12 unchanged sentences
legal and financial risk.
−Removed: The Company has policies and procedures in place to ensure compliance with its cybersecurity program and cybersecurity
−Removed: Our program relies on a philosophy of continuous improvement by using periodic self-assessments, 3 rd party assessments,
−Removed: and customer/agency audits to determine cyber control presence, applicability, and effectiveness.
−Removed: Our program is customized with additional
−Removed: controls that address financial systems risk, nuclear quality assurance, Sarbanes Oxley, European Union cyber and data protection requirements,
−Removed: and supply chain risks.
+Added: The Company has policies and
+Added: procedures in place to ensure compliance with its cybersecurity program and cybersecurity controls.
+Added: program relies on a philosophy of continuous improvement by using periodic self-assessments, 3 rd party assessments, and customer/agency
+Added: audits to determine cyber control presence, applicability, and effectiveness.
+Added: program is customized with additional controls that address financial systems risk, nuclear quality assurance, Sarbanes Oxley, European
+Added: Union cyber and data protection requirements, and supply chain risks.
risk management process addresses confidentiality, availability, and integrity and includes evaluating information systems specific threats,
11 unchanged sentences
implement new methods or controls for reducing risk associated with a particular emerging threat or vulnerability.
−Removed: Company’s cybersecurity program is managed by the Vice President (“VP”) of IS, who has been employed by the Company
−Removed: for 20 years and has over 35 years of total experience in information systems.
−Removed: The VP of IS has an extensive career in software development
−Removed: and infrastructure management including working with Fortune 500 companies in his prior positions.
−Removed: The VP of information system is a
−Removed: participant in the overall Company strategic process and has aligned the program to best service the strategic objectives of the business.
+Added: Company’s cybersecurity program is managed by the Vice President (“VP”) of Information Systems, who has been employed
+Added: by the Company for 21 years and has over 36 years of total experience in information systems.
+Added: The VP of Information Systems has an extensive
+Added: career in software development and infrastructure management including working with Fortune 500 companies in his prior positions.
+Added: VP of information Systems is a participant in the overall Company strategic process and has aligned the program to best service the strategic
+Added: objectives of the business.
Cybersecurity
6 unchanged sentences
incidents and related responses.
−Removed: Our Board is also engaged in discussion with senior management and the Audit Committee at least on a
−Removed: quarterly basis on cybersecurity matters to discuss any updates to our cybersecurity risk management and strategy program.
−Removed: of our Board has a working knowledge and/or experience with cybersecurity, IT strategy and IT risk assessment.
−Removed: the past 2 years, the Company does not believe that it has experienced any material cybersecurity incidents, nor any material costs related
−Removed: to immaterial cyber incidents.
−Removed: Although we have a comprehensive process for the prevention of material cybersecurity incidents as discussed,
−Removed: we cannot provide assurance that our results of operations and financial condition and business strategy will not be materially impacted
−Removed: from cybersecurity risks in the future.
−Removed: For more information on our cybersecurity related risk and potential effects on the Company of
−Removed: a material cybersecurity breach, see under “General Risk Factors” in “Item 1A.
+Added: Our Board is also engaged in discussion with senior management and the Audit Committee on at least a
+Added: quarterly basis to discuss any updates to our cybersecurity risk management and strategy program.
+Added: Each member of our Board has a working
+Added: knowledge and/or experience with cybersecurity, IT strategy and IT risk assessment.
+Added: the past two years, the Company does not believe that it has experienced any material cybersecurity incidents, nor any material costs
+Added: related to immaterial cyber incidents.
+Added: Although we have a comprehensive process for the prevention of material cybersecurity incidents
+Added: as discussed, we cannot provide assurance that our results of operations and financial condition and business strategy will not be materially
+Added: impacted from cybersecurity risks in the future.
+Added: For more information on our cybersecurity related risk and potential effects on the
+Added: Company of a material cybersecurity breach, see under “General Risk Factors” in “Item 1A.
Risk Factors”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.