Unresolved Staff Comments
−Removed: Cybersecurity Risk Management, Strategy, and Governance
+Added: Cybersecurity Risk Management, Strategy,
+Added: and Governance
the ordinary course of our business, we receive, process, use, store and share digitally large amounts of data, including user data as
10 unchanged sentences
management team is responsible for monitoring, preventing, detecting, mitigating and remediating cybersecurity incidents.
−Removed: Our chief technology
−Removed: officer has over 41 years of experience and has held various leadership roles in information technology, including serving as a chief
−Removed: information officer and chief technology officer for the last 13 years.
−Removed: He has successfully implemented and managed large enterprise
−Removed: resource planning systems, e-commerce websites, stores and enterprise infrastructure, both cloud-based and on-premise.
−Removed: His expertise
−Removed: extends to evaluating and hiring cybersecurity personnel and outsourced managed services, defining incident response plans, conducting
−Removed: tabletop exercises, and establishing communication protocols with internal executives, board members, and vendors.
−Removed: He has firsthand experience
−Removed: in responding to actual cybersecurity incidents, showcasing a deep understanding of the challenges and complexities within the cybersecurity
−Removed: landscape in the retail sector.
−Removed: Our senior director of cybersecurity and compliance has a 16-year track record as an information technology
−Removed: and information security professional, complemented by an Executive MBA.
−Removed: His career is distinguished by a decade of leadership as the
−Removed: commander of the United States Army cyber protection team (174 CPT), where he gained cybersecurity experience at USCYBERCOM and ARCYBER.
−Removed: He holds multiple professional certifications, including CISSP, PMP and multiple SANS certifications.
−Removed: Our chief technology officer and
−Removed: senior director of cybersecurity and compliance report to the Audit Committee on these matters.
+Added: Our Vice President
+Added: of IT and Systems brings over 13 years of expertise, with a proven track record in various leadership roles, including Director of Software
+Added: Delivery for the past two years.
+Added: He has spearheaded the successful implementation and management of multiple website platforms, enterprise
+Added: resource planning (ERP) systems, retail store infrastructures, and cloud-based enterprise solutions.
+Added: In his current role, he oversees
+Added: our cybersecurity team and outsourced managed services, while developing incident response plans and establishing clear communication
+Added: protocols with internal executives and external vendors.
+Added: Our Network Systems Associate Director brings over 15 years of expertise in
+Added: enterprise IT, with a proven track record in various leadership roles, including 13 years in technical leadership roles.
+Added: His distinguished
+Added: career includes leading the transition to a managed NOC/SOC, spearheading email security initiatives, architecting the migration to Okta
+Added: with multi-factor authentication (MFA) and automated user-access auditing, and designing robust showroom network infrastructure.
+Added: end-user technology and security operations, encompassing endpoints and Microsoft 365, identity policies, vulnerability management, incident
+Added: response, SOC and vendor collaboration, telecommunications, and SaaS platforms.
+Added: He holds a B.S.
+Added: in Information Technology from Utah Valley
maintain a cybersecurity risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
15 unchanged sentences
security, compliance, legal, and operations.
−Removed: This TRC conducts assessments to ensure that any new software tools meet our standards for
+Added: The TRC conducts assessments to ensure that any new software tools meet our standards for
security, compliance, and operational efficiency.
7 unchanged sentences
with lesser impact potential.
−Removed: The Audit Committee received one report from our Senior Director of Cybersecurity and Compliance in 2024.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.