1 unchanged sentence
Cybersecurity
−Removed: Cybersecurity Risk, Strategy and Governance
The Company maintains a robust cybersecurity infrastructure to safeguard our operations, networks and data through comprehensive security measures including our technology tools, internal management and external service providers.
9 unchanged sentences
Additionally, we conduct periodic internal exercises to gauge the effectiveness of the trainings and assess the need for additional training.
−Removed: In addition, we engage independent third-party cybersecurity providers for testing and vulnerability detection.
+Added: At least annually, we engage independent third-party cybersecurity providers for testing and vulnerability detection.
We regularly engage with third-party vendors to perform external penetration testing, which identifies potential threats and reduces the impact and/or likelihood of these threats.
3 unchanged sentences
Our Board of Directors, primarily through the Audit Committee , oversees management’s approach to managing cybersecurity risks as part of its risk management oversight.
−Removed: The Audit Committee holds periodic discussions with management regarding the Company’s guidelines and policies with respect to cybersecurity risks and receives regular reports from the CIO regarding such risks and the steps management has taken to monitor and control any exposure resulting from such risks.
−Removed: As of the date of this report, we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: The Audit Committee holds discussions at least annually with management regarding the Company’s guidelines and policies with respect to cybersecurity risks and receives regular reports from the CIO regarding such risks and the steps management has taken to monitor and control any exposure resulting from such risks.
+Added: Computer viruses, hackers, and employee or vendor misconduct, and other external hazards could expose our data systems and those of our vendors to security breaches, cybersecurity incidents or other disruptions, any of which could materially and adversely affect our ability to conduct our business.
+Added: The sophistication of cybersecurity threats continues to increase, and the controls and preventative actions we take to reduce the risk of cybersecurity incidents and protect our systems, including the regular testing of our cybersecurity incident response plan, may be insufficient.
+Added: In addition, new technology that could result in greater operational efficiency may further expose our computer systems to the risk of cybersecurity incidents.
+Added: While we have experienced cybersecurity incidents, to date, we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: For more information, see “Item 1A.
+Added: Risk Factors - We are increasingly dependent on information technology, and our business and reputation could suffer if we are unable to protect our information technology systems against, or effectively respond to, cyber-attacks or other cyber security incidents or breaches, or if our information technology systems are otherwise disrupted.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.