8 unchanged sentences
We rely on a multidisciplinary team, including our information security function, outside legal counsel, management, and third-party service providers, as described further below, to identify, assess, and manage cybersecurity threats and risks.
−Removed: These processes include, among other things, annual security awareness training for employees, instituting programs to increase awareness of phishing attempts, tools to detect and monitor unusual network activity, and processes to contain, escalate and respond to incidents.
+Added: These processes include, among other things, quarterly security awareness training for employees, instituting programs to increase awareness of phishing attempts, multi-layered tools to detect and monitor unusual network activity, and processes to contain, escalate and respond to incidents.
In addition, we have an enterprise Information Security Policy describing our cybersecurity program and governance structure and the processes and procedures in place to identify, mitigate and remediate cybersecurity threats and risks.
2 unchanged sentences
They provide cybersecurity risk assessment and threat intelligence to the Company, in addition to acting as a managed service provider for our information technology program.
−Removed: We decided to retain a third party for these services given the small size of our Company and internal information technology staff and the quality, comprehensiveness, and cost-effectiveness of the services offered.
−Removed: An internal team, led by our Senior Vice President of Information Technology , who has extensive years of experience in IT security matters , oversees and works collaboratively with this third-party vendor to evaluate the strength of our cybersecurity protocols and the results of testing to determine what additional actions, such as trainings or remedial actions, are necessary to lessen cybersecurity risks.
+Added: While third-party providers contribute specialized resources and around-the-clock monitoring capabilities, responsibility for the Company’s cybersecurity strategy, risk management and decision-making remains with the internal IT team.
+Added: Led by our Vice President of Information Technology , who has extensive experience in information security and technology risk management , the internal team works closely with these partners to evaluate cybersecurity risks, review testing and assessment results, prioritize remediation efforts and implement security improvements to lessen cybersecurity risk.
+Added: This cost-effective partnership model enables the Company to leverage external expertise while maintaining strong internal oversight, accountability and alignment with business objectives.
+Added: By combining internal knowledge of the Company’s operations with specialized third-part capabilities, the Company has established a comprehensive cybersecurity program designed to identify, assess, manage and mitigate cybersecurity risk.
Third Party Risk Management
−Removed: We also monitor and manage cybersecurity risks associated with our third-party service providers, including our managed security service provider, suppliers, customers and vendors, though, among other things, the processes set forth in our policies and procedures, due diligence processes, regular oversight, monitoring and auditing of our relationships by internal staff, supplier codes of conduct and escalation practices for reporting issues.
+Added: We also monitor and manage cybersecurity risks associated with our third-party service providers , including our managed security service provider, system support vendors and other critical relationships, among other things, the processes set forth in our policies and procedures, due diligence processes, regular oversight, monitoring and auditing of our relationships by internal staff, supplier codes of conduct and escalation practices for reporting issues.
We require our third-party providers to meet appropriate security requirements and controls prior to providing access to our internal systems, and investigate and report any security incidents, as appropriate.
11 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.