8 unchanged sentences
As one of the critical elements of the Company’s overall risk management and compliance approach, the Company’s cybersecurity program is focused on the following key areas:
−Removed: The Board’s oversight of cybersecurity risk management is led by the Audit Committee of the Board, which regularly interacts with our Chief Compliance Officer, our Executive Director of IT, and other members of management.
+Added: The board of directors’ oversight of cybersecurity risk management is led by the Audit Committee of the board of directors, which regularly interacts with our Chief Compliance Officer, our Chief Financial Officer, and other members of management.
Collaborative Approach :
11 unchanged sentences
These efforts include a wide range of activities, including audits, assessments, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: The results of such assessments, audits and reviews are reported to the Audit Committee and the Board, and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
−Removed: The Board, with leadership from the Audit Committee, oversees our cybersecurity risk management process.
+Added: The results of such assessments, audits and reviews are reported to the Audit Committee and the board of directors, and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
+Added: The board of directors, with leadership from the Audit Committee, oversees our cybersecurity risk management process.
The Audit Committee receives regular presentations and reports on cybersecurity risks, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
The board of directors and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: On a periodic basis, the board of directors, through the Audit Committee, discuss our approach to cybersecurity risk management with the Executive Director of IT.
−Removed: Our Executive Director of IT, in coordination with our executive management team, works collaboratively across the Company to implement a program designed to protect our information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with our incident response and recovery plans.
−Removed: Through ongoing communications with our entire employee base and appropriate third-party contractors, the Executive Director of IT and the management team monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
−Removed: Our Executive Director of IT has over 28 years of experience in leading IT teams and managing cybersecurity in several industries including biotech, media and consumer products.
−Removed: He has hands-on experience as an IT network engineer and systems administrator, configuring and hardening systems against security threats.
−Removed: In addition, he has previously held executive-level leadership IT roles.
−Removed: Throughout his career, he has kept abreast of new developments in cybersecurity and has implemented industry standards to secure IT infrastructure and systems.
−Removed: He works closely with the Company’s IT managed service provider to assess all security incidents and events and escalate as needed.
+Added: On a periodic basis, the board of directors, through the Audit Committee, discuss our approach to cybersecurity risk management with management.
+Added: Our management team has implemented a program designed to protect our information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with our incident response and recovery plans.
+Added: Through ongoing communications with our entire employee base and appropriate third-party contractors, the management team monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
+Added: Our enterprise risk management team consists of cross-functional professionals who collaborate with subject matter specialists, as necessary, including an independent third-party expert we have retained to identify and assess material risks from cybersecurity threats, their severity, and potential mitigation steps.
+Added: Our Chief Financial Officer, Kathleen Borthwick, currently serves as our Chief Cybersecurity Officer and leads our cybersecurity risk assessment and management processes.
+Added: Prior to being named CFO, Ms.
+Added: Borthwick served as the Company’s Senior Vice President, Finance, and interim CFO.
+Added: She is supported by external Information Technology and third-party internal audit personnel who regularly review and assess cybersecurity initiatives, including our incident response plan, as well as cybersecurity compliance, training, and risk management efforts.
No cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to affect us, including our business strategy, results of operations or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.