5 unchanged sentences
In general, our Adviser seeks to address cybersecurity risks of the Company through a comprehensive, cross-functional approach that is focused on continually assessing the Company’s information systems to detect, prevent and mitigate cybersecurity threats and effectively respond to cybersecurity incidents when they occur.
−Removed: As one of the critical elements of the Company’s overall risk management, our Adviser’s cybersecurity program is focused on the following key areas:
−Removed: The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which interacts with our Adviser’s Director of Information Technology and Chief Compliance Officer and other members of management of our Adviser that implement and oversee our Adviser’s cybersecurity program.
+Added: As one of the critical elements of the Company’s overall risk management, our cybersecurity program is focused on the following key areas:
+Added: The Board’s oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the “Audit Committee”), which interacts with our Adviser’s Director of Information Technology and other members of management of our Adviser that implement and oversee our Adviser’s cybersecurity program.
Risk Assessment:
5 unchanged sentences
Incident Response and Recovery Planning:
−Removed: Our Adviser has established and maintains comprehensive business continuity plans that address potential impacts should the information or technology systems become compromised, and such plans are tested and evaluated on a regular basis.
+Added: Our Adviser has established and maintains comprehensive business continuity plans that address potential impacts should the information or technology systems become compromised, and the technological components of such plans are tested and evaluated on a regular basis.
Third-Party Risk Management:
3 unchanged sentences
Our Adviser engages in the periodic assessment and testing of our Adviser’s policies, standards, processes and practices that are designed to address the Company’s cybersecurity threats and incidents.
−Removed: These efforts include a wide range of activities, including annual penetration and third-party compliance testing and ongoing internal testing and creation and modification of policies and procedures.
+Added: These efforts include a wide range of activities, including annual penetration and third-party compliance testing and ongoing internal testing and
+Added: creation and modification of policies and procedures.
The results of the annual assessments are reported to the Audit Committee and the Board, and our Adviser adjusts its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments and ongoing testing.
2 unchanged sentences
The Audit Committee also receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: basis, the Board and the Audit Committee discuss the Company’s approach to cybersecurity risk management with our Adviser, including the Adviser’s Director of Information Technology.
+Added: On an annual basis, the Board and the Audit Committee discuss the Company’s approach to cybersecurity risk management with our Adviser, including the Adviser’s Director of Information Technology.
The Adviser’s Director of Information Technology, in coordination with relevant senior management and personnel of the Adviser, which includes our Adviser’s Chief Financial Officer, Senior Infrastructure Engineer, and Chief Compliance Officer, work to conceive, implement, and monitor the effectiveness of a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any security incidents in accordance with the Company’s business continuity plan.
5 unchanged sentences
Combined, our Adviser’s information technology team has over 50 years of experience covering all major aspects of network architecture and management.
−Removed: Cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
+Added: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and we do not believe are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
However, the risk of cybersecurity threats could be significant if the cyber-attack disrupts the Company’s critical operations, service or financial systems.
−Removed: See “Risk Factors - We depend on information systems, and systems failures could significantly disrupt our business, which may, in turn, negatively affect our ability to pay dividends to our stockholders”.
+Added: See “Risk Factors - We are highly dependent on information technology and security breaches or systems failures could significantly disrupt our business, which may, in turn, negatively affect the market price of our securities and our ability to pay distributions”.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.