3 unchanged sentences
One of our Co-Presidents is responsible for managing cybersecurity risk.
−Removed: They develop mitigation strategies and implement controls to reduce the likelihood of a cybersecurity incident occurring and to reduce the impact of such an incident should it occur.
−Removed: At least annually, they report on this risk and their mitigation work to the Audit Committee of our Board of Trustees, which is the committee that has primary responsibility for overseeing our enterprise risk management program and is composed solely of independent trustees.
+Added: He develops mitigation strategies and implements controls to reduce the likelihood of a cybersecurity incident occurring and to reduce the impact of such an incident should it occur.
+Added: At least annually, he reports on this risk and related mitigation work to the Audit Committee of our board of trustees, which is the committee that has primary responsibility for overseeing our enterprise risk management program and is composed solely of independent trustees.
The Audit Committee reviews and discusses all of our key enterprise risks, including cybersecurity risk, and the enterprise risk management program itself.
−Removed: The chair of the Audit Committee may, at their discretion, report to the Chairman of the Board or the full Board of Trustees regarding any aspect of the program or risks.
+Added: The chair of the Audit Committee may, at his discretion, report to the Chairman of the Board or the full board of trustees regarding any aspect of the program or risks.
As of December 31, 2024, no risk from cybersecurity threats, including as a result of any previous cybersecurity incident, has materially affected our business, results of operations or financial condition .
1 unchanged sentence
We maintain cybersecurity insurance coverage to mitigate our financial exposure to certain incidents, and we consult with external advisors regarding opportunities and enhancements to strengthen our policies and practices.
−Removed: We have elected to outsource our information technology function to a third-party managed service provider, or the MSP, that specializes in fully managed information technology services and fully managed cybersecurity.
+Added: We have elected to outsource our information technology function to a third-party managed service provider, ("MSP") that specializes in fully managed information technology services and fully managed cybersecurity.
The MSP is responsible for managing all of our hosted services, all of the computer and computer-related hardware and software we use, and all onsite and offsite backups.
7 unchanged sentences
While we have control, through our contract with the MSP, over our information systems, we do not have control over the information systems of our hotel managers, which are the third-party operators of our hotels and resorts, or of our franchisors.
−Removed: Although we set clear expectations of our hotel managers and franchisors, we rely on our hotel managers and franchisors for managing their cybersecurity risk.
+Added: We set clear expectations of our hotel managers and franchisors regarding cybersecurity, but we rely on our hotel managers and franchisors for managing their cybersecurity risk.
We conduct surveys of our hotel managers and franchisors to assess their cybersecurity risk management programs and procedures, to identify gaps and request remediation and to understand our risk exposure.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.