9 unchanged sentences
Our ISMS is designed to help us identify and manage material risks from cybersecurity threats, and as part of our ISMS, we engage a range of third-party service providers , including assessors, consultants, and auditors, to assist us in these processes.
−Removed: Our risk assessment framework involves an information security risk assessment procedure that helps us identify potential cybersecurity threats and vulnerabilities (including relating to the use of third-party service providers) and then determine strategies to mitigate or counter the threats.
−Removed: As part of this process, we conduct annual penetration testing utilizing a third-party service provider.
+Added: Our risk assessment framework involves an information security risk assessment procedure that helps us oversee and identify potential cybersecurity threats and vulnerabilities (including relating to the use of third-party service providers) and then determine strategies to mitigate or counter the threats.
+Added: As part of this process, we aim to conduct annual penetration testing utilizing a third-party service provider.
We have implemented controls designed to identify and mitigate cybersecurity threats associated with our use of third-party service providers.
2 unchanged sentences
In addition, we require our providers to meet appropriate security requirements, controls and responsibilities and investigate security incidents that have impacted our third-party providers, as appropriate.
−Removed: Our Information Technology Director also works with third-party service providers to assess potential cybersecurity threats and determines risk scores based on the likelihood of threats and the potential impacts of the threats, prioritizes risk and determines and recommends to our management controls aimed to counter such threats.
−Removed: We assess third-party cybersecurity controls through a cybersecurity questionnaire and include security and privacy addenda to our contracts where applicable.
+Added: Our Information Technology Director also works with third-party service providers to assess potential cybersecurity threats, determines risk scores based on the likelihood of threats and the potential impacts of the threats, prioritizes risk and determines and recommends to our management controls aimed to counter such threats.
+Added: We assess third-party cybersecurity controls through a cybersecurity questionnaire and aim to include security and privacy addenda to our contracts where applicable.
We also maintain procedures designed to protect the security of personally identifiable information, and our Privacy Policy provides details regarding the collection, storage, usage, and destruction of data.
2 unchanged sentences
Management is responsible for assessing, identifying, and managing risks from cybersecurity threats.
−Removed: Our cybersecurity risk management efforts are led by our Information Technology Director , who oversees our cybersecurity activities and is informed about and monitors the prevention, detection, mitigation and remediation of cybersecurity incidents as part of our ISMS.
−Removed: The Information Technology Director reports to the audit committee of our Board with respect to emerging cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
+Added: Our cybersecurity risk management and oversight are led by our Information Technology Director and our Chief Financial Officer , who are responsible for evaluating cybersecurity risks, reviewing incident trends, and overseeing the effectiveness of security controls.
+Added: Our current Information Technology Director and Chief Financial Officer have served in our cybersecurity risk management and oversight function since the second half of fiscal year 2025.
+Added: Our Information Technology Director brings extensive experience in information systems, cybersecurity and enterprise technology leadership.
+Added: His background includes driving our digital transformation, leading the development of the Company’s modern data platform, establishing enterprise-wide data governance, and implementing analytics and core infrastructure strategies to optimize the Company’s business and operations.
+Added: He has successfully aligned technology architecture with business objectives and executed strategic technology initiatives.
+Added: Our Chief Financial Officer was formerly the Chief Executive Officer of a private company and ultimately responsible for managing cybersecurity risks in that role.
+Added: Our Information Technology Director and Chief Financial Officer operate within established governance frameworks defined in the Company’s policies and supported by independent third-party assessments aligned with the U.S.
+Added: National Institute of Standards and Technology Cybersecurity Framework.
+Added: The Information Technology Director directs the information security program, assesses operational risks, and prioritizes mitigation activities, while the Chief Financial Officer participates in enterprise level risk oversight.
+Added: They hold regular discussions to review all operational matters, including cybersecurity posture, emerging threats, and ongoing initiatives.
+Added: To ensure continuous improvement of the Company's cybersecurity posture, they work throughout the year with external cybersecurity experts to evaluate the Company's security maturity, monitor evolving risks, and support the development of annual cybersecurity roadmaps.
+Added: The Information
+Added: Technology Director reports to the audit committee of our Board with respect to emerging cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
Our Information Technology Director and our Chief Financial Officer are ultimately responsible for the implementation of our cybersecurity risk management processes.
−Removed: To facilitate effective oversight, they hold discussions on cybersecurity risks, incident trends, and the effectiveness of cybersecurity measures as necessitated by emerging cybersecurity risks.
−Removed: They have experience managing enterprises relying on technology and business systems with cybersecurity risks and consults with trusted advisors where appropriate.
The audit committee of our Board is responsible for oversight of risks from cybersecurity threats.
1 unchanged sentence
Impact of Risks from Cybersecurity Threats
−Removed: As of the date of this report, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially
−Removed: affect us, including our business strategy, results of operations and financial condition.
+Added: As of the date of this report, though the Company and our service providers have experienced certain cybersecurity incidents, we are not aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations and financial condition.
We acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains.
3 unchanged sentences
Risk Factors” of this Annual Report for additional information about the risks to our business associated with a breach or other compromise to our information and operational technology systems.
−Removed: Our corporate headquarters is located at 303 W.
−Removed: Wall Street, Suite 102, Midland, Texas 79701.
+Added: Our corporate headquarters is located at One Marienfeld Place, 110 N.
+Added: Marienfeld Street, Suite 300, Midland, Texas 79701.
In addition to our headquarters, we also own and lease other properties that are used for field offices, yards, or storage in the Permian Basin.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.