10 unchanged sentences
• a security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;
+Added: OPENDOOR TECHNOLOGIES INC.
• the use of vulnerability scans and penetration testing;
2 unchanged sentences
• a robust cybersecurity incident response plan that includes documented procedures for preparing for, detecting, responding to and recovering from cybersecurity incidents, as well as processes to triage, assess severity for, escalate, contain, investigate, and remediate the incident;
−Removed: OPENDOOR TECHNOLOGIES INC.
• a third-party risk management process for service providers, suppliers, and vendors .
−Removed: We have not identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: We have experienced a limited number of immaterial cybersecurity incidents in the past, regularly experience cybersecurity attempts, and expect that we will continue to experience varying degrees of cybersecurity attempts and incidents in the future.
+Added: To date, we have not identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
However, there can be no assurance that our cybersecurity risk management program and processes, including our policies, controls, or procedures, will be fully implemented, complied with or effective in protecting our systems and information.
4 unchanged sentences
The Committee oversees management’s implementation of our cybersecurity risk management program.
−Removed: The Committee receives reports at least annually from our Chief Technology Officer and management on our cybersecurity risk management and strategy, including, as applicable, progress towards our risk-mitigation goals, results from third-party assessments, and the emerging threat landscape.
+Added: The Committee receives updates at least annually from our Chief Technology and Product Officer and management on our cybersecurity risk management and strategy, including, as applicable, progress towards our risk-mitigation goals, results from third-party assessments, and the emerging threat landscape.
In addition, management updates the Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.
1 unchanged sentence
From time to time, our Committee members receive presentations on cybersecurity topics from our internal or external experts as part of its continuing education on topics that impact public companies.
−Removed: Our Chief Technology Officer, in coordination with our Head of Security and our internal security staff, is responsible for assessing and managing our material risks from cybersecurity threats, and has primary responsibility for our overall cybersecurity risk management program and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
−Removed: Our Chief Technology Officer, who possesses a 25-year track record in overseeing technology, 15 of which includes oversight of information security systems, reports directly to our Chief Executive Officer.
−Removed: This extensive experience spans both public and private companies and includes over a decade as the dedicated key individual responsible for cybersecurity.
−Removed: Our Head of Security, who leads our internal security staff and reports directly to our Chief Technology Officer, has over 20 years of software development experience, ten of which have focused on cybersecurity, and includes managing information security systems, developing cybersecurity strategy and implementing effective information and cybersecurity programs.
−Removed: Our Chief Technology Officer and Head of Security supervise efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, and alerts and reports produced by security tools deployed in the IT environment, such as regular network and endpoint monitoring, vulnerability assessments, penetration testing, and tabletop exercises.
+Added: Our Chief Technology and Product Officer, in coordination with our internal security staff, is responsible for assessing and managing our material risks from cybersecurity threats, and has primary responsibility for our overall cybersecurity risk management program and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Our Chief Technology and Product Officer, who possesses a 20-year track record in product development and engineering, eight years of which consist of overseeing technology, including the oversight of information security systems, reports directly to our Chief Executive Officer.
+Added: This extensive experience spans both public and private companies.
+Added: Our Chief Technology and Product Officer supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, and alerts and reports produced by security tools deployed in the IT environment, such as regular network and endpoint monitoring, vulnerability assessments, penetration testing, and tabletop exercises.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.