3 unchanged sentences
Risk Management Strategy
−Removed: The Company’s cybersecurity risk management function is lead by the Vice President of Information Technology, who evaluates processes and activities within the Company’s information technology infrastructure and automated systems.
−Removed: During 2023, the Company completed a detailed assessment to identify all technology and cyber tools currently in place and assessed its information technology personnel’s cybersecurity capabilities and skill sets.
−Removed: During 2023, the Company focused on formalizing cybersecurity procedures and defining standards for risk identification and communication activities.
+Added: The Company’s cybersecurity risk management function is led by the Vice President of Information Technology, who evaluates processes and activities within the Company’s information technology infrastructure and automated systems.
+Added: In 2023, the Company completed a detailed assessment to identify all technology and cyber tools currently in place and assessed its information technology personnel’s cybersecurity capabilities and skill sets.
+Added: In 2023, the Company focused on formalizing cybersecurity procedures and defining standards for risk identification and communication activities.
The Company utilizes the National Institute of Standards and Technology guidance in all cybersecurity policies and procedures.
−Removed: Annual training for employees is required as well as ad hoc trainings for specific topics or events as deemed appropriate throughout the year.
+Added: Annual training for
+Added: employees is required as well as ad hoc trainings for specific topics or events as deemed appropriate throughout the year.
The Company also has cyber insurance to assist the Company both financially and operationally if a cyber event were to occur.
10 unchanged sentences
• Management’s risk assessment associated with the budgeting and strategic planning process;
−Removed: • Annual update of risk factors in the Company’s Form 10-K by key executives;
−Removed: • Legal risk assessment associated with our response to the Department of Justice proceeding, and
+Added: • Annual update of risk factors in the Company’s Form 10-K by key executives, and
• A broader fraud risk assessment (also performed as part of the internal control program ).
The Company’s information technology and risk management function is highly centralized, with the Corporate Controller and Vice President of Information Technology involved in most of the risk related activities which provides a consistent input throughout risk management activities as well as aiding in identifying dependencies and duplications.
−Removed: The Company engaged a third party who conducted its phishing and penetration tests in 2023.
−Removed: The Company is in the process of implementing new processes, procedures, and tools as a result of the observations from these tests and expects all actions to be implemented during 2024.
+Added: The Company engaged a third party to conduct phishing and penetration tests in 2024.
+Added: The Company continues to evolve its processes, procedures, and tools as a result of the observations from these tests.
The Vice President of Information Technology oversees the population of third-party service providers connected to any of the Company’s networks.
−Removed: The Company obtains a Report on Controls at a Service Organization Relevant to User Entities’ Internal Control over Financial Reporting, Type 2 Report (“SOC-1 Report”) that reports on the fairness of the presentation of the service provider’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives throughout a specified period.
−Removed: The SOC-1 Report is reviewed by Internal Audit.
−Removed: The Company limits access to information based on the nature of the services performed by third party service providers which provides a significant level of risk management before third-party access to data.
+Added: For each third-party service provider that would directly impact the Company’s financial reporting, the Company obtains a System and Organization Controls (SOC) 1, Type 2 Report (“SOC 1 Report”) to evaluate that service provider’s internal controls and help the Company assess the risk of obtaining services from that services provider.
+Added: The SOC-1 Report is reviewed by members of the Company’s management and the Internal Audit group.
+Added: The Company also limits access to information granted to any third-party service provider to only the information necessary for them to perform their services to the Company.
In 2024, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition .
2 unchanged sentences
For additional information about these risks, see Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K.
+Added: Governance and Process for Assessing, Identifying and Managing Material Risks from Cybersecurity Threats
The Audit Committee of the Board (the “Audit Committee”) has been designated as the board committee with oversight responsibility of cybersecurity as delegated in the Audit Committee charter.
−Removed: The below summarizes the role and the frequency in which the Audit Committee oversees and monitors cybersecurity risks:
−Removed: • At least annually the Vice President of Technology presents compliance activities related to cybersecurity to the Audit Committee which includes those activities related to compliance with the cybersecurity disclosure regulations;
−Removed: • Any material breaches would be disclosed to the Audit Committee either in regularly scheduled meetings or in calls with the Chair of the Audit Committee if the communication is urgent;
+Added: The following summarizes the role and frequency in which the Audit Committee oversees and monitors cybersecurity risks:
+Added: • At least annually the Vice President of Information Technology presents compliance activities related to cybersecurity to the Audit Committee which includes those activities related to compliance with the cybersecurity disclosure regulations;
+Added: • Material breaches, if any are, disclosed to the Audit Committee either in regularly scheduled meetings or, if urgent in calls with the Chair of the Audit Committee;
• Periodically, the Vice President of Information Technology provides updates to the Audit Committee on internal controls surrounding information technology (including cybersecurity);
−Removed: • The Chair of the Audit Committee provides regular updates during the Audit Committee meeting activities which includes cybersecurity;
+Added: • The Chair of the Audit Committee provides regular updates during Audit Committee meetings which includes cybersecurity;
• The Vice President of Information Technology presents updates on the cybersecurity program to the Company’s Board annually.
−Removed: All cybersecurity events are communicated to the Corporate Controller and Internal Audit Vice President for disclosure considerations.
−Removed: Material and severe occurrences are escalated to the Chief Executive Officer and Chief Financial Officer for further review, discussion and remediation.
The Vice President of Information Technology is responsible for managing overall cybersecurity and cyber risks, including infrastructure, development, and cybersecurity.
8 unchanged sentences
• Software Development Security.
−Removed: Management is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity threats by the Vice President of Information Technology.
−Removed: The Company’s information technology landscape is not large or complex and it has a limited data footprint which allows the Vice President of Information Technology to be directly responsible and stay aware of all incidents.
−Removed: The Company has sufficient tools and processes in place to allow the Vice President of Information Technology to be effective as the central point person of monitoring and reporting incidents.
+Added: The Company’s Vice President of Information Technology is the central contact point to receive (i) alerts regarding potential cybersecurity incidents and (ii) reports from the Company’s Information Technology personnel regarding potential cybersecurity incidents.
+Added: All confirmed cybersecurity events are communicated by the Vice President of Information Technology to the Corporate Controller and Vice President of Internal Audit.
+Added: Material confirmed cybersecurity events are further escalated to the Chief Executive Officer and Chief Financial Officer for further review, discussion and remediation.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.