1 unchanged sentence
Cybersecurity.
−Removed: Management and Strategy
−Removed: have established policies and processes for assessing, identifying, and managing material risk from cybersecurity threats and integrated
−Removed: these processes into our overall risk management systems and processes.
−Removed: We assess material risks from cybersecurity threats, including
−Removed: any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects on the confidentiality,
−Removed: integrity, or availability of our information systems or any information residing therein.
−Removed: conduct technical risk assessments to identify cybersecurity threats, as well as assessments in the event of a material change in our
−Removed: business practices that may affect information systems that are vulnerable to such cybersecurity threats.
−Removed: We conduct programmatic risk
−Removed: assessments, including identification of reasonably foreseeable internal and external risks, the likelihood and potential damage that
−Removed: could result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.
−Removed: these risk assessments, we evaluate whether and how to re-design, implement, and maintain reasonable safeguards to minimize identified
−Removed: evaluate how to reasonably address any identified gaps in existing safeguards;
−Removed: and regularly monitor the effectiveness of our
−Removed: Our Manager of Information Technology, who has over 25 years of information technology experience, and our Chief Operating
−Removed: Officer, who has over 15 years of information technology management experience, manage the risk assessment and mitigation process.
−Removed: part of our overall risk management system, we monitor and test our safeguards and train our employees on these safeguards, in collaboration
−Removed: with human resources, information technology and management.
−Removed: Personnel at all levels and departments are made aware of our cybersecurity
−Removed: policies through internal communications, training and annual policy updates, and are requested to promptly report any suspected breach
−Removed: of our information systems to management.
−Removed: Additionally, we have implemented annual security training for all employees and staff, which
−Removed: includes targeting the recognition of phishing campaigns.
−Removed: continually review and update our processes to safeguard our information systems.
−Removed: This includes the deployment of advanced security measures
−Removed: and regular audits.
−Removed: We have implemented multi-factor authentication (MFA) for email and cloud services and implement controls for incoming
−Removed: email to mitigate various cyber-attacks, including phishing attacks, malware, viruses and other security breaches.
−Removed: Additionally, we review
−Removed: and revise, as necessary, our incident response and disaster recovery policies on an annual basis.
−Removed: additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents,
−Removed: have materially affected or are reasonably likely to materially affect us , including our business strategy, results of operations, or
−Removed: financial condition, please refer to Item 1A, “Risk Factors,” in this Report on Form 10-K, including the risk factors entitled
−Removed: “Third parties might attempt to gain unauthorized access to our network or seek to compromise our products and services.”
−Removed: role of our board of directors is informed oversight of our risk management process, including risks from cybersecurity threats.
−Removed: board of directors is responsible for monitoring and assessing strategic risk exposure, and our management is responsible for the day-to-day
−Removed: management of the material risks we face.
−Removed: Our board of directors administers its cybersecurity risk function in coordination with the
−Removed: oversight and periodic review of the audit committee.
−Removed: In the event of a cybersecurity incident impacting us, management will report to
−Removed: our board of directors and provide updates on management’s incident response plan for addressing and mitigating any risks associated
−Removed: with such an incident.
−Removed: cybersecurity incident response and vulnerability management policies are designed to escalate certain cybersecurity incidents and threats
−Removed: to management members depending on the circumstances, including the Chief Executive Officer and Chief Financial Officer.
−Removed: The Chief Executive
−Removed: Officer and Chief Financial Officer work with our incident response team to help the Company mitigate and remediate cybersecurity incidents
−Removed: of which they are notified.
−Removed: In addition, the Company’s management and its designees report to the board of directors for certain
−Removed: cybersecurity incidents.
−Removed: board of directors receives periodic reports from management and its designees concerning our significant cybersecurity threats and risks,
−Removed: and the processes we plan to implement and/or have implemented to address them.
+Added: Risk Management and Strategy
+Added: We have established policies
+Added: and processes for assessing, identifying, and managing material risk from cybersecurity threats and integrated these processes into our
+Added: overall risk management systems and processes.
+Added: We assess material risks from cybersecurity threats, including any potential unauthorized
+Added: occurrence on or conducted through our information systems that may result in adverse effects on the confidentiality, integrity, or availability
+Added: of our information systems or any information residing therein.
+Added: We conduct technical risk
+Added: assessments to identify cybersecurity threats, as well as assessments in the event of a material change in our business practices that
+Added: may affect information systems that are vulnerable to such cybersecurity threats.
+Added: We conduct programmatic risk assessments, including
+Added: identification of reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such
+Added: risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.
+Added: Following these risk assessments,
+Added: we evaluate whether and how to re-design, implement, and maintain reasonable safeguards to minimize identified risks;
+Added: evaluate how to
+Added: reasonably address any identified gaps in existing safeguards;
+Added: and regularly monitor the effectiveness of our safeguards.
+Added: of Information Technology, who has over 25 years of information technology experience, and our Chief Operating Officer, who has over 15
+Added: years of information technology management experience, manage the risk assessment and mitigation process.
+Added: As part of our overall risk
+Added: management system, we monitor and test our safeguards and train our employees on these safeguards, in collaboration with human resources,
+Added: information technology and management.
+Added: Personnel at all levels and departments are made aware of our cybersecurity policies through internal
+Added: communications, training and annual policy updates, and are requested to promptly report any suspected breach of our information systems
+Added: to management.
+Added: Additionally, we have implemented annual security training for all employees and staff, which includes targeting the recognition
+Added: of phishing campaigns.
+Added: We continually review and
+Added: update our processes to safeguard our information systems.
+Added: This includes the deployment of advanced security measures and regular audits.
+Added: We have implemented multi-factor authentication (MFA) for email and cloud services and implement controls for incoming email to mitigate
+Added: various cyber-attacks, including phishing attacks, malware, viruses and other security breaches.
+Added: Additionally, we review and revise, as
+Added: necessary, our incident response and disaster recovery policies on an annual basis.
+Added: For additional information
+Added: regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially
+Added: affected or are reasonably likely to materially affect us , including our business strategy, results of operations, or financial condition,
+Added: please refer to Item 1A, “Risk Factors,” in this Report on Form 10-K, including the risk factors entitled “ Third
+Added: parties might attempt to gain unauthorized access to our network or seek to compromise our products and services.”
+Added: A role of our board of directors is informed oversight
+Added: of our risk management process, including risks from cybersecurity threats.
+Added: Our board of directors is responsible for monitoring and assessing
+Added: strategic risk exposure, and our management is responsible for the day-to-day management of the material risks we face.
+Added: Our board of directors
+Added: administers its cybersecurity risk function in coordination with the oversight and periodic review of the audit committee.
+Added: of a cybersecurity incident impacting us, management will report to our board of directors and provide updates on management’s incident
+Added: response plan for addressing and mitigating any risks associated with such an incident.
+Added: Our cybersecurity incident response and vulnerability
+Added: management policies are designed to escalate certain cybersecurity incidents and threats to management members depending on the circumstances,
+Added: including the Chief Executive Officer and Chief Financial Officer.
+Added: The Chief Executive Officer and Chief Financial Officer work with our
+Added: incident response team to help the Company mitigate and remediate cybersecurity incidents of which they are notified.
+Added: In addition, the
+Added: Company’s management and its designees report to the board of directors for certain cybersecurity incidents.
+Added: Our board of directors receives periodic reports
+Added: from management and its designees concerning our significant cybersecurity threats and risks, and the processes we plan to implement
+Added: and/or have implemented to address them.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.