6 unchanged sentences
The Company conducts security assessments of certain third-party providers before engagement and has established monitoring procedures in its effort to mitigate risks related to data breaches or other security incidents originating from third parties.
−Removed: The Company from time to time engages third-party consultants, legal advisors, and audit firms in evaluating and testing the Company’s risk management systems and assessing and remediating certain potential cybersecurity incidents as appropriate.
+Added: The Company from time to time engages third-party consultants, legal advisors, and audit firms in evaluating and testing the Company’s risk management systems and assessing and remediating certain cybersecurity incidents.
+Added: The Company also continues to provide its employees with cybersecurity and data protection training to support its risk mitigation efforts.
Board of Directors
6 unchanged sentences
The CISO has over 25 years of experience in information security, risk management, and compliance, has served as the chief information security officer at other organizations and, among other things, is a certified information systems security professional .
−Removed: The CIDO and CISO are also supported by a Cybersecurity & Privacy Executive Oversight Committee, which is comprised of certain members of senior management and is intended to provide cross-functional support for cybersecurity risk management and facilitate the response to any cybersecurity incidents.
+Added: The CIDO and CISO are also supported by a Cybersecurity & Privacy Executive Oversight Committee, which is comprised of certain members of senior management and is provides cross-functional support for cybersecurity risk management and facilitates the response to any cybersecurity incidents.
The Company’s CISO oversees the Company’s cybersecurity incident response plan and related processes that are designed to assess and manage material risks from cybersecurity threats.
5 unchanged sentences
The Company’s CISO, or a delegate, informs the Disclosure Committee’s Cybersecurity Subcommittee of certain cybersecurity incidents that may potentially be determined to be material pursuant to escalation criteria set forth in the Company’s incident response plan and related processes.
−Removed: The Disclosure Committee’s Cybersecurity Subcommittee is also primarily responsible for advising the Disclosure Committee and the Company’s Chief Executive Officer and Chief Financial Officer regarding cybersecurity disclosures in public filings.
+Added: The Disclosure Committee’s Cybersecurity Subcommittee is also responsible for advising the Disclosure Committee and the Company’s Chief Executive Officer and Chief Financial Officer regarding cybersecurity disclosures in public filings.
The CISO, with the CLO in attendance, also notifies the audit committee chair of any material cybersecurity incident.
As of the date of this Form 10-K, the Company is not aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition and that are required to be reported in this Form 10-K.
−Removed: For further discussion of the risks associated with cybersecurity incidents, see the cybersecurity risk factor beginning on page 14 of the section entitled “Item 1A.
+Added: For further discussion of the risks associated with cybersecurity incidents, see the cybersecurity risk factor in the section entitled “Item 1A.
Risk Factors” in this Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.