6 unchanged sentences
We use the Center for Internet Security’s Critical Security Controls framework in our regular assessment of cybersecurity risks with respect to our information systems, including vulnerability management, access controls, infrastructure hardening, employee training and evaluation of external threats, including in connection with potential data breaches, ransomware and other forms of unauthorized access.
−Removed: FORM 10-K | 35
As part of our overall cybersecurity protection program, we have created a cross-functional cybersecurity team consisting of senior members of information technology, legal, accounting, internal audit and compliance teams (the “Incident Response Team”) that contributes to various aspects of our approach to managing cybersecurity risks.
6 unchanged sentences
The Audit Committee receives regular presentations and reports on cybersecurity matters that address a wide range of topics, including recent developments, evolving standards, vulnerability assessments and third-party reviews.
+Added: FORM 10-K | 35
Incident Response
9 unchanged sentences
Although we have adopted various processes and preventative measures with the objective of preventing breaches and minimizing the risks from cybersecurity matters, given the nature of cybersecurity threats that are constantly evolving over time, there is no guarantee that we, including our business strategy, results of operations or financial condition, will not be adversely affected by such threats or that our preventative measures and processes will be effective.
−Removed: Additionally, although we have insurance coverage for cybersecurity events, there can be no assurance that we will be able to maintain our insurance coverage or it will be enough to cover the cost associated with one or more cybersecurity events.
+Added: Additionally, although we have insurance coverage for cybersecurity events, there can be no assurance that we will be able to maintain our insurance coverage, or it will be enough to cover costs associated with one or more cybersecurity events.
For further discussion of our risks related to cybersecurity, refer to Item 1A—Risk Factors— Material damage to, or interruptions in, information systems as a result of external factors, staffing shortages, cybersecurity breaches or cyber fraud, or difficulties in updating our existing software or developing or implementing new software could have a material adverse effect on our business or results of operations, and we may be exposed to risks and costs associated with protecting the integrity and security of our customers’ information .
−Removed: 36 | FORM 10-K
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.