3 unchanged sentences
Cybersecurity incidents and threats pose a risk to the disruption of our business operations, including the confidentiality, integrity and availability of data and information.
−Removed: CFC’s cybersecurity program is designed to manage operational risks associated with the ever-evolving nature of cybersecurity threats.
+Added: CFC’s cybersecurity program is designed to manage operational risks associated with the ever-evolving nature of cybersecurity threats, including AI risks.
Because these risks could have a material adverse impact on our operations and reputation, both management and the CFC Board of Directors are actively engaged in the oversight of the cybersecurity program and our continuous efforts in monitoring, measuring and managing the risks.
11 unchanged sentences
Mandatory training is required on a quarterly basis for all CFC employees to promote leading practices in protecting information, data and operations in a continually changing environment.
−Removed: We established requirements regarding the use of company-approved generative artificial intelligence tools to ensure that all employees utilize such tools in a manner that safeguards sensitive information and aligns with legal requirements and CFC’s ethical standards.
+Added: We established requirements regarding the use of company-approved AI tools to ensure that all employees utilize such tools in a manner that safeguards sensitive information and aligns with legal requirements and CFC’s ethical standards.
The effectiveness of our cybersecurity operations is regularly examined and tested by third-party vendors who specialize in cybersecurity risk management.
13 unchanged sentences
Management’s approach helps ensure the organization works collaboratively to monitor, assess and respond to cybersecurity incidents at all levels and functions consistent with our incident response procedures and corporate practices.
−Removed: Our first line of defense includes our cybersecurity team lead by our Director, Information Security , who work to ensure that the day-to-day execution of the company’s technology and security operations are in alignment with corporate policies and procedures.
−Removed: Our Director, Information Security, who reports to our Chief Operating Officer ( “ COO”), has over a decade of information security management experience and is a Certified Information Systems Security Professional.
−Removed: Our COO and Director, Information Security are also responsible for information security policies, organizational readiness and the escalation of certain cybersecurity incidents from our cybersecurity personnel to senior management based on our incident response procedures.
+Added: Our first line of defense includes our cybersecurity team led by our Vice President, Information Technology , who works to ensure that the day-to-day execution of the company’s technology and security operations are in alignment with corporate policies and procedures.
+Added: Our Vice President, Information Technology, who reports to our Chief Operating Officer ( “ COO”), has over a decade of information security management experience, enhancing infrastructure defenses and fostering a culture of security awareness at various organizations.
+Added: Additionally, our Vice President, Information Technology, is a member of the Global Information Assurance Certification Advisory Board and actively maintains his certification as a Certified Information Systems Security Professional.
+Added: Our COO and Vice President, Information Technology, are also responsible for information security policies, organizational readiness and the escalation of certain cybersecurity incidents from our cybersecurity personnel to senior management based on our incident response procedures.
Our second line of defense includes our Cybersecurity Committee and the enterprise risk-management framework under the direction of the Chief Risk Officer to monitor cybersecurity functions and risk management.
2 unchanged sentences
Our third line of defense is the internal audit function led by our Vice President, Internal Audit, which plays a crucial role by providing independent and objective assurances on the design and operating effectiveness of our cybersecurity risk management and internal controls through the performance of audits and reviews.
−Removed: Internal Audit engages external consultants and subject matter experts as appropriate to assist in the assessment of management’s cybersecurity program and reports the results directly to the b oard .
−Removed: We have not experienced any material cybersecurity incidents that have impacted our business, results of operations or financial condition to date.
+Added: Internal Audit engages external consultants and subject matter experts as appropriate to assist in the assessment of management’s cybersecurity program and reports the results directly to the board .
+Added: As of the date of this Report, during the last three years, w e have not experienced any cybersecurity incidents that have materially impacted our business, results of operations or financial condition.
See “Item 1A.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.