4 unchanged sentences
These risks include, among other things, operational risks, intellectual property theft, fraud, extortion, harm to employees or customers, violation of privacy or security laws and other litigation and legal risk, and reputational risks.
−Removed: We have implemented several cybersecurity processes, technologies, and controls to aid in our efforts to assess, identify, and manage such material risks.
+Added: We have implemented several cybersecurity processes, technologies, and controls in an effort to assess, identify, and manage such material risks.
Our process for identifying and assessing material risks from cybersecurity threats operates alongside our broader overall risk assessment process, covering all company risks.
1 unchanged sentence
We also have a cybersecurity specific risk assessment process, which helps identify our cybersecurity threat risks.
−Removed: As part of this process, and our processes to provide for the availability of critical data and systems, maintain regulatory compliance, identify and manage our risks from cybersecurity threats, and to protect against, detect, and respond to cybersecurity incidents, as such term is defined in Item 106(a) of Regulation S-K, we undertake the below listed activities, among others:
−Removed: ● maintain a risk register and risk assessment process based on The National Institute of Standards and Technology (“NIST”) Cybersecurity Framework;
+Added: As part of this process, and our processes aimed at providing for the availability of critical data and systems, maintaining regulatory compliance, identifying and managing our risks from cybersecurity threats, and protecting against, detecting, and responding to cybersecurity incidents, as such term is defined in Item 106(a) of Regulation S-K, we undertake the below listed activities, among others:
+Added: ● maintain a risk register and risk assessment process based on The National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (however, this does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST Cybersecurity Framework as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business);
● use various third-party software testing products and services designed to test and assess the security of our software;
19 unchanged sentences
We also maintain disaster recovery plans in place for all mission critical parts of the business, although we do not have a business continuity plan developed to account for all continuity risks.
−Removed: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the headings “We are exposed to risks related to information technology infrastructure, information management and protection, cybersecurity threats, and cyber incidents.” and “Our business is subject to evolving corporate governance and public disclosure regulations and expectations, including with respect to environmental, social and governance matters that could expose us to numerous risks.” included as part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K.
−Removed: For more than 5 years, we have not experienced any material cybersecurity incidents and the expenses we have incurred from cybersecurity incidents were immaterial.
+Added: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the headings “We, and our third-party service providers, are exposed to risks related to information technology infrastructure, information management and protection, cybersecurity threats, and cyber incident;
+Added: if we or our third-party providers fail to protect confidential information and/or experience a cyber incident, there may be damage to our brand and reputation, material financial penalties, and legal liability.” and “Our business is subject to evolving corporate governance and public disclosure regulations and expectations, including with respect to environmental, social and governance matters that could expose us to numerous risks.” included as part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K.
+Added: For more than 5 years, we have not identified any known cybersecurity threats including as a result of any prior cybersecurity incidents, that have materially impacted us, including the expenses we have incurred from cybersecurity incidents that were immaterial.
This includes penalties and settlements, of which there were none.
+Added: We face risks from
+Added: cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
Cybersecurity Governance
8 unchanged sentences
The Audit Committee, which comprises at least two individuals with experience in cybersecurity and related matters, meets with these members of senior management to review our information technology and data security policies and practices, and to assess current and projected threats, cybersecurity incidents, and related risks.
−Removed: Our Vice President of Operations reports directly to our executive management team and advises the company on cybersecurity risks and assesses the effectiveness of information technology and data security processes and business policies impacting our overall cybersecurity risk.
+Added: Our Vice President of Operations reports directly to our executive management team and advises the company on cybersecurity risks and assesses the effectiveness of information technology and information security processes and business policies impacting our overall cybersecurity risk.
Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Vice President of Operations and a cross section of subject matter experts from Information Technology, Exensio Cloud Operations and Corporate Legal and team.
1 unchanged sentence
Our Incident Response Policy is reviewed annually and documents the controls and procedures for timely and accurate reporting of material cybersecurity incidents to the relevant parties, including the Audit Committee when applicable.
−Removed: Our Incident Response Team leads the response to any reported cybersecurity event and comprises experts from Engineering, Information Technology, Legal, Cloud Operations, and Data Security.
+Added: Our Incident Response Team leads the response to any reported cybersecurity event and comprises experts from Engineering, Information Technology, Legal, Cloud Operations, and Network Security.
The Vice President of Operations and Executive Vice President of Products and Solutions are informed about and monitor the prevention, mitigation, detection, and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above including the incident response.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.