7 unchanged sentences
To defend, detect and respond to cybersecurity incidents, we, among other things:
−Removed: conduct proactive cybersecurity reviews of systems and applications, perform penetration testing using external third-party tools and techniques to test security controls, conduct employee training, monitor emerging laws and regulations related to data protection and information security and implement appropriate changes.
+Added: conduct proactive cybersecurity reviews of systems and applications, perform penetration testing using external third-party tools and techniques to test security controls, conduct employee training, utilize an expert third party to continuously monitor and respond to possible threats, monitor emerging laws and regulations related to data protection and information security and implement appropriate changes.
+Added: We regularly collaborate with leading security providers, industry groups, and industry peers to exchange information on trends and best practices to address new and evolving cybersecurity risks.
We have implemented incident response processes which have four overarching and interconnected stages:
4 unchanged sentences
We also conduct tabletop exercises to simulate responses to cybersecurity incidents.
−Removed: Our team of cybersecurity professionals then collaborate with technical and business stakeholders across our business units to further analyze the risk to the company, and form detection, mitigation and remediation strategies.
+Added: Our team of cybersecurity professionals then collaborates with technical and business stakeholders across our business units to further analyze the risk to the Company, and form detection, mitigation and remediation strategies.
As part of the above processes, we regularly engage external auditors and subject matter experts to assess our internal cybersecurity programs and compliance with applicable practices and standards.
7 unchanged sentences
As of the date of this Form 10-K, no risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: For more information on the cybersecurity risks we face that could adversely impact us, please see “Part I, Item IA - Risk Factors - If our network security measures are breached and unauthorized access is obtained to a customer’s data, to our data,
−Removed: or to our information technology systems, we may incur significant legal and financial exposure and liabilities and may experience disruptions in our operations”.
+Added: For more information on the cybersecurity risks we face that could adversely impact us, please see “Part I, Item IA - Risk Factors - If our network security measures are breached and unauthorized access is obtained to a customer’s data, to our data, or to our information technology systems, we may incur significant legal and financial exposure and liabilities and may experience disruptions in our operations”.
Cybersecurity Governance
1 unchanged sentence
At least annually, the Vice President of IT presents the Company’s information security policies and programs to the Board .
−Removed: Our Audit Committee is tasked with overseeing the risks from cybersecurity threats.
+Added: Our Audit Committee is tasked with overseeing risks from cybersecurity threats.
Members of the Audit Committee receive updates on cybersecurity matters on a quarterly basis from one or more representatives from the Company’s Cyber Security Council (“CSC”), which is composed of our business unit general managers, other members of senior management, our Vice President of IT and our IT Security Manager.
4 unchanged sentences
We have also established a process whereby potentially material cybersecurity incidents are escalated to a Cybersecurity Disclosure Committee (“CDC”) consisting of our CEO, CFO, Vice President and General Counsel, Vice President of IT and Corporate Controller.
−Removed: The Cybersecurity Disclosure Committee is tasked with evaluating whether such incidents have material impact on the Company, and thus require disclosure, as well as any other actions that may be appropriate in response to the incident.
−Removed: The CDC promptly notifies the Audit Committee if it determines that an incident is likely to have a material impact on the Company and updates the Audit Committee on a quarterly basis of any incidents that it determined were not material.
+Added: The CDC is tasked with evaluating whether such incidents have material impact on the Company, and thus require disclosure, as well as any other actions that may be appropriate in response to the incident.
+Added: The CDC promptly notifies the Audit Committee if it determines that an incident is likely to have a material impact on the Company and updates the Audit Committee on a quarterly basis of any incidents that it has evaluated and determined were not material.
The Vice President of IT acts as our head of information security in leading our information security organization.
−Removed: Our VP of IT has over 20 years of industry experience, including serving in similar roles leading and overseeing cybersecurity programs at other public companies.
−Removed: Team members who support our information security program have relevant educational and industry experience, including holding similar positions at large technology companies.
+Added: Our Vice President of IT has over 25 years of industry experience leading large technology organizations, including, most recently, as the leader of the IT organization at a large privately held company.
+Added: Team members who support our information security program have relevant educational and industry experience, including holding similar positions at other technology companies.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.