8 unchanged sentences
• risk assessments designed to help identify material cybersecurity risks to our critical systems and information;
−Removed: • a Manager of Information Technologies (“IT Manager”) responsible for managing our cybersecurity risk assessment processes, our security controls, and our response to cybersecurity incidents;
+Added: • a Director of Information Technologies and Cybersecurity (“IT Director”) responsible for managing our cybersecurity risk assessment processes, our security controls, and our response to cybersecurity incidents;
• the use of external service providers, where appropriate, to assess, test, or otherwise assist with aspects of our security processes;
6 unchanged sentences
The Board and Audit Committee are supported in their oversight capacity by our Management Cybersecurity Committee (the “MC Committee”) and our internal auditors.
−Removed: The MC Committee consists of our CEO, CFO, EVP of Engineering and Corporate Strategy, Vice President - General Counsel, and our IT Manager.
+Added: The MC Committee consists of our CEO, Interim CFO, Chief Operations Officer, Senior Vice President General Counsel, and our Director of IT.
Our internal auditors perform audit engagements to assess our strategies, policies, procedures, and controls to reduce the risk of a cybersecurity incident.
−Removed: Our IT Manager is responsible for assessing and managing risks from cybersecurity threats, guiding our overall cybersecurity risk management program, and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
−Removed: Our IT Manager is responsible for reporting material incidents to our MC Committee.
−Removed: Our IT Manager has a Bachelor of Science in Computer Science from Texas A&M University and a Master of Business Administration from Rice University.
+Added: Our Director of IT is responsible for assessing and managing risks from cybersecurity threats, guiding our overall cybersecurity risk management program, and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Our Director of IT is responsible for reporting material incidents to our MC Committee.
+Added: Our Director of IT has a Bachelor of Science in Computer Science from Texas A&M University and a Master of Business Administration from Rice University.
He has over 17 years of information technology experience in the energy industry.
1 unchanged sentence
Engagement of Third Parties
−Removed: The MC Committee, internal auditors, our IT Manager and various other groups each occasionally engage third-party service providers to assist in their management of cybersecurity threats, including but not limited to cybersecurity vendors, assessors, consultants, auditors, and other third parties.
−Removed: Our IT Manager oversees third party vendors to identify cyber risks associated with our use of third-party service providers who may have access to sensitive Company data and systems.
+Added: The MC Committee, internal auditors, our Director of IT and various other groups each occasionally engage third-party service providers to assist in their management of cybersecurity threats, including but not limited to cybersecurity vendors, assessors, consultants, auditors, and other third parties.
+Added: Our Director of IT oversees third party vendors to identify cyber risks associated with our use of third-party service providers who may have access to sensitive Company data and systems.
Impact of Risks from Cybersecurity Threats
3 unchanged sentences
Risk Factors – Risks Related to Technology and Cybersecurity” for additional information about our cybersecurity risks.
−Removed: There can be no assurance that our cybersecurity risk management program, including our controls, procedures and processes will be fully effective in protecting the confidentiality, integrity, and availability of our information systems.
+Added: There can be no assurance that our cybersecurity risk management program, including our controls, procedures and processes will be fully effective in protecting the confidentiality, integrity, and availability of our
+Added: information systems.
While we devote resources to our security measures to protect our systems and information, these measures cannot provide absolute security that they will not be subject to cybersecurity attacks and any damages to us from such attacks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.