7 unchanged sentences
Mesa’s Audit Committee has two members with prior work experience overseeing or assessing a cybersecurity function.
−Removed: The Audit Committee briefs the full Board on cybersecurity matters regularly.
−Removed: We have established procedures to keep management and the Audit Committee informed about security incidents that could significantly impact the business.
−Removed: Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience, who in turn reports to our Vice President of Information Services, who has over 25 years of experience in the industry.
−Removed: The Information Security Manager regularly meets with our Business Information Services team, and as applicable, appropriate executive and Board of Directors personnel, to review our cybersecurity posture, the broader cybersecurity landscape, any identified cybersecurity incidents, our monitoring of cybersecurity risks through continuous mitigation efforts, and any anticipated enhancements to our policies, procedures and controls.
+Added: The Audit Committee informs the full Board of pertinent cybersecurity matters regularly.
+Added: We have established policies and procedures to keep management and the Audit Committee informed about security incidents that could significantly impact our business.
+Added: Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience, and who in turn reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry.
+Added: The Information Security Manager regularly meets with our Business Information Services team, and as applicable, appropriate executives and directors, to review our cybersecurity posture, the broader cybersecurity landscape, any identified cybersecurity incidents, our monitoring of cybersecurity risks through continuous mitigation efforts, and any anticipated enhancements to our policies, procedures and controls.
Cybersecurity Risk Management and Strategy
4 unchanged sentences
Third parties that access, process, store or transmit our information or that have access to our systems may have and be subject to additional cybersecurity controls.
−Removed: We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness and event and incident management.
+Added: We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness expectations, and event and incident management.
Consistent with our position that cybersecurity is the responsibility of every Mesa team member, we regularly educate and share best practices to raise awareness of cybersecurity threats.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.