5 unchanged sentences
The program is integrated within our enterprise risk management system and addresses our IT networks and related systems that are essential to the operation of our business.
−Removed: We maintain controls and procedures, including third-party oversight procedures, and cybersecurity training for all employees on an annual basis, which are designed to ensure prompt escalation of cybersecurity incidents so that decisions regarding public disclosure and reporting of such incidents can be made by management in a timely manner.
+Added: We maintain controls and procedures, including third-party oversight procedures, and cybersecurity training for all employees on an annual basis.
We work with third parties that assist us to identify, assess, and manage cybersecurity risks, including professional services firms, consulting firms, threat intelligence service providers, and penetration testing firms.
5 unchanged sentences
Cybersecurity Governance
−Removed: The Board of Directors considers cybersecurity risk as part of its risk oversight function , and the Audit Committee of our Board oversees Realty Income's cybersecurity and other information technology risk exposures and the steps taken by management to monitor and control such exposures.
+Added: The Board of Directors considers cybersecurity risk as part of its risk oversight function, and the Audit Committee of our Board of Directors oversees Realty Income's cybersecurity and other information technology risk exposures and the steps taken by management to monitor and control such exposures.
Our cybersecurity risk profile and cybersecurity program status are reported to the Audit Committee on a quarterly basis.
−Removed: In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.
−Removed: The Audit Committee reports to the full Board regarding its activities, including those related to cybersecurity, and the full Board also receives briefings from management on our cybersecurity risk management program, as appropriate.
−Removed: Our management team, including the Cybersecurity Risk Committee chaired by our Head of IT and comprised of executive leaders across the Company, provides oversight, direction and guidance related to the cybersecurity risk management decisions and is responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: The team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
−Removed: Our management team has extensive experience implementing and operating cybersecurity technologies, policies, and procedures throughout various industries and includes a Certified Information Systems Security Professional with ISC2.
−Removed: Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel;
+Added: In addition, management updates the Audit Committee, as necessary, regarding any significant cybersecurity incidents, as well as any incidents with lesser impact potential.
+Added: The Audit Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity, and the full Board of Directors also receives briefings from management on our cybersecurity risk management program, as appropriate.
+Added: Our Senior Vice President of Information Technology is primarily responsible for assessing and managing our material risks from cybersecurity threats, including our overall cybersecurity risk management program, and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Our Senior Vice President of Information Technology has served in IT roles for the Company since 2007, and has led the department since 2020.
+Added: He has over 20 years of experience implementing and operating cybersecurity technologies, policies, and procedures throughout various industries.
+Added: Our Senior Vice President of Information Technology works closely with our management team to keep them informed about and to monitor the Company’s efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel;
threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us;
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.