15 unchanged sentences
• Audits and Assessments:
−Removed: Regular audits and assessments are conducted by both internal and external experts (consultants, auditors, and other third parties) to evaluate the effectiveness of our cybersecurity controls and processes
−Removed: and recommend improvements.
+Added: Regular audits and assessments are conducted by both internal and external experts (consultants, auditors, and other third parties) to evaluate the effectiveness of our cybersecurity controls and processes and recommend improvements.
These assessments help us achieve compliance with internal policies as well as external regulations and standards.
14 unchanged sentences
These educational initiatives empower Board members to make informed decisions and actively contribute to the oversight of cybersecurity governance.
−Removed: Currently, our Vice President of Infrastructure and Security assumes primary responsibility for assessing and managing material cybersecurity risks.
−Removed: With experience spanning restaurant, retail, financial, and technology brands, including serving in similar roles overseeing information security programs at other companies, and a degree in Computer Science, our Vice President of Infrastructure and Security brings experience and expertise to the role.
−Removed: Our Vice President of Infrastructure and Security leads a team of professionals who oversee the prevention, detection, and remediation activities within our cybersecurity environment.
+Added: Currently, our senior management team, together with our Vice President of Infrastructure and Security, assumes primary responsibility for assessing and managing material cybersecurity risks.
+Added: Our Vice President of Infrastructure and Security brings over 20 years of experience in restaurant operations, infrastructure, and security operations for the Company and leads a team of internal professionals and utilizes a third-party service provider to oversee the prevention, detection, and remediation activities within our cybersecurity environment.
Our Company has established robust policies and processes governing the assessment, response, and notifications associated with cybersecurity incidents.
−Removed: These protocols ensure a systematic and coordinated approach to incident management, with collaboration among engineering, legal, and senior leadership to oversee compliance with legal and regulatory requirements and have clear mechanisms in place for escalating notifications to our CEO and the Board based on the nature and severity of each incident.
+Added: These protocols ensure a systematic and coordinated approach to incident management, with collaboration among engineering, legal, and senior leadership to oversee compliance with legal and regulatory requirements and have clear mechanisms in place for escalating notifications to our executive leadership team and the Board based on the nature and severity of each incident.
While we have experienced cybersecurity incidents in the past, in the last fiscal year we have not identified risks from known cybersecurity threats, including as a result of prior cybersecurity incidents, that have materially affected the Company or our financial position, results of operations and/or cash flows.
−Removed: We continue to invest in cybersecurity and the resiliency of our networks and to enhance our internal controls and processes, which are designed to help protect our systems and infrastructure, and the information they contain.
−Removed: For more information regarding the risks we face from cybersecurity threats, please see “Risk Factors."
+Added: We continue to invest in cybersecurity and the resilience of our networks and to enhance our internal controls and processes, which are designed to help protect our systems and infrastructure, and the information they contain.
+Added: For more information regarding the risks we face from cybersecurity threats, please see Item 1A, "Risk Factors".
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.