1 unchanged sentence
Cybersecurity.
−Removed: The Company’s cybersecurity measures are primarily focused on ensuring the security and protection of its information technology systems and data.
+Added: The Company’s cybersecurity measures are primarily focused on ensuring the security and protection of its IT systems and data.
The Company’s information security program is managed by a dedicated Chief Information Security Officer (CISO) , whose group is responsible for leading enterprise-wide cybersecurity risk management, strategy, policy, standards, architecture, and processes.
5 unchanged sentences
These reports include updates on the Company’s cybersecurity risks and threats, the status of projects intended to strengthen its information security systems, assessments of the information security program (including remediation, mitigation, and management of identified vulnerabilities), and the emerging threat landscape.
−Removed: The information security program is regularly evaluated by internal and external consultants and auditors
−Removed: Table of C o ntent s
−Removed: with the results of those reviews reported to senior management and the Audit Committee, which is comprised entirely of independent directors and has oversight responsibility for these risks.
+Added: The information security program is regularly evaluated by internal and external consultants and auditors with the results of those reviews reported to senior management and the Audit Committee, which is comprised entirely of independent directors and has oversight responsibility for these risks.
The Company’s information security group monitors the Company’s information systems to prevent, detect, mitigate, and remediate cybersecurity incidents.
1 unchanged sentence
The Company engages with key vendors, industry participants, and intelligence and law enforcement communities as part of its continuing efforts to obtain current threat intelligence, collaborate on security enhancements, and evaluate and improve the effectiveness of its information security program.
−Removed: As part of this program, the Company conducts periodic tabletop exercises to assess its cybersecurity incident response processes.
+Added: As part of this program, the Company conducts periodic tabletop and red-teaming exercises to assess its cybersecurity incident response processes and defenses.
The Company also maintains vendor management diligence and oversight processes to identify and monitor potential risks from cybersecurity threats attendant to its use of third-party service providers.
Additionally, the Company monitors cybersecurity threat intelligence received from key third-party service providers associated with the Company.
−Removed: In the event of a cybersecurity incident, the Company has a process in place whereby members of the security group will alert the CISO and the CISO will alert the appropriate levels of management, including an incident assessment team, as well as the legal and finance departments so that the materiality of any such event can be assessed in furtherance of fulfilling any reporting requirements.
+Added: In the event of a cybersecurity incident, the Company has a process in place whereby members of the information security group will alert the CISO and the CISO will alert the appropriate levels of management, including an incident assessment team, as well as the legal and finance departments so that the materiality of any such event can be assessed in furtherance of fulfilling any reporting requirements.
If warranted, senior management will notify the Audit Committee or the full Board, as appropriate.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.