2 unchanged sentences
The Company is exposed to diverse cybersecurity risks that have the potential to significantly impact our business operations, financial standing, and reputation.
−Removed: We seek to identify, assess, and manage these risks, with the aim of safeguarding our critical systems and information, and employ a documented process to respond in the event of a cybersecurity incident.
−Removed: This approach includes regular evaluations of our information systems and infrastructure to identify vulnerabilities and potential weaknesses through the use of system monitoring tools, as well as monitoring industry trends, threat intelligence, and emerging risks to anticipate and proactively assess potential threats.
+Added: We seek to identify, assess, and manage these risks, with the aim of safeguarding our critical systems and information and employing a documented process to respond in the event of a cybersecurity incident.
+Added: This approach includes regular evaluations of our information
+Added: systems and infrastructure to identify vulnerabilities and potential weaknesses through the use of system monitoring tools, as well as monitoring of industry trends, threat intelligence, and emerging risks to anticipate and proactively assess potential threats.
We engage third-party cybersecurity experts to conduct penetration testing, vulnerability scans, and risk assessments, informed by the NIST (National Institute of Standards and Technology) Cybersecurity Framework guidelines or ISO (International Organization for Standardization) 27001 standard, to increase the likelihood that system risks are identified.
−Removed: To identify potential risks, Ambac or a third party vendor engaged by the Company also assesses the security measures of vendors and third-party service providers that have access to the Company’s information systems and sensitive data.
+Added: To identify potential risks, Octave or a third party vendor engaged by the Company also assesses the security measures of vendors and third-party service providers that have access to the Company’s information systems and sensitive data.
Each review involves an initial risk assessment of the provider and initial and periodic reviews of the provider's cybersecurity program to evaluate security standards, access controls and security measures.
2 unchanged sentences
We conduct mandatory annual employee cybersecurity training programs and frequent simulated phishing campaigns to enhance cybersecurity knowledge and practices across the organization.
−Removed: Ambac maintains an incident response plan that is updated regularly to respond to changes in the organization, risks and laws.
−Removed: Ambac also conducts an annual test to restore business critical systems and data from back-ups.
+Added: Octave maintains an incident response plan that is updated regularly to respond to changes in the organization, risks and laws.
+Added: Octave also conducts an annual test to restore business critical systems and data from back-ups.
We have established reporting processes and escalation pathways for our business units and functions to identify, assess and manage potential cybersecurity incidents in a timely manner.
4 unchanged sentences
In addition the Board receives periodic cybersecurity awareness training.
−Removed: The Company’s technology staff and CISO conduct weekly meetings to review:
−Removed: (i) implementation of new security measures, (ii) results of existing technical system monitoring tools to identify any potential risk and propose remediation, as necessary;
−Removed: (iii) newly disclosed software patch updates to assess risks and set patch implementation priorities;
−Removed: and (iv) threat intelligence from various organizations, such as the Cybersecurity and Infrastructure Security Agency, to assess risks and suggest security measures, as necessary.
−Removed: Cybersecurity risk is also included in the Company’s Enterprise Risk Management (“ERM”) process that involves senior management and other personnel in the identification, assessment and management of a broad range of risks (including cybersecurity risks) that could affect the Company’s ability to execute on its corporate strategy and fulfill its business objectives.
−Removed: The Company’s Chief Operating Officer and Chief Information Officer provide input and updates to the Enterprise Risk Committee (comprised of members of management) on cybersecurity preparedness and emerging risks.
−Removed: The Enterprise Risk Committee produces the relevant risk management information for executive and senior management and the Board
−Removed: Ambac Financial Group, Inc.
+Added: The CISO conducts weekly meetings with the Chief Information Officer, and as necessary with the Enterprise Architecture Committee, to discuss the implementation of new cybersecurity measures.
+Added: Identified cybersecurity risks and newly disclosed software patch updates are escalated, as appropriate, for further assessment and remediation in accordance with the Company’s vulnerability management procedures.
+Added: The CISO also receives ongoing cybersecurity threat intelligence from external sources, including government and industry organizations such as the
+Added: Octave Specialty Group, Inc.
2025 Form 10-K
Table of Contents ,
−Removed: of Directors, which receives ERM updates on a quarterly basis.
+Added: Cybersecurity and Infrastructure Security Agency, which is used to inform the Company’s cybersecurity risk assessment and mitigation efforts.
+Added: Cybersecurity risk is also included in the Company’s Enterprise Risk Management (“ERM”) process that involves senior management and other personnel in the identification, assessment and management of a broad range of risks (including cybersecurity risks) that could affect the Company’s ability to execute on its corporate strategy and fulfill its business objectives.
+Added: The Company’s Chief Operating Officer and Chief Information Officer provide input and updates to the Enterprise Risk Committee (comprised of members of management) on cybersecurity preparedness and emerging risks.
+Added: The Enterprise Risk Committee produces the relevant risk management information for executive and senior management and the Board of Directors, which receives ERM updates on a quarterly basis.
The Chief Operating Officer and Chief Information Officer are also members of the Company's Disclosure Committee and provide updates on cybersecurity threats and emerging risks to the Disclosure Committee prior to the filing of each quarterly report on Form 10-Q and annual report on Form 10-K.
3 unchanged sentences
He holds an active ISO/ANSI-accredited cybersecurity certification and has experience managing security programs across multiple industries, including financial services and insurance.
−Removed: Other credentials among Ambac’s IT staff include a Certified Information Systems Security Professional certification and a Masters Degree in cybersecurity risk and management.
−Removed: Ambac and its subsidiaries are subject to various U.S.
+Added: Octave and its subsidiaries are subject to various U.S.
federal and state laws and regulations with respect to privacy, data protection and cybersecurity that require financial institutions, including insurance companies and agencies, to safeguard personal and other sensitive information, and may provide for notice of their practices relating to the collection, disclosure and processing of personal information, disclosure of cybersecurity risk management practices, reporting of cybersecurity incidents, and implementation of governance practices.
−Removed: For example, the National Association of Insurance Commissioners (“NAIC”) adopted the NAIC Insurance Data Security Model Law (#668) (“NAIC Model Law”) that creates rules for insurers and other covered entities addressing data security and the investigation and notification of cybersecurity events involving unauthorized access to, or the misuse of, certain nonpublic information.
+Added: For example, the NAIC adopted the NAIC Insurance Data Security Model Law (#668) (“NAIC Model Law”) that creates rules for insurers and other covered entities addressing data security and the investigation and notification of cybersecurity events involving unauthorized access to, or the misuse of, certain nonpublic information.
This includes maintaining an information security program based on ongoing risk assessment, overseeing third-party service providers, investigating data breaches and notifying regulators of a cybersecurity event.
1 unchanged sentence
Certain of our subsidiaries, as insurance companies and agencies licensed in the State of New York, are also required to comply with the New York Department of Financial Services (“NYDFS”) cybersecurity regulation, which establishes requirements for covered financial services institutions to implement a cybersecurity program designed to protect the confidentiality, integrity and availability of information systems of regulated entities, and information stored on those systems.
−Removed: The regulation imposes a governance framework for cybersecurity program, risk based minimum standards for technology systems for data protection, monitoring and testing, third-party service provider reviews, security incident response and reporting to NYDFS of certain security incidents, annual certifications of regulatory compliance to NYDFS, and other requirements.
+Added: The regulation imposes a governance
+Added: framework for cybersecurity programs, risk-based minimum standards for technology systems for data protection, monitoring and testing, third-party service provider reviews, security incident response and reporting to NYDFS of certain security incidents, annual certifications of regulatory compliance to NYDFS, and other requirements.
Recent amendments to the NYDFS cybersecurity regulation impose additional security requirements and new governance obligations.
−Removed: The California Consumer Privacy Act, went into effect in January 2020, and provides additional privacy rights for
−Removed: California residents, and in November 2020, California further expanded privacy rights for California residents by enacting the California Privacy Rights Act, which became effective January 1, 2023.
+Added: In the United States, portions of our business are subject to state laws that impose obligations with respect to personal information and grant consumers specific rights with respect to such information, For example, the California Consumer Privacy Act, went into effect in January 2020, and provides additional privacy rights for California residents, and in November 2020, California further expanded privacy rights for California residents by enacting the California Privacy Rights Act, which became effective January 1, 2023.
Several other states have enacted similar comprehensive privacy laws.
−Removed: We anticipate federal and state regulators to continue to enact legislation related to privacy and cybersecurity, which may require additional compliance investments and changes to policies, procedures and operations.
+Added: We anticipate that federal and state regulators will continue to enact legislation related to privacy and cybersecurity, which may require additional compliance investments and changes to policies, procedures and operations.
The federal Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”) impose minimum standards on covered entities, such as health insurers, for the privacy and security of protected health information (“PHI”).
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.