16 unchanged sentences
· Prioritize risks based on their potential severity, likelihood, and detectability.
+Added: · Continuous improvement of our information technology hardware and software infrastructure including operating systems, network services, and encryption security protocols.
· Controls to mitigate risks, including access controls, data protection, data backups , redundant systems, and incident response plans.
9 unchanged sentences
· Written incident response plans.
−Removed: · Regular cybersecurity reporting to the Audit Committee.
+Added: · Regular cybersecurity reporting to the Audit Committee of our Board of Directors.
We have a full-time information technology specialist who reports directly to our CEO and is responsible for assessing and managing cybersecurity risks.
Both our information technology specialist and our CEO have extensive experience managing our cybersecurity.
−Removed: We have not engaged third-party service providers for cybersecurity, because we believe it is better to have the expertise in-house.
+Added: In the past year we also added a full-time information technology t echnician to help maintain and secure our infrastructure.
+Added: We have not engaged third-party service providers for cybersecurity because we believe it is preferable to have expertise in-house.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.