4 unchanged sentences
Accordingly, we have implemented and maintain various information security processes designed to identify, assess, and manage material risks from cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, and data related to our customers and employees (“Information Systems and Data”).
+Added: We maintain a risk-based cybersecurity program that is designed to align with industry-recognized frameworks and standards, including elements of the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.
+Added: Our cybersecurity program includes policies and procedures designed to assess, identify, and manage material risks from cybersecurity threats, including controls relating to access management, network security, encryption, vulnerability management, incident detection and response, business continuity, and disaster recovery.
We have a cybersecurity leadership team comprised of our Chief Information Security Officer ("CISO"), our Global Head of Infrastructure, and other senior leaders on our Information Technology group (“ Cybersecurity Leadership Team ”).
1 unchanged sentence
Our Cybersecurity Leadership Team identifies and assesses risks from cybersecurity threats by monitoring and evaluating our threat environment and our risk profile using various methods, including automated and manual tools, third-party threat feeds, internal audits, access control assessments, and evaluating threats reported to us by various third-party enterprise threat reporting services.
−Removed: The members of our Cybersecurity Leadership Team, including our CISO, have significant experience in managing and leading cybersecurity teams and in developing and implementing cybersecurity and data privacy systems and processes.
+Added: The members of our Cybersecurity Leadership Team, including our CISO, have experience in information
+Added: security, infrastructure management, and cybersecurity risk management, including experience developing and implementing security programs, managing incident response, and overseeing data protection initiatives.
+Added: We maintain a formal cybersecurity incident response plan that sets forth procedures for identifying, escalating, investigating, containing, mitigating, and remediating cybersecurity incidents.
+Added: The incident response process includes defined escalation protocols to senior management, including our Chief Financial Officer and General Counsel, as appropriate, to assess the potential materiality of an incident and determine disclosure obligations under applicable securities laws.
+Added: Where appropriate, incidents are escalated to the Audit Committee of the Board of Directors.
Depending on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards, and policies designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data.
+Added: We also maintain business continuity and disaster recovery plans designed to support the resiliency of our critical Information Systems and Data, including backup and recovery procedures and periodic testing of recovery capabilities.
Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes.
For example, cybersecurity risks are considered a part of our overall business strategy, financial planning, and capital allocation.
−Removed: We use third-party service providers to assist us from time to time in identifying, assessing, and managing material risks from cybersecurity threats.
−Removed: Our Cybersecurity Leadership Team inventories and prioritizes information security risks
−Removed: and evaluates material risks from cybersecurity threats, and reports those periodically to the Audit Committee of our Board of Directors , which evaluates our overall enterprise risk.
−Removed: To date, the Company has not experienced a cybersecurity threat or incident that has materially affected or is reasonably likely to materially affect the Company.
+Added: We engage third-party service providers to assist in identifying, assessing, monitoring, and managing cybersecurity risks, including through security assessments, penetration testing, managed detection and response services, and external threat intelligence.
+Added: In addition, we maintain processes designed to evaluate and monitor cybersecurity risks associated with third-party service providers, including through due diligence reviews, contractual security requirements, and ongoing performance monitoring, as appropriate.
+Added: Our Cybersecurity Leadership Team inventories and prioritizes information security risks and evaluates material risks from cybersecurity threats, and reports those periodically to the Audit Committee of our Board of Directors , which evaluates our overall enterprise risk.
+Added: As of the date of this Annual Report on Form 10-K, we are not aware of any cybersecurity incident that has materially affected or is reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial condition.
The Company, however, has experienced and expects to continue to experience cyber incidents of varying degrees.
2 unchanged sentences
Our Board of Directors has ultimate oversight responsibility over cybersecurity-related matters and has assigned oversight of cybersecurity risk management to the Audit Committee.
−Removed: The Audit Committee assists the Board in fulfilling its oversight responsibilities with respect to the management of risks arising from cybersecurity threats and, in furtherance thereof, regularly receives reports from our senior management and Cybersecurity Leadership Team on cybersecurity matters.
+Added: The Audit Committee assists the Board in fulfilling its oversight responsibilities with respect to cybersecurity risk management and receives periodic reports, at least annually and more frequently as warranted, from senior management and the Cybersecurity Leadership Team regarding cybersecurity risk posture, significant threats, incident response readiness, and key risk mitigation initiatives.
These reports are intended to highlight the state of our cybersecurity and data security programs, as well as our progress on key initiatives in this area.
1 unchanged sentence
As appropriate, the Board also may receive information regarding specific cybersecurity incidents and resulting mitigation efforts.
+Added: For additional information regarding cybersecurity-related risks that could materially affect us, see Item 1A, “Risk Factors.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.