5 unchanged sentences
We have implemented cybersecurity processes, technologies, and controls to aid in our efforts to assess, identify, and manage such material risks.
−Removed: To identify and assess material risks from cybersecurity threats, our enterprise risk management program considers cybersecurity threat risks alongside other company risks as part of our overall risk assessment process.
−Removed: Our enterprise risk professionals collaborate with subject matter specialists, as necessary, to gather insights for identifying and assessing material cybersecurity risks, their severity, and potential mitigation strategies.
+Added: To identify and assess material risks from cybersecurity threats, our enterprise risk management program considers cybersecurity risks alongside other company risks as part of our overall risk assessment process.
+Added: enterprise risk professionals collaborate with subject matter specialists, as necessary, to gather insights for identifying and assessing material cybersecurity risks, their severity, and potential mitigation strategies.
We employ various tools and services for such purposes, including network, cloud and endpoint monitoring, vulnerability assessments, penetration testing, and tabletop exercises.
−Removed: We also have a cybersecurity risk assessment process, which helps identify our cybersecurity threat risks by considering certain industry standards as well as by engaging third parties to assess the security posture of our information security program.
+Added: We also have a cybersecurity risk assessment process, which surfaces cybersecurity risks by measuring our posture against industry standards and engaging third parties to assess our information security program .
To manage our material risks from cybersecurity threats, we take certain measures, including the below listed activities, depending on the nature of the relevant systems, data, and environment:
• undertaking period reviews of our consumer-facing policies and statements;
−Removed: • conduct phishing email simulations for employees and contractors with access to corporate email systems;
−Removed: • require employees, and certain service providers, to treat customer information with care;
+Added: • conduct phishing security training for employees and contractors with access to corporate email systems;
+Added: • require employees, and data service providers with whom we share customer, employee or partner data, to treat customer information with care;
• running tabletop exercises to simulate a response to a cybersecurity incident;
3 unchanged sentences
As part of our efforts to identify, assess, and manage material risks from cybersecurity threats, we engage third-party cybersecurity consultants and use them to, among other things, conduct a review of our cybersecurity program or conduct a tabletop exercise to help identify areas for continued focus, improvement and/or compliance.
+Added: In addition to maintaining a robust incident response plan, we regularly test our response capabilities through real-world simulations, post-incident reviews, and lessons-learned exercises to ensure continuous improvement in our ability to respond effectively to cybersecurity incidents.
Our processes also address cybersecurity risks associated with our use of third-party service providers, including those in our supply chain, which also include, but are not limited to, open-source software in our application development processes, or those who have access to our customer and employee data or our systems.
+Added: Our cybersecurity program is closely aligned with our commitment to data privacy.
+Added: We adhere to applicable data protection laws and regulations, integrate privacy-by-design principles into our processes, and routinely assess our practices to ensure that we protect customer, employee, and partner information.
Addressing these risks is part of our enterprise risk management program.
2 unchanged sentences
Additionally, we may impose contractual requirements related to cybersecurity on certain third parties that could pose significant cybersecurity risk to us and require them to agree to audits as appropriate.
−Removed: We describe the risks from cybersecurity threats that may materially affect us and how they may do so under the heading “Risks Related to Our Business Operations” under Item 1A of this Annual Report on Form 10-K, which disclosures are incorporated by reference herein.
+Added: Cybersecurity Incidents
+Added: During the last fiscal year, we did not identify any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: While we have encountered routine cybersecurity threats and attempted attacks, such as phishing emails and malware attempts, our security measures have effectively mitigated these risks without causing material disruption.
+Added: Despite our efforts, the risk of cybersecurity incidents remains, and we continue to monitor, adapt and enhance our security posture to address evolving threats.
+Added: Any future cybersecurity breaches or system vulnerabilities could impact our business operations, reputation and regulatory compliance obligations.
+Added: We remain committed to maintaining a robust cybersecurity program to mitigate these risks.
+Added: We provide disclosures on the potential material impacts of cybersecurity threats on our business operations, which are detailed under the heading 'Risks Related to Our Business Operations' in Item 1A of this Annual Report on Form 10-K, and those disclosures are incorporated by reference herein.
Cybersecurity Governance
−Removed: Cybersecurity is an important part of our risk management processes and an area of increasing focus for our Board and management.
+Added: Cybersecurity is a critical component of our enterprise risk management framework and a key area of focus for both our Board and management .
Our approach is to treat cybersecurity not just as a technology issue, but to recognize that it can have wide-ranging impacts on the business, operations, and financials of our company.
3 unchanged sentences
Members of the Board are also encouraged to regularly engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
−Removed: Material cybersecurity threat risks are also considered during separate Board meeting discussions of important matters like enterprise risk management, operational budgeting, business continuity planning, mergers and acquisitions, brand management, and other relevant matters.
−Removed: Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Chief Information Security Officer (CISO) in connection with our Chief Technology Officer, Chief Legal and People Officer, our Senior Vice President of Legal and Vice President, Internal Audit.
−Removed: Such individuals have extensive prior work experience and expertise spanning over three decades in various roles involving managing information security, developing cybersecurity strategy, implementing effective information and cybersecurity programs, managing cybersecurity operations and incident response, and incorporating security and privacy by design into software development programs, and our CISO has both CISSP and CRISC certifications.
+Added: Material cybersecurity threat risks are also integrated into Board meeting discussions of important matters like enterprise risk management, operational budgeting, business continuity planning, mergers and acquisitions, brand management, and other relevant matters.
+Added: Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our VP Information Security in connection with our Chief Technology Officer, Chief Legal and People Officer, our Senior Vice President of Legal and Vice President, Internal Audit.
+Added: Such individuals have extensive prior work experience and expertise spanning over three decades in various roles involving managing information security, developing cybersecurity strategy, implementing effective information and cybersecurity programs, managing cybersecurity operations and incident response, and incorporating security and privacy by design into software development programs.
These members of management are informed about and monitor the prevention, mitigation, detection, and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above, including the operation of our incident response plan.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.