7 unchanged sentences
As part of this exercise, mitigating measures are planned and implemented into action as necessary.
−Removed: As an additional feature of our cybersecurity risk management process, we have engaged an external third-party service provider to support our cybersecurity team and perform certain periodic external evaluations in addition to the assessments and network penetration tests we perform internally.
+Added: As an additional feature of our cybersecurity risk management process, we have engaged an external service provider to support our cybersecurity team by performing penetration tests and periodic external security evaluations .
We undertake to align our cybersecurity program, which encompasses both enterprise security and operational security, with the standards of the National Institute of Standards and Technology Cybersecurity Framework.
We maintain continuous cyber threat-detection systems and have established an incident response plan, which contains playbooks for addressing and recovering from potential material cyberattacks and breaches of data security.
−Removed: In addition to security measures for third-party vendors, we require onboarding orientation and periodic training covering cybersecurity and information management for all employees and board members and conduct regular cybersecurity awareness campaigns.
+Added: In addition to establishing security measures for vendors, we require onboarding orientation and periodic training for all employees and board members that focuses on cybersecurity and information management, and we conduct regular cybersecurity awareness campaigns.
As of the date of our filing of this report, we are not aware of any cybersecurity incident that has had or is reasonably likely to have a material impact on our business operations.
−Removed: Given the rapid evolution of cyber-related attack techniques, cybersecurity risks associated with our information technology systems and the systems of our customers and vendors continue to grow.
+Added: Given the rapid evolution of cyber-related attack techniques, including through the use of AI, cybersecurity risks associated with our information technology systems and the systems of our customers and vendors continue to grow.
Notwithstanding our cybersecurity management processes, a future cybersecurity incident could have a material adverse effect on our business or on our financial position, results of operations or cash flows.
3 unchanged sentences
Our board of directors oversees our enterprise risk register and cybersecurity program, including related policies and procedures.
−Removed: As part of this oversight, the audit committee of our board of directors receives regular status reports and updates from our management team and conducts periodic executive sessions with our Chief Information Officer.
+Added: As part of this oversight, the audit committee of our board of directors receives regular status reports and updates from our management team and conducts periodic executive sessions with our Vice President, Information Technology .
Such status reports and executive sessions cover cybersecurity matters, such as developments to our program, key risk indicators, emerging risks, and identified incidents.
−Removed: In addition, our Chief Information Officer, who has more than 40 years of industry experience and over 20 years of experience with the development, training and controls of effective global enterprise cybersecurity programs, oversees the implementation and compliance of our cybersecurity program and mitigation of information security related risks.
+Added: In addition, our Vice President , Information Technology, who has more than 20 years of industry experience and over 25 years of experience with the development, training and controls of effective global enterprise cybersecurity programs , oversees the implementation and compliance of our cybersecurity program and mitigation of information security related risks.
Such oversight includes (i) reviewing our enterprise risk register, (ii) maintaining adequate processes to manage the identified risks under our cybersecurity program, (iii) regularly analyzing logs of cybersecurity threats and vulnerabilities and (iv) overseeing prevention, detection, mitigation and remediation efforts in general, including the development and maintenance of the above-mentioned incident response plan.
−Removed: Additionally, we maintain an experienced information technology team at the employee level that supports our Chief Information Officer in implementing our cybersecurity program and internal reporting, security and mitigation functions.
+Added: Additionally, we maintain an experienced information technology team at the employee level that supports our Vice President, Information Technology in implementing our cybersecurity program and internal reporting, security and mitigation functions.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.