4 unchanged sentences
This approach includes regular evaluations of our information systems and infrastructure to identify vulnerabilities and potential weaknesses through the use of system monitoring tools, as well as monitoring industry trends, threat intelligence, and emerging risks to anticipate and proactively assess potential threats.
−Removed: We engage third-party cybersecurity experts to conduct penetration testing, vulnerability scans, and risk assessments, informed by the NIST (National Institute of Standards and Technology) Cybersecurity Framework guidelines, to increase the likelihood that system risks are identified.
−Removed: To identify potential risks, Ambac also assesses the security measures of vendors and third-party service providers that have access to the Company’s information systems and sensitive data.
+Added: We engage third-party cybersecurity experts to conduct penetration testing, vulnerability scans, and risk assessments, informed by the NIST (National Institute of Standards and Technology) Cybersecurity Framework guidelines or ISO (International Organization for Standardization) 27001 standard, to increase the likelihood that system risks are identified.
+Added: To identify potential risks, Ambac or a third party vendor engaged by the Company also assesses the security measures of vendors and third-party service providers that have access to the Company’s information systems and sensitive data.
Each review involves an initial risk assessment of the provider, and initial and periodic reviews of the provider's cybersecurity program to evaluate security standards, access controls and security measures.
8 unchanged sentences
updates on information systems;
−Removed: and any cybersecurity threats of which management
−Removed: Ambac Financial Group, Inc 25
−Removed: 2023 Form 10-K
−Removed: Table of Contents ,
−Removed: has become aware.
+Added: and any cybersecurity threats of which management has become aware.
In addition the Board receives periodic cybersecurity awareness training.
−Removed: The Company’s technology staff and CISO conduct weekly meetings, attended regularly by the Chief Operating Officer and Chief Information Officer, to review:
+Added: The Company’s technology staff and CISO conduct weekly meetings to review:
(i) implementation of new security measures, (ii) results of existing technical system monitoring tools to identify any potential risk and propose remediation, as necessary;
3 unchanged sentences
The Company’s Chief Operating Officer and Chief Information Officer provide input and updates to the Enterprise Risk Committee (comprised of members of management) on cybersecurity preparedness and emerging risks.
−Removed: The Enterprise Risk Committee produces the relevant risk management information for executive and senior management and the Board of Directors, which receives ERM updates on a quarterly basis.
+Added: The Enterprise Risk Committee produces the relevant risk management information for executive and senior management and the Board
+Added: Ambac Financial Group, Inc.
+Added: 2024 Form 10-K
+Added: Table of Contents ,
+Added: of Directors, which receives ERM updates on a quarterly basis.
The Chief Operating Officer and Chief Information Officer are also members of the Company's Disclosure Committee and provide updates on cybersecurity threats and emerging risks to the Disclosure Committee prior to the filing of each quarterly report on Form 10-Q and annual report on Form 10-K.
7 unchanged sentences
For example, the National Association of Insurance Commissioners (“NAIC”) adopted the NAIC Insurance Data Security Model Law (#668) (“NAIC Model Law”) that creates rules for insurers and other covered entities addressing data security and the investigation and notification of cybersecurity events involving unauthorized access to, or the misuse of, certain nonpublic information.
−Removed: includes maintaining an information security program based on ongoing risk assessment, overseeing third-party service providers, investigating data breaches and notifying regulators of a cybersecurity event.
+Added: This includes maintaining an information security program based on ongoing risk assessment, overseeing third-party service providers, investigating data breaches and notifying regulators of a cybersecurity event.
Legislation based on the NAIC Model Law has been enacted in many states and may be enacted in other states.
2 unchanged sentences
Recent amendments to the NYDFS cybersecurity regulation impose additional security requirements and new governance obligations.
−Removed: The California Consumer Privacy Act, went into effect in January 2020, and provides additional privacy rights for California residents, and in November 2020, California further expanded privacy rights for California residents by enacting the California Privacy Rights Act, which became effective January 1, 2023.
+Added: The California Consumer Privacy Act, went into effect in January 2020, and provides additional privacy rights for
+Added: California residents, and in November 2020, California further expanded privacy rights for California residents by enacting the California Privacy Rights Act, which became effective January 1, 2023.
Several other states have enacted similar comprehensive privacy laws.
3 unchanged sentences
Xchange specializes in accident and health insurance and is a business associate of the health insurers carriers it partners with, making it subject to compliance with the provisions of HITECH and HIPAA applicable to business associates.
+Added: In the United Kingdom, data protection is governed by the UK General Data Protection Regulation 2016/679 and the UK Data Protection Act of 2018 (together the “UK GDPR”), which requires companies to manage the access and transfer of personal information of UK residents.
+Added: The Company’s affiliates licensed and doing business in the UK are subject to compliance with the provisions of the UK GDPR.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.