2 unchanged sentences
Risk Management and Strategy
−Removed: We have an information security
−Removed: program designed to identify, protect, detect and respond to, and manage reasonably foreseeable cybersecurity risks and threats.
−Removed: our information systems from cybersecurity threats, we utilize various security tools that help prevent, identify, escalate, investigate,
−Removed: resolve, and recover from identified vulnerabilities and security incidents in a reasonably timely manner.
−Removed: These include, but are not
−Removed: limited to, internal reporting and tools for monitoring and detecting cybersecurity threats.
−Removed: We evaluate the risks associated
−Removed: with technology and cybersecurity threats and monitor our information systems for potential weaknesses.
−Removed: We review and test our information
−Removed: technology system on an as-needed basis and also utilize internal team personnel to evaluate and assess the efficacy of our information
−Removed: technology system and enhance our controls and procedures.
−Removed: The results of these assessments are reported to our Audit Committee and, from
−Removed: time to time, our Board of Directors.
−Removed: can be no assurances that our cybersecurity risk management program and processes, including our policies, controls, or procedures, will
−Removed: be fully implemented, complied with or are effective in protecting our systems and information.
−Removed: As of the date of this report,
−Removed: we are not aware of any cybersecurity incidents, that have had a materially adverse effect on our operations, business, results of operations,
−Removed: or financial condition.
−Removed: Our Board of Directors considers
−Removed: cybersecurity risk as part of its risk oversight function.
−Removed: It has delegated oversight of cybersecurity and other information technology
−Removed: risks to the Audit Committee of the Board of Directors.
−Removed: The Audit Committee oversees the implementation of the cybersecurity risk management
−Removed: The Audit Committee receives
−Removed: periodic reports from management on potential cybersecurity risks and threats.
−Removed: The Audit Committee reports to the full Board of Directors
−Removed: regarding its activities, including those related to cybersecurity.
−Removed: The full Board of Directors also receives briefings from management
−Removed: on the cybersecurity risk management program as needed.
−Removed: Management is responsible for
−Removed: assessing and managing our material risks from cybersecurity threats.
−Removed: Management has primary responsibility for our overall cybersecurity
−Removed: risk management program and supervises both the internal cybersecurity personnel and external cybersecurity consultants.
−Removed: The management team supervises
−Removed: efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings
−Removed: from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including
−Removed: external consultants;
+Added: We have an information security program designed
+Added: to identify, protect, detect and respond to, and manage reasonably foreseeable cybersecurity risks and threats.
+Added: To protect our information
+Added: systems from cybersecurity threats, we utilize various security tools that help prevent, identify, escalate, investigate, resolve, and
+Added: recover from identified vulnerabilities and security incidents in a reasonably timely manner.
+Added: These include, but are not limited to, internal
+Added: reporting and tools for monitoring and detecting cybersecurity threats.
+Added: We evaluate the risks associated with technology
+Added: and cybersecurity threats and monitor our information systems for potential weaknesses.
+Added: We review and test our information technology
+Added: system on an as-needed basis and also utilize internal team personnel to evaluate and assess the efficacy of our information technology
+Added: system and enhance our controls and procedures.
+Added: The results of these assessments are reported to our Audit Committee and, from time to
+Added: time, our Board of Directors.
+Added: There can be no assurances that our cybersecurity
+Added: risk management program and processes, including our policies, controls, or procedures, will be fully implemented, complied with or are
+Added: effective in protecting our systems and information.
+Added: As of the date of this report, we are not aware
+Added: of any cybersecurity incidents, that have had a materially adverse effect on our operations, business, results of operations, or financial
+Added: Our Board of Directors considers cybersecurity
+Added: risk as part of its risk oversight function.
+Added: It has delegated oversight of cybersecurity and other information technology risks to the
+Added: Audit Committee of the Board of Directors.
+Added: The Audit Committee oversees the implementation of the cybersecurity risk management program.
+Added: The Audit Committee receives periodic reports
+Added: from management on potential cybersecurity risks and threats.
+Added: The Audit Committee reports to the full Board of Directors regarding its
+Added: activities, including those related to cybersecurity.
+Added: The full Board of Directors also receives briefings from management on the cybersecurity
+Added: risk management program as needed.
+Added: Management is responsible for assessing and managing
+Added: our material risks from cybersecurity threats.
+Added: Management has primary responsibility for our overall cybersecurity risk management program
+Added: and supervises both the internal cybersecurity personnel and external cybersecurity consultants.
+Added: The management team supervises efforts to prevent,
+Added: detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security
+Added: personnel, threat intelligence and other information obtained from governmental, public or private sources, including external consultants;
and alerts and reports produced by security tools deployed in the IT environment.
−Removed: Our cybersecurity incident response
−Removed: plan governs our assessment and response upon the occurrence of a material cybersecurity incident, including the process for informing
−Removed: senior management and our Board of Directors.
+Added: Our cybersecurity incident response plan governs our
+Added: assessment and response upon the occurrence of a material cybersecurity incident, including the process for informing senior management
+Added: and our Board of Directors.
Our executive office is located at 580 N.
−Removed: Berry Street, Brea, California
−Removed: and our telephone number is (714) 784-6369.
−Removed: As of December 31, 2023, we had 14 company-owned retail
−Removed: locations across California, all of which are leased.
+Added: Street, Brea, California and our telephone number is (714) 784-6369.
+Added: As of December 31, 2024, we had 12 company-owned
+Added: retail locations across California, in Korea, and in Malaysia, all of which are leased.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.