6 unchanged sentences
We have documented cybersecurity policies and standards, and we assess risks from cybersecurity threats and monitor information systems for potential cybersecurity issues.
−Removed: These processes are managed and monitored by a dedicated cybersecurity team, including third-party service providers, and led by our Head of IT, and include mechanisms, controls, technologies, systems, and other processes designed to help prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and help maintain a stable information technology environment.
+Added: These processes are managed and monitored by a dedicated cybersecurity team, including third-party service providers, and led by our Head of IT, and include mechanisms, controls, technologies, systems, and other processes designed to help prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting our data and help maintain a stable information technology environment.
For example, we use processes, tools and external services to conduct regular vulnerability testing, penetration testing, data recovery testing, security audits, and ongoing risk assessments, including due diligence on and audits of our key technology vendors, CROs, and other contractors and suppliers .
We work to maintain a strong cybersecurity posture through a multi-layered approach.
−Removed: Our endpoint detection and response (“EDR”) system helps monitor and analyze endpoint devices, and is designed to assist us in quickly identifying and responding to emerging threats.
+Added: Our endpoint detection and response (“EDR”) system helps monitor and analyze endpoint devices, and is designed to assist us in quickly identifying and responding to emerging threats, including those from our third-party service providers.
Complementing our EDR capabilities, our managed detection and response service assists with threat monitoring, proactive threat hunting, and rapid incident response.
Furthermore, we employ data loss prevention tools to help enforce strict data security policies, prevent unauthorized access and protect the transmission of sensitive information.
−Removed: These integrated technologies help us to detect, mitigate, and respond to cyber threats, with the goal of minimizing potential disruptions to our business operations.
+Added: These integrated technologies help us to detect, mitigate, and respond to cyberthreats, with the goal of minimizing potential disruptions to our business operations.
We have an incident response plan designed to help quickly detect, contain and remediate cybersecurity incidents.
2 unchanged sentences
In addition, we consult with outside advisors and experts when appropriate to assist with assessing, identifying, and managing cybersecurity risks, including to help anticipate future threats and trends, and their impact on our risk environment.
−Removed: Our current Head of IT reports directly to our Chief Financial Officer and has over twenty years of experience managing information technology and cybersecurity matters, holds a Master of Science degree in Telecommunications and Computer Networks and is Project Management Professional, Certified Scrum Master and IT Infrastructure Library certified.
+Added: Our current Head of IT reports directly to our Chief Financial Officer and has over twenty years of experience managing information technology and cybersecurity matters, holds a Master of Science degree in Telecommunications
+Added: and Computer Networks and is Project Management Professional, Certified Scrum Master and IT Infrastructure Library certified.
We have established a cybersecurity council, facilitated by the Head of IT, which includes senior leadership from various departments.
1 unchanged sentence
Our Board as a whole has oversight for the most significant risks facing us and for our processes to help identify, prioritize, assess, manage, and mitigate those risks, including oversight of cybersecurity risks.
−Removed: Our Board receives at least two updates each year on cybersecurity and information technology matters and related risk exposures from our Head of IT as well as other members of our senior leadership team.
+Added: Our Board receives updates at least annually on cybersecurity and information technology matters and related risk exposures from our Head of IT as well as other members of our senior leadership team.
We consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.