8 unchanged sentences
Assessment results are reported to the Audit Committee and the Board of Directors, and the Company may make modifications to its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments and reviews.
−Removed: New Jersey Resources Corporation
−Removed: CYBERSECURITY (Continued)
Key components of our cybersecurity risk management program include:
1 unchanged sentence
• the use of external service providers with specific expertise, where appropriate, to assess, test or otherwise assist with aspects of our security processes;
−Removed: • evaluating, and where appropriate, implementing effective, up-to-date technologies and processes to enhance our cybersecurity capabilities;
+Added: • evaluating our cybersecurity capabilities and, where appropriate, implementing effective, up-to-date technologies and processes to enhance them;
• mandatory cybersecurity awareness training for our employees, including incident response personnel and senior management, as well as periodic experiential learning through phishing simulations;
−Removed: • risk assessments of third-party suppliers and incorporating cybersecurity contractual stipulations in our supplier contracts if deemed necessary;
+Added: • risk assessments of third-party suppliers and the incorporation of cybersecurity contractual stipulations in our supplier contracts if deemed necessary;
• physical security around sensitive infrastructure and critical cyber systems;
• intelligence sharing about emerging threats through collaboration with peer companies and government intelligence agencies.
+Added: New Jersey Resources Corporation
+Added: CYBERSECURITY (Continued)
Enterprise-wide, proactive cybersecurity risk mitigation is imperative to the Company.
15 unchanged sentences
The members of the cybersecurity organization are expected to keep their knowledge, skills and training current by participating in industry events and continuing education programs as applicable.
−Removed: The Company also maintains an internal Cyber Resiliency Committee, which includes members of senior management from Information Technology, Cybersecurity, Enterprise Risk Management, Internal Audit, Corporate Communications, Legal, Finance and Corporate Physical Security.
−Removed: The Managing Director of Information Security chairs this committee, which is responsible for the following:
+Added: The Company also maintains an internal, cross-functional Cyber Resiliency Committee, which includes members of senior management from Information Technology, Cybersecurity, Enterprise Risk Management, Internal Audit, Corporate Communications, Legal, Finance and Corporate Physical Security.
+Added: The Managing Director of Information Security chairs this committee, which is responsible for:
• establishing cybersecurity policies and standards that align with our corporate objectives and regulatory requirements;
4 unchanged sentences
• facilitating cross-departmental collaboration to address cybersecurity challenges and responses.
−Removed: New Jersey Resources Corporation
−Removed: CYBERSECURITY (Continued)
−Removed: Through this ongoing engagement with these internal teams and certain third-party service providers, our CIO and our Managing Director of Information Security monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and report on cybersecurity incidents.
+Added: Through ongoing engagement with these internal teams and certain third-party service providers, our CIO and our Managing Director of Information Security monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and report on cybersecurity incidents.
The Company has a notification process in our incident response plan that contains requirements for timely notification to senior management by the CIO and to the Board of Directors by the CEO for incidents that reach established thresholds as well as procedures for external reporting.
2 unchanged sentences
The Senior Vice President and CIO is also responsible for compliance with applicable federal standards and critical infrastructure protection and reports to the Company’s President and CEO.
+Added: New Jersey Resources Corporation
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.