2 unchanged sentences
CYBERSECURITY
−Removed: In general, the Company addresses cybersecurity risks through a comprehensive approach that is focused on preserving the security of its information and by identifying, preventing and mitigating cybersecurity threats, as well as effectively responding to cybersecurity incidents when they occur.
−Removed: The Company believes that this comprehensive approach helps to ensure that the highest levels of oversight is provided to its cybersecurity risk management activities and fosters collaborative consultation between management and the Board.
+Added: In general, the Company addresses cybersecurity risks through a comprehensive approach that is focused on preserving the security of its information, products and environments by identifying, preventing and mitigating cybersecurity threats, as well as effectively responding to cybersecurity incidents when they occur.
+Added: The Company believes that this comprehensive approach helps to ensure that the highest level of oversight is provided to its cybersecurity risk management activities and fosters collaborative consultation between management and the Board.
Board Oversight
1 unchanged sentence
In this role, the Audit Committee monitors the prevention, detection, mitigation and remediation of cybersecurity incidents through the regular receipt of reports from management on the effectiveness of its cybersecurity programs.
−Removed: These reports include semi-annual cybersecurity updates from the Company’s Chief Information Officer and quarterly reports from the Company’s risk management personnel on the progress of the Company’s broader Enterprise Risk Management (“ERM”) risk mitigation activities.
+Added: These reports include quarterly cybersecurity updates from the Company’s Chief Information Security Officer and quarterly reports from the Company’s risk management personnel on the progress of the Company’s broader Enterprise Risk Management (“ERM”) risk mitigation activities.
As part of the ERM process, the Audit Committee provides input on key risks for the Company to consider.
1 unchanged sentence
The Audit Committee then reports to the full Board on a quarterly basis regarding its oversight activities and the risk management activities of the Company.
−Removed: In addition, the full Board periodically participates in cybersecurity-related table-top exercises and receives incident reports from the SIRT (as defined herein) as significant matters may arise .
+Added: In addition, the full Board receives semiannual updates from the Chief Information Security Officer and periodically participates in cybersecurity-related tabletop exercises and receives incident reports from the SIRT (as defined herein) as significant matters may arise .
Enterprise Risk Management
−Removed: The Company utilizes a structured, biannual ERM process to identify, assess, and address material risks facing the Company, including cybersecurity risks, during which business leaders across the Company are surveyed about current and emerging risk areas.
+Added: The Company utilizes a structured, biennial ERM process to identify, assess, and address material risks facing the Company, including cybersecurity risks, during which business leaders across the Company are surveyed about current and emerging risk areas.
After the ERM survey is completed and risk areas are identified, the results are discussed with the relevant management personnel across the organization in the key risk areas, root causes are analyzed, risk mitigation plans are developed, and key risk indicators are utilized to monitor mitigation efforts.
−Removed: The Chief Information Officer works closely with the Company’s management team in all facets of its ERM risk mitigation activities related to cybersecurity and information security risks.
+Added: The Chief Information Security Officer works closely with the Company’s management team in all facets of its ERM risk mitigation activities related to cybersecurity and information security risks.
Ongoing Mitigation Efforts
1 unchanged sentence
In addition, the Company has continued its efforts to migrate its platforms to cloud-based computing, which is designed to further strengthen its security posture.
−Removed: The Company has focused on its incident response procedures and retained a leading incident response provider.
−Removed: The Company has also recently strengthened its disaster recovery procedures.
+Added: The Company has continued to focus on maturing its incident response procedures and has retained a leading cybersecurity forensic firm.
+Added: The Company also continues to strive to enhance its disaster recovery procedures.
The Company’s solutions incorporate cybersecurity features that are routinely analyzed.
3 unchanged sentences
This approach resulted in the Company further hardening its identity computing environments as part of its progress to a zero trust environment, heightened cybersecurity awareness efforts through increased comprehensive information security awareness training for employees on a quarterly basis , and the strengthening of the Company’s cybersecurity defenses through implementation of multifactor authentication for Privileged Access Management and Endpoint Detection and Response solutions across the Company’s computing environment.
+Added: Previous cybersecurity incidents have not materially affected us , including our business strategy, results of operations or financial condition.
+Added: However, risks from cybersecurity threats, including but not limited to exploitation of vulnerabilities, ransomware, denial of service, supply chain attacks, or other similar threats may materially affect us, including our execution of business strategy, reputation, results of operations and/or financial condition.
+Added: “Risk Factors - “We are subject to laws, regulations, and other legal obligations related to privacy, data protection, and information security, and the costs of compliance with, and potential liability associated with, our actual or perceived failure to comply with such obligations could
+Added: harm our business” and “Significant disruptions in our information technology systems, breaches of data security, or cyber-attacks on our systems or solutions, could adversely impact our business” for a discussion of cybersecurity risks.
Incident Response
−Removed: In the event of a cybersecurity incident, dependent upon the nature of the incident, the Company has a Security Incident Response Team (“SIRT”) that is comprised of employees who have responsibility and authority to act during a cyber incident without delay, including, dependent upon the nature of the incident, the Company’s Chief Legal Officer, Chief Information Security Officer and Chief Information Officer.
−Removed: The SIRT includes individuals responsible for assessing, containing, and responding to incidents, as well as those responsible for assessing the business and legal impacts, reporting incidents as appropriate, communicating to internal and external stakeholders, and engaging with industry and government response partners to coordinate information and resource sharing when needed.
−Removed: During a cybersecurity incident, as warranted, the SIRT keeps the Company’s senior leadership and Board apprised of the response to the incident, any material operational or
−Removed: business impacts, and any material internal or external communications regarding the incident.
+Added: In the event of a cybersecurity incident, dependent upon the nature of the incident, the Company has a Security Incident Response Team (“SIRT”) that is comprised of employees who have responsibility and authority to act during a cyber incident without delay, including, dependent upon the nature of the incident, the Company’s Chief Legal and Administrative Officer or Chief Information Security Officer.
+Added: The SIRT includes individuals responsible for assessing, containing, and responding to incidents, as well as those responsible for assessing the business and legal impacts, reporting incidents as appropriate, communicating to internal and external stakeholders, and engaging with industry and government partners to coordinate information and resource sharing when needed.
+Added: During a cybersecurity incident, as warranted, the SIRT keeps the Company’s senior leadership and Board apprised of the response to the incident, any material operational or business impacts, and any material internal or external communications regarding the incident.
The SIRT will also seek the input of the Company’s senior leadership and Board, as needed, when addressing a cybersecurity incident.
1 unchanged sentence
The Audit Committee then monitors the completion of the remediation actions and mitigation efforts.
−Removed: Cybersecurity Leaders in Management
−Removed: The Company’s IT strategy and implementation is overseen by a dedicated Chief Information Officer with over 20 years of experience in the field, including previously serving a 17-year tenure, most recently as Vice President of Global IT, with a global technology leader of fiber optic subsystems and components.
−Removed: He holds a Bachelor of Science in Computer Science and Engineering from Andhra University in India and an MBA from the Indian School of Business.
−Removed: In addition, the Company has engaged a Chief Information Security Officer (“CISO”) that has built and managed world-class information security programs and technology teams for industry leading global companies.
−Removed: She has deep experience securing healthcare-focused companies in both the provider and supplier space.
−Removed: She holds a Bachelor of Science from the University of Redlands and an MBA from Notre Dame De Namur University along with holding certified information systems security professional (“CISSP”) and certified information security manager (“CISM”) certifications.
+Added: Cybersecurity Leader
+Added: The Company’s cybersecurity strategy and implementation is overseen by a dedicated Chief Information Security Officer with over 20 years of experience in the field, having most recently served as Senior Vice President and Global Chief Information Security Officer, with a leading diversified healthcare services company where he led enterprise-wide cybersecurity strategy and governance.
+Added: He holds a Bachelor of Science from the University of Illinois Urbana-Champaign and an MBA from Northwestern University’s Kellogg School of Management.
Third Parties
The Company utilizes third-party service providers, such as cloud services, in connection with its operations, and its information security department implements a third-party risk assessment and review process in connection with those services to evaluate security posture and risk.
−Removed: The Company also engages third parties to assist in its cybersecurity management efforts, such as the leading incident response provider mentioned above and another provider to perform continuous monitoring and regular penetration testing of its information security systems and environment.
+Added: The Company also engages third parties to assist in its cybersecurity management efforts, such as the leading cybersecurity forensic firm mentioned above and another provider to perform continuous monitoring and regular penetration testing of its information security systems and environment.
The Company and its personnel also actively engage with a number of other key vendors, industry participants and intelligence and law enforcement communities as part of its information security and cybersecurity efforts.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.