1 unchanged sentence
Cybersecurity
−Removed: We recognize the critical importance of maintaining the trust and confidence of customers, clients, business partners and employees toward our business and are committed to protecting the confidentiality, integrity and availability of our business operations and systems.
+Added: We recognize the critical importance of maintaining the trust and confidence of customers, clients, business partners and employees toward our business and are committed to protecting the confidentiality, integrity and
+Added: availability of our business operations and systems.
Our board of directors is actively involved in oversight of our risk management activities, and cybersecurity represents an important element of our overall approach to risk management.
−Removed: Our cybersecurity policies, standards, processes and practices are based on recognized
−Removed: frameworks such as the National Institute of Standards and Technology (“NIST”) and other similar industry standards.
+Added: Our cybersecurity policies, standards, processes and practices are based on recognized frameworks such as the National Institute of Standards and Technology (“NIST”) and other similar industry standards.
In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
3 unchanged sentences
To identify and assess material risks from cybersecurity threats, we maintain a comprehensive cybersecurity program to ensure our systems are effective and prepared for information security risks, including regular oversight of our programs for security monitoring for internal and external threats to ensure the confidentiality and integrity of our information assets.
−Removed: We consider risks from cybersecurity threats alongside other company risks as part of our overall risk assessment process.
−Removed: We employ a range of tools and services, including regular network and endpoint monitoring, audits, vulnerability assessments, penetration testing, threat modeling and tabletop exercises to inform our risk identification and assessment.
+Added: Our board of directors and management consider risks from cybersecurity threats alongside other company risks as part of our overall risk assessment process.
+Added: We employ a range of tools and services, including regular network and endpoint monitoring, audits, vulnerability assessments, penetration testing, threat modeling and data recovery testing to inform our risk identification and assessment.
As discussed in more detail under “Cybersecurity Governance;
−Removed: Management” below, our board of directors provides oversight of our cybersecurity risk management and strategy processes, which are led by our Chief Financial Officer and Senior Director of IT and Security.
+Added: Management” below, our board of directors provides oversight of our cybersecurity risk management and strategy processes, which are led by our Chief Financial Officer and our third party IT and Security services partners.
We also identify our cybersecurity threat risks by comparing our processes to standards set by NIST.
10 unchanged sentences
In addition, cybersecurity considerations affect the selection and oversight of our third-party service providers.
−Removed: perform diligence on third parties that have access to our systems, data or facilities that house such systems or data, and continually monitor cybersecurity threat risks identified through such diligence.
−Removed: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “Difficulties with our global information technology systems, including any unauthorized access or cyber-attacks, could harm our business” which disclosures are incorporated by reference herein.
+Added: We perform diligence on third parties that have access to our systems, data or facilities that house such systems or data, and continually monitor cybersecurity threat risks identified through such diligence.
+Added: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “Our global information technology systems, including those of our vendors, may fail, suffer unauthorized access or cyber-attacks, loss of data, and other disruptions, which could result in a material disruption of our business or product development, and could materially and adversely harm our business” which disclosures are incorporated by reference herein.
In the last three fiscal years, we have not experienced any material cybersecurity incidents and the expenses we have incurred from cybersecurity incidents were immaterial.
3 unchanged sentences
Our board of directors is responsible for the oversight of risks from cybersecurity threats.
−Removed: Our sole director, who also serves as our President and Chief Executive Officer, regularly receives updates from other members of management regarding our cybersecurity threat risk management and strategy processes covering topics such as data security posture, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
−Removed: In these sessions, our sole director generally receives materials that include a cybersecurity dashboard and other materials discussing current and emerging material cybersecurity threat risks, and describing our ability to mitigate those risks, as well as recent developments, evolving standards, technological developments and information security considerations arising with respect to our peers and third parties, and discusses such matters with our Chief Financial Officer.
−Removed: Our sole director also receives prompt and timely information regarding any cybersecurity incident that meets establishing reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Chief Financial Officer and Senior Director of IT and Security .
+Added: Our President and Chief Executive Officer, regularly receives updates from other members of management regarding our cybersecurity threat risk management and strategy processes covering topics such as data security posture, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
+Added: In these sessions, our President and Chief Executive Officer generally receives materials that include a cybersecurity dashboard and other materials discussing current and emerging material cybersecurity threat risks, and describing our ability to mitigate those risks, as well as recent developments, evolving standards, technological developments and information security considerations arising with respect to our peers and third parties, and discusses such matters with our Chief Financial Officer.
+Added: Our President and Chief Executive Officer also receives prompt and timely information regarding any cybersecurity incident that meets establishing reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: Our board of directors communicates with our President and Chief Executive Officer regarding these updates and related matters.
+Added: Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Chief Financial Officer and Senior Director of our third-party IT and Security services partners .
Such individuals have over 30 years of prior work experience in various roles involving managing information security, developing cybersecurity strategy, implementing effective information and cybersecurity programs .
These management team members are informed about and monitor the prevention, mitigation, detection, and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above, including the operation of our incident response plan.
−Removed: As discussed above, these management team members report to our sole director about cybersecurity threat risks, among other cybersecurity related matters, on a regular basis .
+Added: As discussed above, these management team members report to our President and Chief Executive Officer about cybersecurity threat risks, among other cybersecurity related matters, on a regular basis .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.