11 unchanged sentences
Additionally, our Audit Committee, which consists solely of independent trustees, is responsible for overseeing cybersecurity risks and related initiatives.
−Removed: Our Audit Committee reviews our enterprise risk and cybersecurity risks.
+Added: Our Audit Committee reviews our cybersecurity risks.
It also reviews the steps our Advisor has taken to protect against threats to our information systems and security and receives updates on cybersecurity on a quarterly basis.
+Added: Net Lease Office Properties 2025 10-K – 17
Our Advisor’s information technology team is led by its Chief Information Officer who reports to its Chief Financial Officer and has extensive experience working with information security systems.
7 unchanged sentences
In addition, our Advisor’s information technology team conducts routine security assessments as well as ongoing cybersecurity training campaigns for the Advisor’s employees and board of directors to enhance awareness and increase vigilance for the various types of cybersecurity attacks to which they may be exposed.
−Removed: Our Advisor’s internal audit team evaluates and monitors
−Removed: Net Lease Office Properties 2024 10-K – 20
−Removed: our internal controls over systems access in an effort to mitigate information security risks that may result from unauthorized access to systems and data.
+Added: Our Advisor’s internal audit team evaluates and monitors our internal controls over systems access in an effort to mitigate information security risks that may result from unauthorized access to systems and data.
Third-party vendors are vetted through our Advisor’s service delivery program to ensure they have an established cybersecurity program.
−Removed: Our Advisor has also engaged a managed security provider to manage a supply chain defense subscription that will help obtain visibility into cybersecurity risks across third party vendors by proactively identifying, prioritizing, and driving remediation for cyber risks posed by critical business partners.
+Added: Our Advisor has also engaged a managed security provider to manage a supply chain defense subscription that will help obtain visibility into cybersecurity risks across high-risk third party vendors by proactively identifying, prioritizing, and driving remediation for cyber risks posed by critical business partners.
Our Advisor’s managed security provider’s risk operations center will escalate certain alerts regarding third-party vendors directly to the IT Department thus providing direct collaboration with third parties, saving time and improving risk reduction while safeguarding our relationships with such third parties.
7 unchanged sentences
They may include returning affected systems to an operationally ready state and confirming that the affected systems are functioning normally.
+Added: Net Lease Office Properties 2025 10-K – 18
Our Advisor has relationships with a number of third party service providers to assist with cybersecurity containment and remediation efforts, including outside legal counsel, vendors and external insurance brokers.
1 unchanged sentence
Cybersecurity Risks
−Removed: As of December 31, 2024, we are not aware of any instances of material cybersecurity incidents that impacted the Company in the last three years.
+Added: As of December 31, 2025, we have not had any known instances of material cybersecurity incidents, including third-party incidents, during any of the last three fiscal years.
However, there can be no assurance that our cybersecurity efforts and measures will be effective or that attempted cybersecurity incidents or disruptions would not be successful or damaging.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.