16 unchanged sentences
Our team of cybersecurity professionals then collaborates with technical and business stakeholders across our business units to further analyze the risk to the Company, and form detection, mitigation and remediation strategies.
−Removed: As part of the above processes, we regularly engage external auditors and subject matter experts to assess our internal cybersecurity programs and compliance with applicable practices and standards.
−Removed: Since 2021, our Information Security Management System has been certified to conform to the requirements of ISO/IEC 27001:2013.
+Added: Our controls are informed by recognized industry standards and frameworks and are designed to address prevention, detection, and response.
+Added: Since 2021, our Information Security Management System has been certified to ISO/IEC 27001, and in the current year we achieved certification to the ISO/IEC 27001:2022 standard.
+Added: Our program includes policies and standards, identity and access management (including multi‑factor authentication where appropriate), endpoint detection and response, network security and segmentation, logging and monitoring, data protection controls, secure software development practices where applicable, and business continuity and disaster recovery planning.
+Added: Our program is also informed by elements of the NIST Cybersecurity Framework.
Our cybersecurity program also includes third-party assessments to identify and mitigate risks from third parties such as vendors, suppliers, and other business partners associated with our use of third-party service providers.
Cybersecurity risks are evaluated when determining the selection and oversight of applicable third-party service providers and potential risks when handling and/or processing our employee, business or customer data.
−Removed: In addition to new vendor onboarding, we perform risk assessments during third-party cybersecurity compromise incidents to identify and mitigate risks to us from third-party incidents.
+Added: In addition to new vendor onboarding, we have ongoing monitoring and perform risk assessments during third-party cybersecurity compromise incidents to identify and mitigate risks to us from third-party incidents.
Our individual employees also play an important role in our information security systems.
−Removed: All employees are required to familiarize themselves with the Company’s information security policies and, at least annually, employees are required to participate in an information security training program, which is designed to help employees identify potentially threats and train them on how to respond.
−Removed: Throughout the year, the IT department conducts phishing campaigns and other simulated hacking attacks with employees as a way of reminding them of their security obligations and ensuing that our SETA (security education and training awareness) has been effective.
+Added: All employees are required to familiarize themselves with the Company’s information security policies and, at least annually, employees are required to participate in an information security training program, which is designed to help employees identify potential threats and train them on how to respond.
+Added: Throughout the year, the IT department conducts simulated phishing campaigns and other simulated hacking attacks with employees as a way of reminding them of their security obligations and ensuing that our SETA (security education and training awareness) has been effective.
As of the date of this Form 10-K, no risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
4 unchanged sentences
Our Audit Committee is tasked with overseeing risks from cybersecurity threats.
−Removed: Members of the Audit Committee receive updates on cybersecurity matters on a quarterly basis from one or more representatives from the Company’s Cyber Security Council (“CSC”), which is composed of our business unit general managers, other members of senior management, our Vice President of IT and our IT Security Manager.
+Added: Members of the Audit Committee receive updates on cybersecurity matters on a quarterly basis from one or more representatives from the Company’s Cyber Security Council (“CSC”), which is composed of our Senior Executive Team, our Vice President of IT and our IT Security Director.
These updates include a discussion of existing and new cybersecurity risks (if any), updates on how management is addressing and/or mitigating those risks, and the status of information security initiatives.
2 unchanged sentences
The CSC receives regular quarterly reports from the Vice President of IT on the Company’s cybersecurity risk profile and enterprise cybersecurity program.
−Removed: We have also established a process whereby potentially material cybersecurity incidents are escalated to a Cybersecurity Disclosure Committee (“CDC”) consisting of our CEO, CFO, Vice President and General Counsel, Vice President of IT and Corporate Controller.
+Added: We have also established a process whereby potentially material cybersecurity incidents are escalated to a Cybersecurity Disclosure Committee (“CDC”) consisting of our CEO, CFO, Senior Vice President and General Counsel, Vice President of IT and Corporate Controller.
The CDC is tasked with evaluating whether such incidents have material impact on the Company, and thus require disclosure, as well as any other actions that may be appropriate in response to the incident.
2 unchanged sentences
Our Vice President of IT has over 25 years of industry experience leading large technology organizations, including, most recently, as the leader of the IT organization at a large privately held company.
−Removed: Team members who support our information security program have relevant educational and industry experience, including holding similar positions at other technology companies.
+Added: Our IT Security Director is a senior cybersecurity and IT leader with 27 years of experience across infrastructure design and architecture engineering, enterprise network engineering, and security operations.
+Added: Other team members who support our information security program have relevant educational and industry experience, including holding similar positions at other technology companies.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.