4 unchanged sentences
These risks include, among other things:
−Removed: operational disruptions, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
−Removed: Our cybersecurity programs are built on both operational and compliance foundations.
−Removed: The operational component focuses on continuous detection, prevention, measurement, analysis and response to cybersecurity alerts and incidents, and on emerging threats.
−Removed: The compliance component establishes oversight of our cybersecurity programs by creating risk-based controls to protect the integrity, confidentiality, accessibility and availability of company data stored, processed or transferred.
+Added: operational disruptions, intellectual property theft, fraud, extortion, harm to employees or customers and violations of data privacy or security laws.
+Added: Our cybersecurity program is built on both operational and compliance foundations.
+Added: The operational component focuses on continuous monitoring, detection, prevention, measurement, analysis and response to cybersecurity threats and incidents, including emerging risks.
+Added: The compliance component provides oversight through risk-based controls designed to protect the confidentiality, integrity and availability of company data stored, processed or transmitted.
Our cybersecurity program is fully integrated into our enterprise-wide risk management framework.
Kronos and CompX each have their own cybersecurity programs.
−Removed: Our corporate cybersecurity program is led by our chief information officer ( CIO ), who is responsible for developing and executing our overall information security strategy, policy, security engineering, operations and cyber threat detection and response.
+Added: Our corporate cybersecurity program is led by our chief information officer (“ CIO ”), who is ultimately responsible for developing and executing our overall information security strategy, policies, security engineering, operations and cyber threat detection and response.
Our corporate information systems are owned and operated by Contran and provided to us through the ISA.
2 unchanged sentences
The director of IT reports to CompX’s vice president in charge of coordinating operational activities within CompX’s two operating business segments.
−Removed: Both our CIO and the director of IT have extensive information technology and program management experience and lead teams that have many years of experience with each organization.
+Added: Both our CIO and the director of IT have extensive information technology and program management experience and lead teams with significant tenure and familiarity with each organization.
Cybersecurity risks at each company are also reviewed and tested annually through third-party assessments and internal and external information technology audits.
−Removed: Our, Kronos’ and CompX’s information technology teams review cybersecurity risks at least annually, integrating findings into strategic risk assessments.
+Added: Our, Kronos’ and CompX’s information technology teams review cybersecurity risks at least annually, integrating findings into strategic risk assessments and applicable corrective action plans.
We, Kronos and CompX continually enhance our cyber defense strategy with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while simultaneously bolstering our system resilience in an effort to minimize the business impact should an incident occur.
−Removed: Third parties also play a role in our cybersecurity.
−Removed: We, Kronos and CompX engage reputable third-party security firms for consultation on industry best practices and regulatory standards and to conduct routine evaluations of our cybersecurity, such as through penetration testing and security audits;
−Removed: these evaluations include testing both the design and operational effectiveness of security controls.
−Removed: All employees are required to complete cybersecurity training at least once a year and have access to more frequent cybersecurity training through periodic updates.
+Added: Third parties also play a role in our cybersecurity posture.
+Added: We, Kronos and CompX engage reputable third-party security firms provide guidance on industry best practices and regulatory standards, to support proactive and reactive cybersecurity efforts, and to conduct periodic routine evaluations of our cybersecurity posture, including penetration testing and security audits;
+Added: these evaluations include testing both the design and operational effectiveness of our security controls.
+Added: All company employees are required to complete cybersecurity training at least once a year, have access to more frequent cybersecurity training through periodic updates.
Employees in certain roles also receive additional role-based, specialized cybersecurity training.
1 unchanged sentence
Our CIDAC is comprised of our CIO and other senior executives including our chief executive officer, chief financial officer and general counsel.
−Removed: Security events and data incidents are evaluated, ranked by severity and prioritized for response and remediation.
−Removed: The IT teams are responsible for categorizing cybersecurity incidents, and those deemed high-risk or critical are escalated to the CIDAC for review and response coordination.
−Removed: Incidents are evaluated to determine materiality and for operational, financial and reputational impact.
−Removed: Our CIDAC, as well as the Kronos and CompX CIDAC, performs simulations and tabletop exercises at a
−Removed: management level to evaluate our readiness and response to cybersecurity incidents.
+Added: Information security events and incidents are evaluated, ranked by severity and prioritized for response and remediation.
+Added: The IT teams are responsible for categorizing cybersecurity incidents, and those deemed high-risk or critical are escalated to the CIDAC for strategic review and response coordination.
+Added: Incidents are evaluated to determine regulatory requirements, materiality and potential operational, financial and reputational impact.
+Added: Our CIDAC, as well as the Kronos and CompX CIDAC, performs simulations and tabletop exercises at a management level to evaluate our readiness and response to cybersecurity incidents.
As needed, we collaborate with external cybersecurity experts and legal advisors to help ensure a robust response strategy.
4 unchanged sentences
Our full board retains oversight of cybersecurity because of its importance to us and visibility with our customers.
+Added: We also maintain a documented incident response plan.
In the event of an incident, we follow a structured incident response playbook, which outlines clear and defined steps to be followed from incident detection to mitigation, recovery and notification, including notifying functional areas (such as legal and human resources), senior leadership, and the board, as appropriate.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.