9 unchanged sentences
As part of the ERM process, the Audit Committee provides input on key risks for the Company to consider.
−Removed: In addition, the Board also provides quarterly input on its views regarding potential emerging risk areas for the Company.
+Added: The Board also provides quarterly input on its views regarding potential emerging risk areas for the Company.
The Audit Committee then reports to the full Board on a quarterly basis regarding its oversight activities and the risk management activities of the Company.
−Removed: In addition, the full Board receives periodic presentations from management on emerging information security and cybersecurity risks, as well as incident reports as significant matters may arise.
+Added: In addition, the full Board periodically participates in cybersecurity-related table-top exercises and receives incident reports from the SIRT (as defined herein) as significant matters may arise .
Enterprise Risk Management
−Removed: Omnicell utilizes a structured, biannual ERM process to identify, assess, and address material risks facing the Company, including cybersecurity risks, during which business leaders across the Company are surveyed about current and emerging risk areas.
−Removed: After the ERM survey is completed and risk areas are identified, the results are discussed with the relevant management personnel across the organization in the key risk areas, root causes are analyzed and risk mitigation plans are developed.
−Removed: The Chief Information Officer works closely with Omnicell’s management team in all facets of its ERM risk mitigation activities related to cybersecurity and information security risks.
+Added: The Company utilizes a structured, biannual ERM process to identify, assess, and address material risks facing the Company, including cybersecurity risks, during which business leaders across the Company are surveyed about current and emerging risk areas.
+Added: After the ERM survey is completed and risk areas are identified, the results are discussed with the relevant management personnel across the organization in the key risk areas, root causes are analyzed, risk mitigation plans are developed, and key risk indicators are utilized to monitor mitigation efforts.
+Added: The Chief Information Officer works closely with the Company’s management team in all facets of its ERM risk mitigation activities related to cybersecurity and information security risks.
Ongoing Mitigation Efforts
4 unchanged sentences
The Company’s solutions incorporate cybersecurity features that are routinely analyzed.
−Removed: In addition, the Company maintains insurance that includes coverage for cyber-attacks, which coverage is discussed and reviewed with the Audit Committee annually.
+Added: In addition, the Company maintains insurance that responds to cyber-attacks, which coverage limit and cost is discussed and reviewed with the Audit Committee annually.
The Company has what it believes are appropriate physical, technical, and administrative controls in place that are designed to protect customers’ data.
−Removed: However, as previously disclosed, on May 4, 2022, the Company determined that certain of its information technology systems were affected by ransomware impacting certain internal systems.
−Removed: Upon detecting the security event, the Company took immediate steps designed to contain the incident and implement its business continuity plans to restore and support continued operations.
−Removed: Subsequently, the Company contained the incident and restored substantially all of its critical information technology systems.
−Removed: Following this cybersecurity event, the Company immediately implemented several key learnings from the incident, including using a three-pronged approach focused on further reducing exposure, raising greater security awareness, and further strengthening the Company’s cybersecurity defenses.
+Added: The Company uses a three-pronged approach focused on further reducing exposure, raising greater security awareness, and further strengthening the Company’s cybersecurity defenses.
This approach resulted in the Company further hardening its identity computing environments as part of its progress to a zero trust environment, heightened cybersecurity awareness efforts through increased comprehensive information security awareness training for employees on a quarterly basis , and the strengthening of the Company’s cybersecurity defenses through implementation of multifactor authentication for Privileged Access Management and Endpoint Detection and Response solutions across the Company’s computing environment.
Incident Response
−Removed: In the event of a cybersecurity incident, dependent upon the nature of the incident, the Company has a Security Incident Response Team (“SIRT”) that is comprised of employees who have responsibility and authority to act during a cyber incident without delay, including, dependent upon the nature of the incident, the Company’s Chief Legal Officer, Chief
−Removed: Information Security Officer and Chief Information Officer.
+Added: In the event of a cybersecurity incident, dependent upon the nature of the incident, the Company has a Security Incident Response Team (“SIRT”) that is comprised of employees who have responsibility and authority to act during a cyber incident without delay, including, dependent upon the nature of the incident, the Company’s Chief Legal Officer, Chief Information Security Officer and Chief Information Officer.
The SIRT includes individuals responsible for assessing, containing, and responding to incidents, as well as those responsible for assessing the business and legal impacts, reporting incidents as appropriate, communicating to internal and external stakeholders, and engaging with industry and government response partners to coordinate information and resource sharing when needed.
−Removed: During a cybersecurity incident, as warranted, the SIRT keeps the Company’s senior leadership and Board apprised of the response to the incident, any operational or business impacts, and any internal or external communications regarding the incident.
+Added: During a cybersecurity incident, as warranted, the SIRT keeps the Company’s senior leadership and Board apprised of the response to the incident, any material operational or
+Added: business impacts, and any material internal or external communications regarding the incident.
The SIRT will also seek the input of the Company’s senior leadership and Board, as needed, when addressing a cybersecurity incident.
4 unchanged sentences
He holds a Bachelor of Science in Computer Science and Engineering from Andhra University in India and an MBA from the Indian School of Business.
−Removed: In addition, the Company has recently engaged a Chief Information Security Officer (“CISO”).
−Removed: The Company’s CISO has built and managed world-class information security programs and technology teams for industry leading global companies.
+Added: In addition, the Company has engaged a Chief Information Security Officer (“CISO”) that has built and managed world-class information security programs and technology teams for industry leading global companies.
She has deep experience securing healthcare-focused companies in both the provider and supplier space.
4 unchanged sentences
The Company and its personnel also actively engage with a number of other key vendors, industry participants and intelligence and law enforcement communities as part of its information security and cybersecurity efforts.
−Removed: Impact of Recent Cyber Incident
−Removed: While the previously disclosed ransomware incident led to (i) temporarily delayed invoicing that impacted the timing of cash collections and free cash flow in 2022 and (ii) customer implementation delays in 2022, as the Company recovered from the impacts of the ransomware incident, substantially all delayed implementations due to the ransomware incident were completed as of the end 2022.
−Removed: Furthermore, any delayed or impacted processes have returned to normal operations.
−Removed: To date, the Company does not believe the ransomware incident, or other identified cyber risks, have had, or will have, a material adverse effect on its business, operating results, cash flow, or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.