3 unchanged sentences
Risk Management and Strategy
−Removed: face various cyber risks, including, but not limited to, risks related to unauthorized access, misuse, data theft, computer viruses,
−Removed: system disruptions, ransomware, malicious software and other intrusions.
−Removed: We utilize a multilayered, proactive approach to identify, evaluate,
−Removed: mitigate and prevent potential cyber and information security threats through our cybersecurity risk management program.
−Removed: Our cybersecurity
−Removed: risk management program is designed to identify, assess, prioritize and mitigate risks across the organization to enhance our resilience
−Removed: and support the achievement of our strategic objectives.
−Removed: This integrated approach helps ensure that cyber risks are not viewed in isolation,
−Removed: but are assessed, prioritized and managed in alignment with the Company’s operational, financial and strategic risks, assisting
−Removed: the Company in more effectively managing interdependencies among risks and enhancing risk mitigation strategies.
+Added: face various cyber risks, including, but not limited to, risks related to unauthorized access, misuse, customer data theft, computer
+Added: viruses, system disruptions, ransomware, malicious software and other intrusions.
+Added: We utilize a multilayered, proactive approach to identify,
+Added: evaluate, mitigate and prevent potential cyber and information security threats through our cybersecurity risk management program 24/7.
+Added: Our cybersecurity risk management program is designed to identify, assess, prioritize and mitigate risks across the organization to enhance
+Added: our resilience and support the achievement of our strategic objectives.
+Added: This integrated approach helps ensure that cyber risks are not
+Added: viewed in isolation, but are assessed, prioritized and managed in alignment with the Company’s operational, financial and strategic
+Added: risks, assisting the Company in more effectively managing interdependencies among risks and enhancing risk mitigation strategies.
devote resources to protecting the security of our computer systems, software, networks and other technology assets.
Our efforts are
−Removed: designed to adapt with the evolution of information security risks and appropriate best practices and include physical, administrative
+Added: designed to adapt to the evolution of information security risks and appropriate best practices and include physical, administrative
and technical safeguards.
3 unchanged sentences
investigation and remediation of incidents, as well as complying with applicable legal obligations, communicated promptly and effectively.
−Removed: internal audit team assesses the effectiveness of our internal controls relating to cybersecurity.
−Removed: Our management team also engages,
−Removed: at times when needed, certain outside advisors and consultants to assist in the identification, oversight, evaluation and management
−Removed: of cybersecurity risks, as well as to advise on specific topics.
−Removed: As part of our overall risk mitigation strategy, the Company also maintains
−Removed: cyber insurance coverage;
−Removed: however, such insurance may not be sufficient in type or amount to cover us against claims related to security
−Removed: breaches, cyberattacks and other related breaches.
+Added: internal audit team assesses regularly the effectiveness of our internal controls relating to cybersecurity and updates as necessary.
+Added: Our management team also engages, at times when needed, certain outside advisors and consultants to assist in the identification, oversight,
+Added: evaluation and management of cybersecurity risks, as well as to advise on specific topics.
+Added: As part of our overall risk mitigation strategy,
+Added: the Company also maintains cyber insurance coverage;
+Added: however, such insurance may not be sufficient in type or amount to cover us against
+Added: claims related to security breaches, cyberattacks and other related breaches.
have various processes and procedures in place to evaluate cybersecurity threats associated with third parties.
8 unchanged sentences
enterprise-wide cybersecurity strategy, policy, standards, architecture and processes .
−Removed: Our current SMIS received his Bachelors in Computer
−Removed: Sciences and has over 20 years of cybersecurity experience, including relevant prior senior leadership experience at our companies.
−Removed: he has also achieved globally recognized information security certifications, including CISSP (Certified Information Systems Security
−Removed: Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CRISC (Certified in Risk
−Removed: and Information Systems Control), CompTIA Security+, ISO 27001 Lead Auditor, CEH (Certified Ethical Hacker), CHFI (Computer Hacking Forensic
−Removed: Investigator), among others.
+Added: Our current SMIS received his bachelor’s
+Added: in computer sciences and has over 20 years of cybersecurity experience, including relevant prior senior leadership experience at our
+Added: Furthermore, he has also achieved globally recognized information security certifications, including CISSP (Certified Information
+Added: Systems Security Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CRISC (Certified
+Added: in Risk and Information Systems Control), CompTIA Security+, ISO 27001 Lead Auditor, CEH (Certified Ethical Hacker), CHFI (Computer Hacking
+Added: Forensic Investigator), among others .
SMIS attends and is invited to all Company Cybersecurity Committee meetings, a cross-functional management committee that drives awareness,
14 unchanged sentences
committee s promptly informed by SMIS’s team of cybersecurity incidents that could adversely affect the Company or its information
−Removed: systems and is also regularly updated about incidents with lesser impact potential.
+Added: systems and is also regularly updated about incidents with less impact potential.
The Board of Directors and Audit committee are informed
of any incidents that could adversely affect the Company by the Cybersecurity committee and SMIS’s team .
−Removed: an effort to detect and defend against cyber threats, the Company annually provides its employees with various cybersecurity and data
+Added: an effort to detect and defend against cyber threats, the Company annually, and, periodically as needed, provides its employees with various cybersecurity and data
protection training programs.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.