8 unchanged sentences
We routinely review, modify, and update this program as necessary to address emerging risks.
−Removed: Our process for addressing risk is based on industry best practices outlined in CIS Critical Security Controls.
+Added: Our process for addressing risk is based on industry-best practices outlined in Center for Internet Security (" CIS") Critical Security Controls.
Although this program is integrated within the Company's overall risk management system, the implementation of this program requires a unique and specialized level of expertise and experience, which has led us to create a cybersecurity team and various processes designed to address these specific risks, as discussed more below.
7 unchanged sentences
We routinely test our incident response process through simulated incidents.
−Removed: No risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
While we have not experienced any cybersecurity incidents or threats that have materially impacted us or our business, we have encountered incidents in the past, which we have used to improve our program and defenses.
4 unchanged sentences
The Governance Committee is also tasked with reviewing any significant cybersecurity incident that occurs.
−Removed: The Governance Committee is required by its Charter to consist of not fewer than three independent directors, and the committee currently consists of five independent directors.
+Added: The Governance Committee is required by its Charter to consist of not fewer than three independent directors, and the committee currently consists of four independent directors.
The Governance Committee typically meets on a quarterly basis.
−Removed: At each meeting, a written cybersecurity brief from IT leadership is provided.
+Added: At least each year, a written cybersecurity brief from IT leadership is provided.
These reports include a review of emerging cybersecurity risks and developments and updates to our cybersecurity risk assessment program.
−Removed: The Governance Committee provides regular reports to the full Board of Directors on its oversight of the Company's cybersecurity risks and risk management system.
+Added: The Governance Committee provides annual reports to the full Board of Directors on its oversight of the Company's cybersecurity risks and risk management system.
Management's Role
14 unchanged sentences
• Incident response plans to ensure swift, effective, and adequate disclosure of cybersecurity incidents to the appropriate individuals within the Company.
−Removed: These processes are regularly reviewed and updated to adapt to evolving cybersecurity threats and any changes in our systems or business operations.
−Removed: Our head of IT, cybersecurity manager, and other members of our cybersecurity team provide quarterly updates and reports to the Governance Committee of our Board of Directors on cybersecurity risks and our risk management systems.
+Added: These processes are reviewed and updated to adapt to evolving cybersecurity threats and any changes in our systems or business operations.
Our cybersecurity team is also required to provide senior management and the Governance Committee with more frequent updates on major developments regarding cybersecurity matters or as otherwise appropriate.
−Removed: As noted above, the Governance Committee provides regular updates to the Board on these matters so that the Board remains adequately informed about this important aspect of the Company's overall risk management.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.