2 unchanged sentences
CYBERSECURITY
+Added: Board and Audit Committee Oversight
Our Board of Directors oversees our risk management process, including risks from cybersecurity threats.
−Removed: Our Board of Directors reviews strategic risk exposure, and members of our management are responsible for addressing the material risks we face on a day-to-day basis.
−Removed: Our Board of Directors administers its cybersecurity risk oversight function directly as a whole as well as through our Audit Committee.
−Removed: Our Board and our Audit Committee receive updates from time to time from our management as appropriate on cybersecurity.
−Removed: Our Chief Financial Officer and our Information Technology department are primarily responsible to assess and manage material risks from cybersecurity threats and oversee key cybersecurity policies and processes.
−Removed: They are informed about policies and processes to monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents.
−Removed: Our Global IT Director has 20 years of experience in the design, implementation, and support of information technology infrastructures .
+Added: The Board administers its cybersecurity risk oversight function directly and through the Audit Committee.
+Added: The Board and Audit Committee receive quarterly updates from management, including reports from our Global IT Director, regarding cybersecurity risks, mitigation efforts, and any significant incidents or vulnerabilities identified.
+Added: These updates include assessments of the effectiveness of our cybersecurity controls and recommendations for improvements.
+Added: Our Chief Financial Officer and Information Technology department are primarily responsible for assessing and managing material risks from cybersecurity threats and overseeing key cybersecurity policies and processes.
+Added: Our Global IT Director leads the day-to-day management of cybersecurity risk and has over 20 years of experience in the design, implementation, and support of information technology infrastructure and security systems.
+Added: Management regularly evaluates cybersecurity risks and reports significant findings to senior management and the Board of Directors.
Network and information systems and other technologies play an important role in our business activities.
4 unchanged sentences
Our hardware and software systems are equipped with technology intended to offer access and intrusion protection, software and communications systems protections, and mitigate cybersecurity threats.
−Removed: We have established policies and processes for assessing, identifying, and managing material risk from cybersecurity threats, and have integrated these processes into our overall risk management systems and processes.
−Removed: We routinely assess material risks from cybersecurity threats, including any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or any information maintained in them.
+Added: Incident Response and Materiality Assessment
+Added: We maintain a formal incident response plan that outlines procedures for detecting, containing, investigating, and remediating cybersecurity incidents.
+Added: This plan includes escalation protocols to senior management and the Board , as appropriate.
+Added: We assess the materiality of any cybersecurity incident based on its potential impact on our operations, financial condition, and reputation, in accordance with SEC guidance.
+Added: To date, no cybersecurity incidents have had a material impact on the Company’s business, operations, or financial results.
+Added: Risk Management Processes
We utilize industry standard software packages such as RSA and Cisco Firepower to secure our networks.
−Removed: We conduct regular risk assessments to identify cybersecurity threats.
−Removed: These risk assessments include identifying reasonably foreseeable potential internal and external risks, the likelihood of occurrence and any potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, controls, and other safeguards in place to manage such risks.
−Removed: As part of our risk management process, we may engage third party experts to help identify and assess risks from cybersecurity threats.
−Removed: For example, we perform penetration tests, data recovery testing, security audits and risk assessments throughout the year.
−Removed: We hold online cybersecurity training for our employees.
−Removed: Our risk management process also encompasses cybersecurity risks associated with our use of third-party service providers .
−Removed: Following these risk assessments, we design, implement, and maintain safeguards intended to minimize the identified risks;
−Removed: address any identified gaps in existing safeguards;
−Removed: update existing safeguards as necessary;
−Removed: and monitor the effectiveness of our safeguards.
−Removed: While we develop and maintain protocols, controls, and systems, that seek to prevent cybersecurity incidents from occurring, we must constantly monitor and update these protocols, controls, and systems in the face of sophisticated and rapidly evolving attempts to overcome them.
−Removed: The occurrence of cybersecurity incidents could cause a variety of material adverse impacts on our business, although no such incident has had any such impact to date.
−Removed: F or additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this report, including the risk factor entitled “Security breaches and other disruptions to our information technology infrastructure could interfere with our operations and expose us to liability.” and Item 1, “Business – Environmental and Other Regulations - Safety Management System Requirements” in this report.
+Added: We also hold online cybersecurity training for our employees.
+Added: Our cybersecurity risk management processes are integrated into our enterprise risk management framework and include regular risk assessments, vulnerability scans, and penetration testing.
+Added: We prioritize risks based on their likelihood and potential impact, and implement mitigation strategies accordingly.
+Added: Management reviews the results of these assessments and reports significant findings and remediation actions to the Board and Audit Committee.
+Added: Third-Party Risk Management
+Added: We evaluate cybersecurity risks associated with third-party service providers through initial and ongoing security assessments, contractual requirements for data protection, and continuous monitoring of their cybersecurity practices.
+Added: Any significant risks or incidents involving third-party providers are promptly reported to management and, if material, to the Board and Audit Committee.
+Added: Reference to Risk Factors
+Added: For a more detailed discussion of risks related to cybersecurity threats, including potential impacts and mitigation strategies, please refer to Item 1A, ‘Risk Factors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.