2 unchanged sentences
The Company maintains a comprehensive information security and cybersecurity program (the “Cybersecurity Program”) guided by established best practice and tailored to the Company’s business needs.
−Removed: The Cybersecurity Program is an extension of the Company’s enterprise risk management program that seeks to identify and manage risks throughout the Company by having its Chief Financial Officer meet with members of each of the Company’s various departments annually to solicit feedback regarding risks affecting the Company, which is then reported to the audit committee of our board of directors.
−Removed: Under the Cybersecurity Program, systems and networks under Company control are monitored for anomalies using various security tools that identify potential cybersecurity threats and alert the Company’s internal cybersecurity team to suspicious activity.
−Removed: If a potential cybersecurity incident is identified, it is investigated by the Company’s internal cybersecurity team (including the Company’s Chief Information Security Officer (the “CISO”)) to assess whether a cybersecurity incident has occurred, its severity and the risk involved, in accordance with internal processes and procedures and the Company’s incident response plan.
+Added: The Cybersecurity Program is an extension of the Company’s enterprise risk management program that seeks to identify and manage risks throughout the Company by
+Added: having its Chief Financial Officer meet with members of each of the Company’s various departments annually to solicit feedback regarding risks affecting the Company, which is then reported to the audit committee of our board of directors.
+Added: Under the Cybersecurity Program, systems and networks under Company control are monitored for anomalies using various security tools (including artificial intelligence-assisted tools) that identify potential cybersecurity threats and alert the Company’s internal cybersecurity team to suspicious activity.
+Added: If a potential cybersecurity incident is identified, it is investigated by the Company’s internal cybersecurity team (including the Company’s Chief Information Security Officer and Senior Director, Cybersecurity (together, the “CISO”) to assess whether a cybersecurity incident has occurred, its severity and the risk involved, in accordance with internal processes and procedures and the Company’s incident response plan.
The CISO is responsible for management of these cybersecurity processes, and reports to the Company’s Chief Information Officer (the “CIO”), who reports to the Company’s Chief Technology Officer (the “CTO”).
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.