1 unchanged sentence
CYBERSECURITY
−Removed: maintains a cybersecurity program that aims to protect the confidentiality, integrity, and availability of data required by our business
−Removed: to be stored, analyzed, transported, and/or processed.
−Removed: We have implemented various internal and external controls and processes, including
−Removed: internal risk assessment and policy implementation, to incorporate a risk-based cybersecurity framework to monitor and mitigate security
−Removed: threats and other strategies to increase security for our information, facilities, and infrastructure.
+Added: maintains a risk-based cybersecurity program designed to protect the confidentiality, integrity, and availability of information systems
+Added: and data used in our operations.
+Added: The program includes technical, administrative, and organizational safeguards intended to identify,
+Added: assess, and mitigate cybersecurity risks.
Management and Strategy.
−Removed: Mexco recognizes the risk that cybersecurity threats pose to our operations, and cybersecurity is an
−Removed: important component of our overall risk management strategy.
−Removed: Mexco’s cybersecurity team consists of our executive officers and
−Removed: third-party cybersecurity personnel.
−Removed: The third-party cybersecurity team, led by professionals with cybersecurity expertise across multiple
−Removed: industries, takes a cross-functional approach to addressing these risks and engages in discussions with our executive management team
−Removed: on an as-needed basis.
−Removed: have implemented a monitoring and detection system to help promptly identify cybersecurity incidents.
−Removed: We also require our employees to
−Removed: receive annual cybersecurity awareness training.
−Removed: We perform cybersecurity tabletop exercises to test the effectiveness of our incidence
−Removed: response plan (“IRP”) and implement post-incident “lessons learned” to enhance our response.
−Removed: We provide our system
−Removed: users with access consistent with the principle of least privilege, which requires that such users be given no more access than necessary
−Removed: to complete their job functions.
−Removed: We have programs in place to monitor our retained data with the goal of identifying personal identifiable
−Removed: information and taking appropriate actions to secure the data.
−Removed: have an IRP that delineates the procedures to be followed for handling a variety of cybersecurity incidents;
−Removed: categorizes potential cybersecurity
−Removed: incidents and the required timeframe for reporting each;
−Removed: establishes cybersecurity incident response levels;
−Removed: provides for investigations
−Removed: designed to help us to meet applicable legal obligations, including possible notification requirements;
−Removed: and outlines the roles and responsibilities
−Removed: for various personnel in the event of a cybersecurity incident.
−Removed: The Board, in coordination with the Audit Committee and Chief Financial Officer, is responsible for the oversight of risks from
−Removed: cybersecurity threats.
−Removed: The responsibilities of the Audit Committee include overseeing policies and management systems for cybersecurity
−Removed: matters and reviewing Mexco’s strategy, objectives, and policies relative to cybersecurity.
−Removed: In addition, the Board and the Audit
−Removed: Committee receive regular presentations and reports on cybersecurity risks that address a range of topics, including developments, technological
−Removed: trends or tools, third party updates, and regulatory standards.
−Removed: Our IRP calls for prompt and timely direct notifications and updates
−Removed: to the Board (or its committees) as necessary in connection with cybersecurity incidents deemed to have a moderate or higher business
−Removed: impact, even if immaterial.
−Removed: On a periodic basis, the Board and the Audit Committee discuss our approach to cybersecurity with our executive
−Removed: officers and cybersecurity personnel.
−Removed: plays a role in assessing and managing our material risks from cybersecurity threats through membership on our cybersecurity team, as
−Removed: well as by making final materiality determinations and disclosures and other compliance decisions, as reflected in our IRP.
+Added: Cybersecurity risk is integrated into our overall risk management processes.
+Added: We use internal policies
+Added: and controls, supported by third-party cybersecurity professionals, to monitor and respond to cybersecurity threats.
+Added: We maintain systems
+Added: to detect and respond to potential cybersecurity incidents.
+Added: receive periodic cybersecurity awareness training.
+Added: We implement access controls based on the principle of least privilege.
+Added: We also conduct
+Added: periodic testing of our incident response capabilities, including tabletop exercises, and maintain an incident response plan that outlines
+Added: procedures for identifying, escalating, investigating, and responding to cybersecurity incidents.
+Added: The Board of Directors, through the Audit Committee, oversees cybersecurity risk.
+Added: Management is responsible for implementing
+Added: and maintaining cybersecurity controls and for day-to-day risk management activities.
+Added: The Board and Audit Committee receive periodic
+Added: updates on cybersecurity risks and are notified of material cybersecurity incidents in accordance with our incident response processes.
of Risks from Cybersecurity Threats.
−Removed: As of the date of this Report, we are not aware of any previous cybersecurity threats that
−Removed: have materially affected, or are reasonably likely to materially affect, the Company, including our business strategy, results of operations
−Removed: or financial condition.
−Removed: Notwithstanding the approach we take to cybersecurity, we may not be successful in preventing or mitigating a
−Removed: cybersecurity incident that could have a material adverse effect on us.
+Added: As of the date of this report, we are not aware of any cybersecurity threats that have materially
+Added: affected, or are reasonably likely to materially affect, the Company’s business, financial condition, or results of operations.
+Added: However, we may not be able to prevent all cybersecurity incidents, and future incidents could have a material adverse effect on the
more information on our cybersecurity-related risks, see “Item 1A.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.