12 unchanged sentences
• Cybersecurity Training and Awareness:
−Removed: All employees and contractors are required to receive semi-annual cybersecurity awareness training.
−Removed: Employees also receive training in response to drills and simulated attacks.
+Added: All employees and contractors are required to complete semi-annual cybersecurity awareness training.
+Added: We also conduct periodic drills and simulated attacks—including simulated phishing exercises and other social-engineering tests—to reinforce training, evaluate user response, and assess the effectiveness of our cybersecurity controls.
+Added: Employees who do not successfully complete these exercises are required to undergo additional, targeted training to address identified gaps and strengthen overall security readiness.
• Access Controls:
−Removed: Users are provided with access consistent with the principle of least privilege, which requires that users be given no more access than necessary to complete their job functions.
+Added: We endeavor to limit users' access to no more than necessary to complete their job functions.
A multi-factor authentication process has been implemented for employees accessing company information.
• Encryption and Data Protection:
−Removed: Encryption methods are used to protect sensitive data in transit and at rest.
+Added: We endeavor to use appropriate encryption methods to protect sensitive data.
This includes the encryption of customer data, financial information, and other confidential data.
9 unchanged sentences
Impact of Risks from Cybersecurity Threats
−Removed: As of the date of this report, though the Company and its third-party service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity threats that have materially affected or are reasonably likely to materially affect our business, financial condition, results of operations or cash flows.
+Added: As of the date of this report, though the Company and its third-party service providers have experienced certain cybersecurity incidents, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business, financial condition, results of operations or cash flows.
However, we acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains.
Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cyberattack will not occur.
−Removed: A successful attack on our information technology (“IT”) systems could have significant consequences to the business.
+Added: A successful attack on our information or operational technology systems could have significant consequences to the business.
While we devote resources to our security measures to protect our systems and information, these measures cannot provide absolute security.
No security measure is infallible.
−Removed: See “Risk Factors” for additional information about the risks to our business associated with a breach or compromise to our IT systems.
+Added: See “Risk Factors” for additional information about the risks to our business associated with a breach or compromise of our information or operational technology systems.
Board of Directors’ Oversight and Management’s Role
−Removed: Through the Company’s enterprise risk management program, the Board of Directors is responsible for overseeing cybersecurity, information security, and information technology risks, as well as management’s actions to identify, assess, mitigate, and remediate those risks.
−Removed: As part of its program of regular risk oversight, the Audit Committee assists the Board in exercising oversight of the Company’s cybersecurity, information security, and information technology risks.
+Added: Through the Company’s enterprise risk management program, the Board of Directors is responsible for overseeing cybersecurity, information security, and information and operational technology risks, as well as management’s actions to identify, assess, mitigate, and remediate those risks.
+Added: As part of its program of regular risk oversight, the Audit Committee assists the Board in exercising oversight of the Company’s cybersecurity, information security, and information and operational technology risks.
The Board or Audit Committee regularly reviews and discusses with management the Company’s policies, procedures and practices with respect to cybersecurity, information security and information and operational technology, including related risks.
1 unchanged sentence
Recognizing the importance of cybersecurity to the success and resilience of our business, the Board considers cybersecurity to be a vital aspect of corporate governance.
−Removed: To facilitate effective oversight, our cybersecurity leadership team holds discussions on cybersecurity risks, incident trends, and the effectiveness of cybersecurity measures as necessitated by emerging material cyber risks.
−Removed: Our cybersecurity leadership team is made up of highly experienced professionals with a background in information security, risk management, and incident response.
−Removed: This background includes leading and developing cyber security operations and incident response programs for business organizations, developing comprehensive cyber security strategies, and managing complex cybersecurity projects across various industries.
+Added: To facilitate effective oversight, our Information Systems team holds discussions on cybersecurity risks, incident trends, and the effectiveness of cybersecurity measures as necessitated by emerging material cyber risks.
+Added: Management is responsible for assessing, identifying, and managing risks from cybersecurity threats.
+Added: Our cybersecurity risk management efforts are led by our Information Systems team, including our Director of Information Systems , who has worked in the information systems field for over 15 years and has lead our Information Systems team for over 10 years.
+Added: Our Director of Information Systems oversees our cybersecurity activities and is informed about and monitors the prevention, detection, mitigation and remediation of cybersecurity incidents.
+Added: Our Information Systems team is made up of highly experienced professionals with a background in information security, risk management, and incident response.
+Added: This background includes leading and developing cyber security operations and incident response programs for business organizations, developing comprehensive cyber security strategies, and managing complex cyber security projects across various industries.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.