8 unchanged sentences
We rely on a multidisciplinary team, including our information security function, outside legal counsel, management, and third-party service providers, as described further below, to identify, assess, and manage cybersecurity threats and risks.
−Removed: These processes include, among other things, annual security awareness training for employees, programs to increase awareness of phishing attempts, tools to detect and monitor unusual network activity, and processes to contain, escalate and respond to incidents.
+Added: These processes include, among other things, annual security awareness training for employees, instituting programs to increase awareness of phishing attempts, tools to detect and monitor unusual network activity, and processes to contain, escalate and respond to incidents.
In addition, we have an enterprise Information Security Policy describing our cybersecurity program and governance structure and the processes and procedures in place to identify, mitigate and remediate cybersecurity threats and risks.
3 unchanged sentences
We decided to retain a third party for these services given the small size of our Company and internal information technology staff and the quality, comprehensiveness, and cost-effectiveness of the services offered.
−Removed: An internal team, led by our Vice President of Information Technology, who has over 30 years’ of experience in IT security matters, oversees and works collaboratively with this third-party vendor to evaluate the strength of our cybersecurity protocols and the results of testing to determine what additional actions, such as trainings or remedial actions, are necessary to lessen cybersecurity risks.
+Added: An internal team, led by our Senior Vice President of Information Technology , who has extensive years of experience in IT security matters , oversees and works collaboratively with this third-party vendor to evaluate the strength of our cybersecurity protocols and the results of testing to determine what additional actions, such as trainings or remedial actions, are necessary to lessen cybersecurity risks.
Third Party Risk Management
1 unchanged sentence
We require our third-party providers to meet appropriate security requirements and controls prior to providing access to our internal systems, and investigate and report any security incidents, as appropriate.
−Removed: Based on the information available as of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats, including as a result of any cybersecurity incidents, which have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
+Added: Based on the information available as of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats, which have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
Despite our security measures, however, there can be no assurance that we, or the third parties with which we interact, will not experience a cybersecurity incident in the future that will materially affect us.
4 unchanged sentences
The AC is responsible for overseeing our enterprise risk management program, including material risks related to cybersecurity threats.
−Removed: The AC receives regular updates from management, including the information technology and legal teams, on cybersecurity risk resulting from risk assessments and reviews any information on relevant internal and industry cybersecurity incidents and is notified between such updates relative to any incidents which could materially affect the Company.
−Removed: Based on this information, our AC monitors the Company's cybersecurity program, including potential threats, weaknesses and vulnerabilities, and reviews the policies and procedures in place to prevent, detect and respond to cybersecurity threats and unauthorized access to our information security systems.
+Added: The AC receives quarterly reports from management, including the information technology and legal teams, on cybersecurity risk resulting from risk assessments and reviews any information on relevant internal and industry cybersecurity incidents and is notified between such updates relative to any incidents which could materially affect the Company.
+Added: Based on this information, our AC monitors the Company's cybersecurity program, including potential threats, weaknesses and vulnerabilities, the policies and procedures in place to prevent, detect and respond to cybersecurity threats and unauthorized access to our information security systems.
Significant findings related to cybersecurity, data and technology risks or incidents are at least annually reported to and discussed with the Board of Directors.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.