cybersecurity incidents in the future or that such incidents will not materially affect us;
−Removed: however, based on available information as of the date of this annual report, we do not believe that such threats are reasonably likely to materially affect our business.
+Added: We deploy processes and technologies to monitor security alerts from both internal and external sources, including information security research.
+Added: In the event of a confirmed security incident, we maintain a full incident response plan that includes engaging an incident handling team, guidance for determining materiality, and steps to respond to, remediate, and recover from the security incident.
We maintain a cybersecurity insurance policy and a retainer for third -party incident response services, which may mitigate certain financial impacts of a cybersecurity incident, should one occur.
+Added: To date, risks from cybersecurity threats have not materially affected our business, results of operations or financial condition.
+Added: We can provide no assurance that cybersecurity incidents will not occur in the future or that such incidents will not materially affect us.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.