3 unchanged sentences
We consider cybersecurity and privacy to be important issues affecting the enterprise both in terms of reputational risk and economic risk.
−Removed: To effectively assess, identify, and manage material risks from cybersecurity threats, we maintain a cybersecurity risk management program, which is led by our Chief Technology, Logistics & Stores Officer (“CTO”) and our Vice President, Information Security & IT Risk (“VP, IT”), as a part of the Company’s overall risk management and compliance programs.
+Added: To effectively assess, identify, and manage material risks from cybersecurity threats, we maintain a cybersecurity risk management program, which is led by our Chief Technology Officer (“CTO”) and our Vice President, Information Security & IT Risk (“VP, IT”), as a part of the Company’s overall risk management and compliance programs.
To keep pace with ever-evolving threats and industry best practices, we have made, and will continue to make, sizable investments in building and developing cybersecurity talent and expertise and implementing state-of-the-art systems and tools, to detect, identify, classify and mitigate cybersecurity and other data privacy risks within our environment.
1 unchanged sentence
We conduct security and compliance assessments throughout each year to validate the efficacy of our programs and practices.
−Removed: We also engage an independent third party expert to assess our cybersecurity maturity periodically against the retail industry.
−Removed: The results of these assessments inform our cybersecurity development roadmap going forward and are presented to the Audit Committee and the Board of Directors.
+Added: We also engage an independent third party expert to assess our cybersecurity maturity periodically against the retail industry, with the latest assessment currently in process to be completed by the end of April 2026.
+Added: The results of these assessments inform our cybersecurity development roadmap going forward and are presented to the Audit Committee and the Board.
We also maintain cybersecurity insurance as part of our comprehensive insurance portfolio.
9 unchanged sentences
In addition, members of senior management participate in periodic crisis management exercises with third-party experts on crisis management best practices to apply their learnings to the Company’s business continuity management program.
−Removed: In particular, in Fiscal 2023, the table-top exercise that was conducted for senior management focused on the handling of a cyber-security incident.
+Added: In particular, in Fiscal 2023, the table-top exercise that was conducted for senior management focused on the handling of a cybersecurity incident.
Because we are aware of the risks associated with third-party service providers , we also have implemented processes to oversee and manage these risks.
9 unchanged sentences
Our Privacy Policy is available on our website and we continually assess and update this Policy to reflect industry best practices and applicable laws and regulations.
−Removed: Our Board of Directors recognizes the important role of information security and mitigating cybersecurity and other data security threats, as part of our efforts to protect and maintain the confidentiality and security of customer, employee and vendor information, as well as non-public information about our Company.
−Removed: Although the Board of Directors as a whole is ultimately responsible for the oversight of our risk management function, the Board of Directors uses its committees to assist in its risk oversight function.
−Removed: The Audit Committee of our Board of Directors has primary responsibility for our cybersecurity risk identification and mitigation activities, and that Committee and senior management provide reports regularly to the Board of Directors.
+Added: Our Board recognizes the important role of information security and mitigating cybersecurity and other data security threats, as part of our efforts to protect and maintain the confidentiality and security of customer, employee and vendor information, as well as non-public information about our Company.
+Added: Although the Board as a whole is ultimately responsible for the oversight of our risk management function, the Board uses its committees to assist in its risk oversight function.
+Added: The Audit Committee of our Board has primary responsibility for our cybersecurity risk identification and mitigation activities, and they and senior management provide reports regularly to the Board.
The Audit Committee receives periodic reports from management, including our CTO and VP, IT.
8 unchanged sentences
The Company’s management maintains and implements a written Cyber Security Incident Response Policy and Cyber Security Incident Response Plan, both of which are reviewed and updated on a periodic basis.
−Removed: In the event we identify a potential cybersecurity, privacy or other data security issue, we have defined procedures for responding to such issues, including procedures that address when and how to engage with Company management, the Audit Committee, our Board of Directors, other stakeholders and law enforcement when responding to such issues.
+Added: In the event we identify a potential cybersecurity, privacy or other data security issue, we have defined procedures for responding to such issues, including procedures that address when and how to engage with Company management, the Audit Committee, our Board, other stakeholders and law enforcement when responding to such issues.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.