22 unchanged sentences
(2) our information security function works with management, including our Chief Technology Officer (“CTO”), to prioritize our risk management processes and mitigate cybersecurity threats that could more likely lead to a material impact to our business;
−Removed: (3) our senior management/committee evaluates material risks from cybersecurity threats against our overall business objectives and on a quarterly basis reports to the cybersecurity subcommittee of the audit committee of the board of directors, with the cybersecurity subcommittee reporting to the audit committee of the board of directors, which oversees our cybersecurity risk as part of our overall enterprise risk.
+Added: (3) our senior management/committee evaluates material risks from cybersecurity threats against our overall business objectives and on a quarterly basis reports to the audit committee of the board of directors, which oversees our cybersecurity risk as part of our overall enterprise risk.
We use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats , including for example:
8 unchanged sentences
Our board of directors addresses the Company’s cybersecurity risk management as part of its general oversight function.
−Removed: The board of directors’ audit committee , and specifically the subcommittee for cybersecurity, is responsible for overseeing Company’s cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats.
+Added: The board of directors’ audit committee is responsible for overseeing Company’s cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats.
Our cybersecurity risk assessment and management processes are implemented and maintained by our legal team along with third-party service providers in coordination with the CTO.
5 unchanged sentences
Our information security function, together with our CTO, works with the Company’s incident response team to help the Company mitigate and remediate cybersecurity incidents of which they are notified.
−Removed: In addition, the Company’s incident response and vulnerability management processes include reporting to the cybersecurity subcommittee of the board of directors’ audit committee for certain cybersecurity incidents in accordance with the incident response plan.
−Removed: The cybersecurity subcommittee receives periodic reports from the CTO, which reflect input from the third-party service provider, concerning the Company’s risk profile, including significant cybersecurity threats and risk and the processes the Company has implemented to address them.
−Removed: The cybersecurity subcommittee also has access to various reports, summaries and presentations related to cybersecurity threats, risk and mitigation.
+Added: In addition, the Company’s incident response and vulnerability management processes include reporting to the audit committee of the board of directors for certain cybersecurity incidents in accordance with the incident response plan.
+Added: The audit committee receives periodic reports from the CTO, which reflect input from the third-party service provider, concerning the Company’s risk profile, including significant cybersecurity threats and risk and the processes the Company has implemented to address them.
+Added: The audit committee also has access to various reports, summaries and presentations related to cybersecurity threats, risk and mitigation.
Cybersecurity Threats
3 unchanged sentences
For a description of the risks from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under Part 1.
−Removed: Risk Factors in this Annual Report on Form 10-K, including If our information technology systems or data, or those of third parties upon which we rely, are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
−Removed: fines and penalties;
−Removed: disruptions of our business operations;
−Removed: reputational harm;
−Removed: loss of revenue or profits;
−Removed: loss of customers or sales;
−Removed: loss of intellectual property or other confidential business information;
−Removed: and other adverse consequences, which may adversely affect our business .
+Added: Risk Factors in this Annual Report on Form 10-K, including If our information technology systems or data, or those of third parties upon which we rely, are or were compromised, we could experience adverse consequences, which may adversely affect our business .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.