2 unchanged sentences
Risk Management and Strategy
−Removed: Our cybersecurity program is an important component of our broader risk management strategy in which cyber risk has been identified and is actively managed with preventive and mitigating measures.
−Removed: We design and assess our cybersecurity program based on the National Institute of Standards and Technology's Cybersecurity Framework, ISO 27001, and industry-specific regulations.
−Removed: This does not imply that we meet any particular technical standards, specification or requirements, but rather that we use these frameworks as a guide to help us identify, assess and manage cybersecurity risks relevant to our business.
−Removed: On an ongoing basis, we assess our people, processes, and technology, and when necessary, modify the overall program in order to meet the demands of the ever-changing cyber risk environment.
−Removed: As part of our regular training and readiness program, we conduct phishing and penetration testing campaigns in order to ensure that our employees are familiar with all types of phishing emails and similar threats.
−Removed: Our data is dynamically backed up to mitigate against data loss.
−Removed: To prevent unauthorized access and data breaches, we encrypt sensitive data both in transit and at rest and we have also implemented access controls and multi-factor authentication to ensure that only authorized personnel can access sensitive information.
−Removed: We also utilize third-party information technology systems vendors to conduct constant network and endpoint monitoring.
−Removed: We develop and implement robust cybersecurity policies and procedures that address access control, data encryption, use of assets, and data protection.
−Removed: We ensure that all employees, contractors, and third-party vendors adhere to these policies and receive training on cybersecurity best practices.
−Removed: Our cybersecurity function resides within the broader security function and reports to the Vice President of Health, Safety, Security & Environmental (“VP HSSE”), who is responsible for the delivery of a robust and risk-based cybersecurity program.
−Removed: The Senior Manager of Cybersecurity, reporting to the VP HSSE, is responsible for all activities, including improvements, incident response, and investigation.
−Removed: Cyber governance oversight is provided by the Audit Committee of the Board of Directors.
−Removed: The Audit Committee discusses with management our cybersecurity risk exposures and the steps management has taken to mitigate such exposures, including our risk assessment and risk management policies.
+Added: Our cybersecurity program vision is to secure our information, people, and assets.
+Added: It plays a critical role in our overall risk management strategy, where cyber risks are identified and actively managed through preventive and mitigating measures.
+Added: Our Cybersecurity design principles of Secure by Design and Depth in Defense help us to design and evaluate our cybersecurity initiatives and are grounded in frameworks such as the National Institute of Standards and Technology's Cybersecurity Framework, ISO 27001, and industry-specific regulations.
+Added: While this approach does not imply compliance with any specific technical standards or requirements, these frameworks serve as a guide to help us identify, assess, and manage cybersecurity risks that are relevant to our business.
+Added: We continuously evaluate our people, processes, and technology, adjusting our program as needed to keep up with the evolving cyber risk landscape.
+Added: As part of our ongoing training and preparedness efforts, we regularly conduct phishing simulations and penetration testing campaigns to ensure our employees are well-equipped to recognize various phishing emails and other similar threats.
+Added: We actively back up our data to minimize the risk of data loss.
+Added: To safeguard against unauthorized access and data breaches, we encrypt sensitive information both in transit and at rest.
+Added: Additionally, we have implemented access controls and multi-factor authentication to ensure that only authorized personnel can access critical data.
+Added: To further enhance security and ensure operational continuity, we partner with third-party IT service providers and Managed Services vendors who continuously monitor our infrastructure, conducting ongoing network and endpoint surveillance.
+Added: We develop and implement robust cybersecurity standards and procedures that address access control, data encryption, use of assets, and data protection.
+Added: We ensure that all employees, contractors, and third-party vendors adhere to these standards and receive training on cybersecurity best practices.
+Added: Our cybersecurity team resides within Digital & Information Technology function and reports to ML Madhavaro, our Vice President of Information Technology and Chief Information Officer , who is responsible for the delivery of a robust and risk-based cybersecurity program, including threat detection and response, risk management, security architecture, vulnerability management, incident response, and security awareness.
+Added: Madhavarao has decades of experience managing strategic technology operations, including the identification of cybersecurity risk and the defense of information technology assets from global threats.
+Added: Cyber governance oversight is provided by the Chief Financial Officer and the Audit Committee of the Board of Directors.
Incident Response Reporting
−Removed: Our strength in incident response reporting lies in our proactive and transparent approach to addressing cybersecurity incidents swiftly and effectively.
−Removed: We focus on preventative measures to reduce the likelihood of a cybersecurity incident and we have a robust response and recovery program and a cross-functional response team, which would be activated in the event of an incident to manage and reduce the escalation of the incident.
−Removed: We have established a robust incident response framework that enables us to detect, respond to, and mitigate threats with precision and speed.
−Removed: Our strategy involves clear communication channels, defined roles and responsibilities, and regular drills and simulations to ensure readiness.
−Removed: When an incident occurs, we adhere to strict reporting protocols, promptly notifying appropriate regulatory authorities and affected customers and stakeholders, while maintaining transparency and accountability throughout the process, which allows us to not only mitigate the impact of cyber threats but also demonstrate our commitment to cybersecurity risk prevention and response.
−Removed: During the year ended December 31, 2023, there were no cybersecurity incidents or threats that materially affected our business, results of operations or financial condition.
+Added: Our strength in incident response reporting comes from our proactive and transparent approach to swiftly and effectively addressing cybersecurity incidents.
+Added: We prioritize preventative measures to reduce the likelihood of a cybersecurity incident, while maintaining a robust response and recovery program.
+Added: We have established a comprehensive incident response framework that allows us to detect, respond to, and mitigate threats with precision and speed according to our plan.
+Added: Our strategy includes clear communication channels, defined roles and responsibilities, and regular drills and simulations to ensure we are always prepared.
+Added: In the event of an incident, we follow strict reporting protocols, promptly notifying the relevant regulatory authorities, affected customers, and stakeholders.
+Added: We maintain transparency and accountability throughout the process, which helps us mitigate the impact of cyber threats and reinforces our commitment to proactive cybersecurity risk management and response.
+Added: During the year ended December 31, 2024, there were no cybersecurity incidents or threats that had a material impact on our business, results of operations or financial condition .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.