2 unchanged sentences
Cybersecurity
−Removed: recognize the critical importance of maintaining the safety and security of our systems and data and have a process for overseeing and
−Removed: managing cybersecurity and related risks.
−Removed: This process is supported by both management, as well as our Board of Directors and our Science
−Removed: and Technology Committee.
−Removed: The current chair of our Science and Technology Committee is a National Association of Corporate Directors
−Removed: (“NACD”) certified cybersecurity expert.
−Removed: Board of Directors is responsible for overseeing our enterprise risk management activities in general, and each of our Board committees
−Removed: assists the Board in the role of risk oversight .
−Removed: The full Board receives an update on the Company’s risk management process and
−Removed: the risk trends related to cybersecurity at least annually .
−Removed: Science and Technology Committee specifically assists the Board in its oversight of risks related to cybersecurity.
−Removed: To help ensure effective
−Removed: oversight, the Science and Technology Committee receives reports on information security and cybersecurity from the Company’s information
−Removed: technology managers at least four times a year .
−Removed: approach to cybersecurity risk management includes the following key elements:
−Removed: Multi-Layered
−Removed: Defense and Continuous Monitoring – We work to protect our computing environments and products from cybersecurity threats
−Removed: through multi-layered defenses and apply lessons learned from our defense and monitoring efforts to help prevent future attacks.
−Removed: We utilize data analytics to detect anomalies and search for cyber threats.
−Removed: We engage third-party consultants or other advisors to
−Removed: assist in assessing, identifying and/or managing cybersecurity threats.
−Removed: Risk Assessments – We conduct information security assessments before sharing or allowing the hosting of sensitive data
−Removed: in computing environments managed by third parties.
−Removed: and Awareness – We provide awareness training to our employees to help identify, avoid and mitigate cybersecurity threats.
−Removed: Our employees with network access participate periodically in required training, including phishing, spear phishing and other security
−Removed: and awareness training.
−Removed: Engagement – We review critical third-party systems at least annually, including the various System and Organizational
−Removed: Controls (“SOC”) reports or perform risk assessments.
−Removed: we have experienced cybersecurity incidents in the past, to date none have materially affected the Company or our financial
−Removed: position, results of operations and/or cash flows.
−Removed: We continue to invest in the cybersecurity and resiliency of our networks and to enhance
−Removed: our internal controls and processes, which are designed to help protect our systems and infrastructure, and the information they contain.
−Removed: For more information regarding the risks we face from cybersecurity threats, please see Item 1A.
+Added: recognize the critical importance of maintaining the confidentiality, integrity, and availability of our systems, products, and data.
+Added: Our cybersecurity risk management program is designed to identify, assess, and manage material risks arising from cybersecurity threats
+Added: across our U.S.
+Added: and international operations, including third-party service providers and suppliers.
+Added: The program integrates governance,
+Added: technical and administrative controls, incident response, training and awareness, and continuous improvement practices that are tailored
+Added: to our risk profile as a medical device, aerospace & defense, and industrial EMS provider.
+Added: Identification and Assessment.
+Added: employ a risk-based approach to identify and assess cybersecurity threats, including threat-intelligence monitoring, vulnerability management,
+Added: security logging and analytics, and periodic security testing (e.g., penetration tests and tabletop exercises).
+Added: Cybersecurity risks are
+Added: recorded in our enterprise risk register with likelihood and impact scoring and are prioritized for remediation based on potential operational,
+Added: financial, regulatory, and reputational effects.
+Added: We maintain an incident response plan that defines triage, escalation, containment,
+Added: recovery, and post-incident review activities.
+Added: During incident response, management, including representatives from information technology,
+Added: legal, and executive leadership, evaluates cybersecurity incidents to determine whether an event is reasonably likely to have a material
+Added: impact on our business, strategy, financial condition, or results of operations, which informs disclosure decisions under applicable
+Added: SEC requirements.
+Added: with Strategy, Operations, and Capital Allocation.
+Added: Cybersecurity
+Added: risk considerations are incorporated into strategic planning, new program launches, capital allocation, and supplier selection.
+Added: cybersecurity controls in connection with our quality systems and regulatory commitments (including FDA QMSR/ISO 13485 and AS9100), our
+Added: participation in defense supply chains, and customer expectations for secure manufacturing and data handling.
+Added: We maintain cybersecurity
+Added: insurance coverage and periodically reassess limits and retentions in light of market conditions and our evolving risk posture.
+Added: and Supplier Risk Management.
+Added: assess cybersecurity risks associated with third-party service providers and critical suppliers through security questionnaires, contractual
+Added: requirements, and reviews of independent assurance reports (e.g., SOC reports) where available.
+Added: Data sharing with vendors and cloud platforms
+Added: is limited to business need, and we require appropriate controls, including access restrictions, encryption, and incident notification
+Added: We periodically reassess third-party risks and adjust controls as necessary .
+Added: and Awareness.
+Added: with network access participate in periodic training and simulated phishing exercises.
+Added: Role-based training is provided to personnel with
+Added: elevated privileges or access to sensitive data.
+Added: Awareness materials are refreshed to reflect current threat trends.
+Added: and Oversight.
+Added: Board of Directors oversees enterprise risk management, including cybersecurity risk.
+Added: The Audit Committee assists the Board in its oversight
+Added: of cybersecurity matters and receives cybersecurity updates from management at least quarterly, including updates on the Company’s
+Added: cybersecurity risk posture, program initiatives, and significant cybersecurity incidents, if any.
+Added: The full Board receives periodic briefings
+Added: on cybersecurity risk management.
+Added: cybersecurity program is led by the Vice President of Information Technology, who is responsible for day-to-day cybersecurity risk
+Added: management activities, including policy governance, control implementation, security monitoring, incident response, and vendor risk
+Added: management, and reports to Chief Executive Officer.
+Added: The individual responsible for leading the cybersecurity program has over
+Added: 10 years of experience in information technology, cybersecurity, and risk management, including experience in regulated
+Added: manufacturing and defense supply chains, and holds relevant professional certifications.
+Added: Cross-functional
+Added: leaders from Operations, Quality/Regulatory, Supply Chain, and Legal participate in cybersecurity governance and incident response activities.
+Added: Incidents and Program Improvements.
+Added: many companies, we have experienced cybersecurity incidents in the past.
+Added: To date, none have had a material impact on our business, financial
+Added: condition, or results of operations.
+Added: Lessons learned from past events have informed enhancements to controls, user awareness, logging
+Added: and monitoring, and incident response processes.
+Added: Supply Chain and CMMC Compliance.
+Added: participate in the U.S.
+Added: Department of Defense (“DoD”) supply chain, including handling Federal Contract Information and,
+Added: for certain programs, Controlled Unclassified Information (CUI).
+Added: On October 23, 2025, we obtained a Cybersecurity Maturity Model Certification
+Added: (“CMMC”) Level 2 certification via an authorized C3PAO, applicable to the systems within our assessed boundary that process
+Added: Beginning November 10, 2025, DoD CMMC rule phases in requirements for Level 1 or Level 2 compliance in solicitations, with increasing
+Added: reliance on third-party assessments over a staged rollout.
+Added: We maintain the technical and procedural controls necessary for Level 2 and
+Added: manage ongoing compliance through evidence maintenance, annual affirmations, and timely updates to the Supplier Performance Risk System,
+Added: as applicable.
+Added: Non-compliance could limit our eligibility for certain defense contracts;
+Added: therefore, we monitor and remediate any issues
+Added: promptly, including through Plans of Action and Milestones where permitted.
+Added: and Other Regulatory Linkages.
+Added: locations supporting defense customers operate in an ITAR-compliant manner.
+Added: Our cybersecurity controls, including access control,
+Added: network segmentation, encryption, and data-loss prevention, among others, support our ITAR compliance program and align with our quality
+Added: systems for regulated manufacturing.
+Added: more information regarding the risks we face from cybersecurity threats, please see Item 1A.
“Risk Factors.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.