2 unchanged sentences
RISK MANAGEMENT AND STRATEGY
−Removed: We have processes to identify, assess, monitor, and manage material risks related to information technology, including cybersecurity threats, vulnerability management, incident management, data protection and retention, and fraud prevention.
+Added: We have processes to identify, assess, monitor, and manage material risks related to information technology, including, but not limited to:
+Added: cybersecurity threats, vulnerability management, incident management, data protection and retention, recoverability, and fraud prevention.
Our Enterprise Risk Management process evaluates and mitigates cybersecurity risks in alignment with our business objectives and operational needs.
1 unchanged sentence
the results of these assessments are reported to our Audit Committee.
−Removed: Our service providers, and third-party hardware or software applications on our networks and company-issued devices, may pose cybersecurity risks.
+Added: Our service providers, and third-party hardware or software applications on our networks, may pose cybersecurity risks.
As a result, we assess these parties for cybersecurity risks using information supplied by our counterparty and/or third parties.
8 unchanged sentences
This Incident Response Policy is overseen by our Vice President of Infrastructure and Security (“VP Infrastructure”) along with the Incident Response team, which may consist of members from legal, human resources, finance or other functions, if necessary.
−Removed: The Incident Response Policy provides organizational and operational structure, processes, and procedures to our personnel so that employees can respond to incidents that may affect the function and security of our IT assets, information resources, and business operations.
+Added: The Incident Response Policy provides organizational and operational structure, processes, and procedures to our personnel so employees can respond to incidents that may affect the function and security of our IT assets, information resources, and business operations.
We conduct periodic information security awareness training for employees and provide related educational materials.
−Removed: While we have been subject to cyber attacks, the expenses (including penalties and settlements, of which there were none) related to such incidents were immaterial, and the risks related thereto have not been and are not reasonably likely to be material to our business strategy, results of operations or financial condition.
+Added: While we have been subject to cyber incidents, the expenses (including penalties and legal settlements, of which there were none) related to such incidents were immaterial.
+Added: The risks related thereto have not been and are not reasonably likely to be material to our business strategy, results of operations or financial condition.
Any significant disruption to our ability to transact business could adversely affect our business performance as well as our reputation.
13 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.