4 unchanged sentences
The Board is actively involved in the oversight of the Company's risk management program, and cybersecurity represents an important component of the Company's overall approach to enterprise risk management ("ERM").
−Removed: The Company's cybersecurity policies, standards, processes, and practices are fully integrated into the Company's ERM program and are informed by recognized frameworks established by the National Institute of Standards and Technology ("NIST");
−Removed: and other applicable industry standards.
+Added: The Company's cybersecurity policies, standards, processes, and practices are fully integrated into the Company's ERM program and are informed by recognized frameworks established by the National Institute of Standards and Technology ("NIST") and other applicable industry standards.
In general, the Company seeks to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security, and availability of the information that the Company collects and stores by identifying, preventing, mitigating, and remediating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
2 unchanged sentences
To this end, we have implemented processes designed to assess, identify, and manage risks from potential unauthorized occurrences on or through our IT systems that may result in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing therein.
−Removed: These processes are managed and monitored by our Director of Technology and Information Systems and supported by our outsourced IT managed services provider, under the supervision of our Chief Corporate Affairs Officer, and include mechanisms, controls, technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable and secure information technology environment.
−Removed: Our Chief Corporate Affairs Officer, who reports directly to the Chief Executive Officer, and our Director of Technology and Information Systems, who has three decades of experience managing and leading cybersecurity oversight, together with our other executive officers, are responsible for assessing and managing cybersecurity risks.
−Removed: Each member of Management holds undergraduate and graduate degrees in their respective fields and have extensive experience managing risks at the Company and at similar companies, including risks arising from cybersecurity threats .
+Added: These processes are managed and monitored by our Director of Technology and Information Systems and supported by our outsourced IT managed services provider, under the supervision of our Chief Operating Officer, and include mechanisms, controls, technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable and secure information technology environment.
+Added: Our Chief Operating Officer, who reports directly to the Chief Executive Officer, and our Director of Technology and Information Systems, together with our other executive officers, are responsible for assessing and managing cybersecurity risks.
In the last fiscal year, the Company has not identified any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations, or financial condition.
4 unchanged sentences
As one of the critical elements of the Company's overall ERM approach, the Company's cybersecurity program is focused on the following key areas:
−Removed: The Board's oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the "Audit Committee"), which regularly interacts with the Company's Chief Corporate Affairs Officer.
+Added: The Board's oversight of cybersecurity risk management is supported by the Audit Committee of the Board (the "Audit Committee"), which regularly interacts with the Company's Chief Operating Officer.
The Board, as a whole and at the Audit Committee level, has oversight for the most significant risks facing the Company and for the Company's processes to identify, prioritize, assess, manage, and mitigate those risks.
−Removed: The Audit Committee, which is composed solely of independent directors, has been designated by the Company's Board to oversee cybersecurity risks.
−Removed: The Audit Committee and the Board receive updates on cybersecurity and IT matters and related risk exposures from the Company's Chief Corporate Affairs Officer and other members of Management on cybersecurity risks on at least a semi-annual basis.
+Added: The Audit Committee, which is comprised solely of independent directors, has been designated by the Company's Board to oversee cybersecurity risks.
+Added: The Audit Committee and the Board receive updates on cybersecurity and IT matters and related risk exposures from the Company's Chief Operating Officer and other members of Management on cybersecurity risks on at least a semi-annual basis.
Collaborative Approach
−Removed: The Company has implemented a comprehensive, cross-functional approach to identifying, preventing, and mitigating cybersecurity threats and incidents, while also implementing controls and processes that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by Management in a timely manner.
+Added: The Company has implemented a cross-functional approach intended to identify, prevent, and mitigate material cybersecurity threats and incidents, while also implementing controls and processes that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by Management in a timely manner.
Information Security
10 unchanged sentences
Third-Party Risk Management
−Removed: The Company maintains a comprehensive, risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
+Added: The Company maintains a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
Education, Awareness and Training
The Company provides regular, mandatory cybersecurity training as a means to equip the Company’s personnel with effective tools to address cybersecurity threats, and to communicate the Company’s evolving information security policies, standards, processes and practices.
−Removed: We conduct continuous automated phishing simulation campaigns which can trigger additional training for personnel on how to recognize social engineering attempts (e.g., phishing, smishing, vishing, etc.).
−Removed: track performance on phishing exercises to help us monitor the awareness of our employees and inform future training priorities.
+Added: We conduct automated phishing simulation campaigns which can trigger additional training for personnel on how to recognize social engineering attempts (e.g., phishing, smishing, vishing, etc.).
+Added: We track performance on phishing exercises to help us monitor the awareness of our employees and inform future training priorities.
Risk and Readiness Assessments
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.