11 unchanged sentences
Senior management meets regularly with the Company’s risk-management team and internal and external auditors to evaluate the effectiveness of the Company’s systems, controls, and management processes with respect to cybersecurity risks.
−Removed: The results of key assessments are reported in summary to the Board of Directors periodically.
+Added: The results of key assessments are reported in summary to our Board of Directors periodically.
We also recognize that we are exposed to cybersecurity threats associated with our use of third-party service providers.
12 unchanged sentences
As part of its oversight of cybersecurity and informational security risk, on an annual basis, our Board of Directors reviews its Information Security Policy with its appointed Information Security Officer and frequently receives presentations on and discusses cybersecurity and information security risks, industry trends, and best practices from our Chief Information Officer and our Information Security Officer.
+Added: We maintain relevant expertise within the Company's management team to manage cybersecurity risks.
At the management level, the Chief Information Officer and Information Security Officer receive regular reports from the Company’s systems department, both historical and real-time, about the Company’s cybersecurity status.
−Removed: The Company has established written policies and procedures to ensure that significant cybersecurity incidents are immediately investigated, addressed through the coordination of various internal departments, and publicly reported (to the extent required by applicable
−Removed: If management determines a material cybersecurity incident has occurred, the Company’s policies require management to promptly inform the Audit Committee with follow-up information to the full Board of Directors.
+Added: The Company has established written policies and procedures to ensure that significant cybersecurity incidents are immediately investigated, addressed through the coordination of various internal departments, and publicly reported (to the extent required by applicable law).
+Added: management determines a material cybersecurity incident has occurred, the Company’s policies require management to promptly inform the Audit Committee with follow-up information to the full Board of Directors.
Under the direction of the Chief Information Officer, the Information Security Officer is responsible for cybersecurity and business continuity, which includes security architecture, security operations, incident response, IT risk and compliance, and security awareness and training.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.