2 unchanged sentences
Risk management and strategy
−Removed: The Company is committed to securing our information technology systems, including accounting software, point-of-sale software, and back-of-house software, against cybersecurity threats and protecting the privacy of the data of our customers’, employees’, franchisees’, licensees’ and other business partners.
+Added: The Company has developed and implemented a cybersecurity risk management program intended to secure our information technology systems, including accounting software, point-of-sale software, and back-of-house software, against cybersecurity threats and to protect the privacy of the data of our customers’, employees’, franchisees’, licensees’ and other business partners.
However, as described in “Item 1A.
−Removed: Risk Factors – Cyberattacks and breaches could cause operational disruptions, fraud or theft of sensitive information ” of this Form 10-K, we recognize that cybersecurity threats are an ongoing concern in today’s digital world and that, despite devoting resources to secure our information technology systems, cybersecurity incidents can occur and, if so, could negatively impact our brand, business, results of operations and financial condition.
+Added: Risk Factors – Cyberattacks and breaches could cause operational disruptions, fraud or theft of sensitive information ” of this Form 10-K, we recognize that cybersecurity threats are an ongoing concern in today’s digital landscape and that, despite devoting resources to secure our information technology systems, cybersecurity incidents can occur and, if so, could negatively impact our brand, business, results of operations and financial condition.
Cybersecurity threats include any potential unauthorized occurrence on or conducted through our information technology systems or information technology systems of a third party that we utilize in our business that may result in adverse effects on the confidentiality, integrity or access to our information technology systems.
8 unchanged sentences
The Company’s senior management team, including its Chief Executive Officer and its Chief Financial Officer, reviews the assessments performed by its third-party consultants and determines the plans to be executed in collaboration with the Information Technology manager.
−Removed: Our information technology infrastructure includes firewalls, modern endpoint protections, intrusion detection tools and alerts, as well as multi-factor authentication to provide a multi-layered approach to protecting our information technology systems from unauthorized access, use, disclosure, disruption, or destruction.
+Added: We design our cybersecurity infrastructure to include firewall protections, anti-virus protections, modern endpoint protections, intrusion detection tools and alerts, as well as multi-factor authentication to provide a multi-layered approach to protecting our information technology systems from unauthorized access, use, disclosure, disruption, or destruction.
Such applications are regularly monitored and reviewed for adequacy and potential enhancements.
−Removed: We obtain System and Organizational Controls (“SOC”) 1 or SOC 2 reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk amongst our relationships with the host vendors.
+Added: We obtain System and Organizational Controls (“SOC”) 1 or SOC 2 audit reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk amongst our relationships with the host vendors.
We also perform quarterly access reviews for these systems that are subject to Sarbanes-Oxley oversight.
1 unchanged sentence
There is no connectivity between the Company’s network and the networks on which our franchisees and licensees operate.
−Removed: Furthermore, there is no interface between the Company-owned restaurants point-of-sale system and the Company’s network and no interface between the Company’s primary manufacturer, Smithfield Foods, Inc.
−Removed: and the Company’s network.
−Removed: The Company routinely leads training exercises, at least annually, for its employees to reinforce the risk from common tactics and scams like email phishing campaigns, as well as more sophisticated descendants (i.e.
+Added: Furthermore, there is no interface between the Company-owned restaurants point-of-sale system and the Company’s network and no interface between the Company’s primary manufacturer, Smithfield Foods and the Company’s network.
+Added: The Company conducts periodic training exercises for its employees to reinforce the risk from common tactics and scams like email phishing campaigns, as well as more sophisticated descendants (i.e.
spear phishing and smishing) to defend against potential business email and network compromise.
15 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.