17 unchanged sentences
Mandatory training is required on a quarterly basis for all CFC employees to promote leading practices in protecting information, data and operations in a continually changing environment.
+Added: We established requirements regarding the use of company-approved generative artificial intelligence tools to ensure that all employees utilize such tools in a manner that safeguards sensitive information and aligns with legal requirements and CFC’s ethical standards.
The effectiveness of our cybersecurity operations is regularly examined and tested by third-party vendors who specialize in cybersecurity risk management.
5 unchanged sentences
Management reports at least quarterly to the board on matters related to CFC’s security operations, potential threats, industry-wide trends and any other related information requested by the board.
−Removed: The reports include information on material cybersecurity incidents, if any, and management actions to protect CFC.
−Removed: Upon the occurrence of a material cybersecurity incident, the Board of Directors will be promptly notified so it may properly evaluate such cybersecurity incident, including management’s remediation plan.
+Added: The reports include information on significant cybersecurity incidents, if any, and management actions to protect CFC.
+Added: We promptly notify the board of directors upon the occurrence of a significant cybersecurity incident so it may properly evaluate the incident, including management’s remediation plan.
In addition to the regular cybersecurity program reports, the board monitors cybersecurity risk and program effectiveness through internal audit and our enterprise risk m anagement reporting framework.
−Removed: On an annual basis, our Chief Information Officer (“CIO”) and Director, Information Security, provide the Board an overview of the company’s technology strategy and planned activities to continually improve the cybersecurity program, as well as threats and cybersecurity incidents.
+Added: On an annual basis, members of our staff responsible for cybersecurity provide the board an overview of the company’s technology strategy and planned activities to continually improve the cybersecurity program, as well as threats and cybersecurity incidents.
Furt her, on at least an annual basis, the board of directors reviews management reports concerning the disclosure controls and procedures in place to enable CFC to make accurate and timely disclosures about any material cybersecurity incidents.
2 unchanged sentences
Management’s approach helps ensure the organization works collaboratively to monitor, assess and respond to cybersecurity incidents at all levels and functions consistent with our incident response procedures and corporate practices.
−Removed: Our first line of defense includes our CIO and Director, Information Security, who work to ensure that the day-to-day execution of the company’s technology and security operations are in alignment with corporate policies and procedures.
−Removed: Our CIO, who reports to our Chief Operating Officer ( “ COO ” ), has over two decades of experience managing technology risk.
−Removed: Our Director, Information Security, who dually reports to the COO and CIO, has over a decade of information security management experience and as a Certified Information Systems Security Professional.
−Removed: Collectively, they are also
−Removed: responsible for information security policies, organizational readiness and the escalation of certain cybersecurity incidents from our cybersecurity personnel to senior management based on our incident response procedures.
+Added: Our first line of defense includes our cybersecurity team lead by our Director, Information Security , who work to ensure that the day-to-day execution of the company’s technology and security operations are in alignment with corporate policies and procedures.
+Added: Our Director, Information Security, who reports to our Chief Operating Officer ( “ COO”), has over a decade of information security management experience and is a Certified Information Systems Security Professional.
+Added: Our COO and Director, Information Security are also responsible for information security policies, organizational readiness and the escalation of certain cybersecurity incidents from our cybersecurity personnel to senior management based on our incident response procedures.
Our second line of defense includes our Cybersecurity Committee and the enterprise risk-management framework under the direction of the Chief Risk Officer to monitor cybersecurity functions and risk management.
−Removed: In addition to the COO, CIO and Director, Information Security, our Cybersecurity Committee is composed of members of management including, but not limited to, the Chief Risk Officer, General Counsel and Vice President, Internal Audit.
+Added: Our Cybersecurity Committee is composed of members of management including, but not limited to, the COO, Chief Risk Officer, General Counsel and Vice President, Internal Audit.
The Cybersecurity Committee helps ensure corporate policy compliance and reports directly to the board of directors regarding material cybersecurity incidents and emerging threats.
Our third line of defense is the internal audit function led by our Vice President, Internal Audit, which plays a crucial role by providing independent and objective assurances on the design and operating effectiveness of our cybersecurity risk management and internal controls through the performance of audits and reviews.
−Removed: Internal audit engages external consultants and subject matter experts as appropriate to assist in the assessment of management’s cybersecurity program and reports the results directly to the Board.
+Added: Internal Audit engages external consultants and subject matter experts as appropriate to assist in the assessment of management’s cybersecurity program and reports the results directly to the b oard .
We have not experienced any material cybersecurity incidents that have impacted our business, results of operations or financial condition to date.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.