3 unchanged sentences
Securing the Company’s business information, customer, supplier, and employee data and information technology systems is an important part of our overall risk management framework.
−Removed: We rely on certain key information
−Removed: technology systems, some of which are dependent on services provided by third parties, including cloud vendors, for various business functions necessary to operate and manage our business.
−Removed: We select key third-party service providers based on
−Removed: several factors, including the type of data processed and the nature of services offered, and we oversee such key third-party service providers by conducting vendor diligence upon onboarding and ongoing monitoring, including a review of SOC-1
−Removed: reports on an annual basis.
−Removed: We have adopted processes designed to identify, assess and manage material risks from cybersecurity threats.
−Removed: Those processes include response to and an assessment of internal and external threats to the security,
−Removed: confidentiality, integrity and availability of our data and information systems, along with other material risks to our operations.
−Removed: In addition, we have implemented procedures over certain areas such as access on/off boarding and account
−Removed: management to help govern the processes put in place by management designed to protect our IT assets, data, and services from threats and vulnerabilities.
−Removed: Although, to date, we have not experienced a material cybersecurity incident resulting in a
−Removed: significant interruption of our operations, the scope of any future incident cannot be predicted with any meaningful accuracy.
+Added: We rely on certain key information technology systems, some of which are dependent on services provided by third parties, including cloud vendors, for various business functions necessary to operate and manage our business.
+Added: We select key third-party service providers based on several factors, including the type of data processed and the nature of services offered, and we oversee such key third-party service providers by conducting vendor diligence upon onboarding and ongoing monitoring, including a review of SOC-1 reports on an annual basis.
+Added: We have adopted processes, guided by the Center for Internet Security (CIS) Cybersecurity Framework, designed to identify, assess and manage material risks from cybersecurity threats.
+Added: Those processes include response to and an assessment of internal and external threats to the security, confidentiality, integrity and availability of our data and information systems, along with other material risks to our operations.
+Added: We have implemented controls, such as Multi-Factor Authentication (MFA) and endpoint detection and response (EDR) solutions, to help govern the processes put in place by management designed to protect our IT assets, data, and services from threats and vulnerabilities.
+Added: Furthermore, we maintain a formal, Incident Response Plan (IRP) and conduct mandatory, ongoing security awareness training for all employees.
+Added: Although, to date, we have not experienced a material cybersecurity incident resulting in a significant interruption of our operations, the scope of any future incident cannot be predicted with any meaningful accuracy.
See “Item 1A.
Risk Factors” for more information.
−Removed: Management is responsible for the day-to-day management of the risks we face, while our Board
−Removed: of Directors has responsibility for the oversight of risk management, including risks from cybersecurity threats.
−Removed: The cybersecurity program is led by the Company’s
−Removed: Global VP of Data Operations and Information Technology, who provides periodic updates to the Cyber Security Risk Management Committee of our Board of Directors about the program, including information about cyber risk management governance
−Removed: and the status of ongoing efforts to strengthen cybersecurity effectiveness.
−Removed: Our Board of Directors engages in ad hoc conversations with management on cybersecurity-related news events and discuss any significant updates to our
−Removed: cybersecurity risk management and initiatives.
−Removed: The Cyber Security Risk Management Committee regularly reports on its activities to the full Board to promote effective coordination and to ensure that the entire Board remains apprised of the
−Removed: effectiveness of the cybersecurity risk management and the cybersecurity risk landscape, and also assesses how management is managing these risks.
−Removed: The following table presents certain information about the Company’s photomask manufacturing facilities:
−Removed: Brookfield, Connecticut
−Removed: Bridgend, Wales
−Removed: Cheonan, Korea
−Removed: Dresden, Germany
−Removed: Hsinchu, Taiwan
−Removed: Hsinchu, Taiwan
−Removed: Taichung, Taiwan
−Removed: Xiamen, China
−Removed: (1) We own our manufacturing facilities in Hefei, Taichung, Xiamen, and one of our manufacturing facilities in Hsinchu.
−Removed: However, we lease the related land at these sites.
−Removed: We believe our facilities, with planned expansions, are adequate to
−Removed: support our current and near-term requirements.
−Removed: LEGAL PROCEEDINGS
−Removed: Please refer to Note 16 – Commitments and Contingencies to our consolidated financial statements in Part II, Item 8 of this report for information on legal proceedings
−Removed: involving the Company.
−Removed: MINE SAFETY DISCLOSURES
−Removed: Not applicable.
−Removed: MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
−Removed: (a) Market Information
−Removed: Our common stock is traded on the NASDAQ Global Select Market (“NASDAQ”) under the symbol PLAB.
−Removed: On December 12, 2024, the closing sale price of our common stock, per the NASDAQ Global Select
−Removed: Market, was $26.27.
−Removed: (b) Approximate Number of Holders of Common Stock
−Removed: Based on available information, we have 215 registered shareholders.
−Removed: (c) Dividends
−Removed: To date, we have not paid any cash dividends on Photronics shares, and, for the foreseeable future, we anticipate that earnings will continue to be retained for use in our business.
−Removed: (d) Securities Authorized for Issuance Under Equity Compensation Plans
−Removed: The information regarding our equity compensation required to be disclosed by Item 201(d) of Regulation S-K is incorporated by reference from the Photronics, Inc.
−Removed: 2025 Definitive Proxy Statement in Item 12 of Part
−Removed: III of this report.
−Removed: The 2025 Definitive Proxy Statement will be filed within 120 days after our fiscal year ended October 31, 2024.
−Removed: (e) Stock Price Performance Graph
−Removed: (f) Purchase of Equity Securities by Registrant and Affiliated Purchasers
−Removed: In September 2020, the Company’s Board of Directors authorized the repurchase of up to $100 million of its common stock, pursuant to a repurchase plan under
−Removed: Rule 10b5-1 of the Securities Act.
−Removed: The repurchase authorization by the Board of Directors has no expiration date, does not obligate us to acquire any common stock, and is subject to market conditions.
−Removed: Share repurchases under this
−Removed: authorization commenced on September 16, 2020.
−Removed: The most recent 10b5-1 plan expired on September 15, 2022, and has not been renewed.
−Removed: In 2022, we repurchased 0.2 million shares at a cost of $2.5 million (an average of $13.43 per share) and,
−Removed: since the program’s inception, we have repurchased 5.8 million shares at a cost of $68.3 million (an average of $11.70 per share).
−Removed: All shares repurchased under the program have been retired.
−Removed: On August 28, 2024, the Board of Directors authorized an increase to the Company’s existing share repurchase program from the remaining $31.7
−Removed: million up to $100 million under the Board of Director authorization.
−Removed: In 2024, we did not repurchase any further shares as part of this program.
+Added: Management is responsible for the day-to-day management of the risks we face, while our Board of Directors has ultimate responsibility for the oversight of risk management, including risks from cybersecurity threats.
+Added: The Board of Directors has delegated primary oversight of cybersecurity risk to the Cyber Security Risk Management Committee.
+Added: The Committee, in turn, ensures its members either possess or have access to relevant cybersecurity and risk management expertise to effectively challenge and guide management's program.
+Added: The Committee regularly assesses how management is managing these risks and reports on its activities to the full Board of Directors at least quarterly to promote effective coordination and ensure the entire Board remains apprised of the cybersecurity risk landscape and the program's effectiveness.
+Added: The day-to-day cybersecurity program is led by the Company’s Vice President, IT Infrastructure & Information Security.
+Added: This role is supported by a dedicated security team and reports directly to the Chief Executive Officer.
+Added: The Vice President, IT Infrastructure & Information Security provides formal, quarterly updates to the Cyber Security Risk Management Committee.
+Added: These updates cover cyber risk management governance, the status of ongoing efforts to strengthen cybersecurity effectiveness, key risk metrics and the material outcomes of risk assessments, and significant cybersecurity-related news events impacting the industry.
+Added: In addition to scheduled reports, the Board of Directors engages in ad hoc conversations with management to discuss any significant updates to our cybersecurity risk management and initiatives, particularly in response to emerging threats.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.