8 unchanged sentences
The Company maintains processes and systems with an aim to preventing any such attack from disrupting its services to clients as well as to prevent any loss of data concerning its clients, their financial affairs, as well as Company privileged information.
−Removed: Our management is actively involved in the oversight of our cybersecurity risk management program, We have devoted significant financial and personnel resources to implement and maintain security measures to meet regulatory requirements and customer expectations.
+Added: Our management is actively involved in the oversight of our cybersecurity risk management program.
+Added: We have devoted significant financial and personnel resources to implement and maintain security measures to meet regulatory requirements and customer expectations.
We have incorporated cybersecurity processes to assess, identify and manage risks from cybersecurity threats into our overall risk assessment process.
5 unchanged sentences
• we engage third-party cybersecurity firms and tools to assist with network monitoring, endpoint protection, vulnerability assessments and penetration testing;
−Removed: • we engage cyber security consultants, auditors, and other third parties to assess and enhance our cybersecurity practices, such as to perform tabletop exercises and evaluate our cyber processes including an assessment of our incident response procedures.
+Added: • we engage cyber security consultants and auditors to perform tabletop exercises and evaluate our cyber processes including an assessment of our incident response procedures.
Identified risks are formally tracked until mitigated or eliminated;
4 unchanged sentences
The incident response plan includes standard processes for reporting and escalating cybersecurity incidents to senior management.
−Removed: We have processes to evaluate third party service providers and vendors that have access to sensitive systems and Company and customer data, which may include the use of cybersecurity questionnaires and due diligence procedures such as assessments of that service provider’s cybersecurity posture.
+Added: We have processes to evaluate third party service providers and vendors that have access to sensitive systems and Company and customer data, which does include the use of cybersecurity questionnaires and due diligence procedures such as assessments of that service provider’s cybersecurity posture .
Management’s Role
1 unchanged sentence
The Company has a dedicated cybersecurity organization within its technology department that focuses on current and emerging cybersecurity matters.
−Removed: The Company’s cybersecurity function is led by the Company’s CIO and the Company’s CISO, who reports to the Company’s CIO.
+Added: The Company’s cybersecurity function is led by the Company’s Chief Information Officer ("CIO") and the Company’s Chief Information Security Officer ("CISO") , who reports to the Company’s CIO.
The CIO and his direct reports, including the CISO, discuss action items related to risks at a standing monthly meeting.
7 unchanged sentences
In particular, the Audit Committee assists the Board in its oversight of management’s responsibility to assess, manage and mitigate cybersecurity risks.
+Added: Recently the Audit Committee added a member with significant cybersecurity experience.
The Audit Committee receives a cybersecurity update at each regular meeting of the Board covering cybersecurity risks, cybersecurity staffing and staff development including certifications and training.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.