1 unchanged sentence
CYBERSECURITY
−Removed: cybersecurity team, led by our Chief Technology Officer, Peter Shelus, uses a multi-pronged approach to assessing, identifying, and managing
−Removed: material risks from cybersecurity threats.
+Added: Our cybersecurity team, led by our Chief Technology
+Added: Officer, Peter Shelus, uses a multi-pronged approach to assessing, identifying, and managing material risks from cybersecurity threats .
This approach includes identifying and assessing risks through:
−Removed: (1) an enterprise risk management
−Removed: program, which is periodically refreshed and includes an identification of our top risks, including cybersecurity risks;
−Removed: (2) formalized
−Removed: security and privacy reviews designed to identify risks from many new features, software, and vendors;
−Removed: (3) a vulnerability management
−Removed: program designed to identify hardware and software vulnerabilities;
−Removed: (4) an internal “red team” program, which simulates cyber
−Removed: threats, intended to allow us to fix vulnerabilities before threat actors identify them;
−Removed: (5) a threat intelligence program designed to
−Removed: model and research our adversaries;
−Removed: and (6) a privacy and security incident response program designed to investigate, respond to, and
−Removed: remediate known incidents.
−Removed: These processes vary in scope and maturity across the business and are processes we work to continually improve.
−Removed: risk management approach is supplemented by external and internal enterprise risk management audits, which are designed to test the effectiveness
−Removed: of our security controls.
−Removed: We conduct penetration testing on a periodic basis, and have established an external bug bounty program to
−Removed: allow security researchers to help identify vulnerabilities and weaknesses in our controls and configurations in our systems.
−Removed: maintain a vendor risk management program designed to identify and mitigate potential risks associated with third-party suppliers and
−Removed: business partners.
−Removed: This program includes pre-engagement diligence, use of contractual cybersecurity and notification provisions, and
−Removed: ongoing monitoring of vendors, as appropriate.
−Removed: use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats,
−Removed: including for example professional service firms (including legal counsel), threat intelligence services, and cybersecurity consultants.
−Removed: material cybersecurity threats identified through these processes are managed by our CISO and, where appropriate, our risk and compliance
−Removed: committee, in consultation with management.
−Removed: Together, they identify responsive actions for inclusion in our annual strategic planning,
−Removed: or earlier resolution depending on the nature of the risk.
−Removed: a description of the risks from cybersecurity threats that may materially affect us and how they may do so, see “Risk Factors”
−Removed: in Part I, Item 1A in this Annual Report on Form 10-K.
+Added: (1) an enterprise risk management program, which is periodically refreshed
+Added: and includes an identification of our top risks, including cybersecurity risks;
+Added: (2) formalized security and privacy reviews designed
+Added: to identify risks from many new features, software, and vendors;
+Added: (3) a vulnerability management program designed to identify hardware
+Added: and software vulnerabilities;
+Added: (4) an internal “red team” program, which simulates cyber threats, intended to allow us to
+Added: fix vulnerabilities before threat actors identify them;
+Added: (5) a threat intelligence program designed to model and research our adversaries;
+Added: and (6) a privacy and security incident response program designed to investigate, respond to, and remediate known incidents.
+Added: These processes
+Added: vary in scope and maturity across the business and are processes we work to continually improve.
+Added: Our risk management approach is supplemented
+Added: by external and internal enterprise risk management audits, which are designed to test the effectiveness of our security controls.
+Added: conduct penetration testing on a periodic basis, and have established an external bug bounty program to allow security researchers to
+Added: help identify vulnerabilities and weaknesses in our controls and configurations in our systems.
+Added: We also maintain a vendor risk management
+Added: program designed to identify and mitigate potential risks associated with third-party suppliers and business partners.
+Added: This program includes
+Added: pre-engagement diligence, use of contractual cybersecurity and notification provisions, and ongoing monitoring of vendors, as appropriate.
+Added: We use third-party service providers to assist
+Added: us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example professional service
+Added: firms (including legal counsel), threat intelligence services, and cybersecurity consultants.
+Added: The material cybersecurity threats identified
+Added: through these processes are managed by our CISO and, where appropriate, our risk and compliance committee, in consultation with management.
+Added: Together, they identify responsive actions for inclusion in our annual strategic planning, or earlier resolution depending on the nature
+Added: For a description of the risks from cybersecurity
+Added: threats that may materially affect us and how they may do so, see “Risk Factors” in Part I, Item 1A in this Annual Report
+Added: on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.