Unresolved Staff Comments.
−Removed: Not applicable.
+Added: There are no material unresolved written comments that were received from the SEC staff 180 days or more before the end of our fiscal year relating to our periodic or current reports under the Securities Exchange Act of 1934, as amended.
Cybersecurity.
3 unchanged sentences
To identify and assess material risks from cybersecurity threats, our enterprise risk management program considers cybersecurity risks alongside other company risks as part of our overall risk assessment process.
−Removed: enterprise risk professionals collaborate with subject matter specialists, as necessary, to gather insights for identifying and assessing material cybersecurity risks, their severity, and potential mitigation strategies.
+Added: Our enterprise risk professionals collaborate with subject matter specialists, as necessary, to gather insights for identifying and assessing material cybersecurity risks, their severity, and potential mitigation strategies.
We employ various tools and services for such purposes, including network, cloud and endpoint monitoring, vulnerability assessments, penetration testing, and tabletop exercises.
1 unchanged sentence
To manage our material risks from cybersecurity threats, we take certain measures, including the below listed activities, depending on the nature of the relevant systems, data, and environment:
−Removed: • undertaking period reviews of our consumer-facing policies and statements;
−Removed: • conduct phishing security training for employees and contractors with access to corporate email systems;
−Removed: • require employees, and data service providers with whom we share customer, employee or partner data, to treat customer information with care;
+Added: • undertaking periodic reviews of our consumer-facing policies and statements;
+Added: • conducting phishing security training for employees and contractors with access to corporate email systems;
+Added: • requiring employees, and data service providers with whom we share customer, employee or partner data, to treat customer information with care;
• running tabletop exercises to simulate a response to a cybersecurity incident;
6 unchanged sentences
Our cybersecurity program is closely aligned with our commitment to data privacy.
−Removed: We adhere to applicable data protection laws and regulations, integrate privacy-by-design principles into our processes, and routinely assess our practices to ensure that we protect customer, employee, and partner information.
+Added: We always intend to adhere to applicable data protection laws and regulations, integrate privacy-by-design principles into our processes, and routinely assess our practices with the goal of protecting customer, employee, and partner information.
Addressing these risks is part of our enterprise risk management program.
13 unchanged sentences
Our Audit Committee is responsible for the oversight of risks from cybersecurity threats and receives updates from management quarterly.
−Removed: At least annually, the entire Board receives an overview from management of our cybersecurity threat risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
+Added: At least annually, the entire Board receives an overview from management of our cybersecurity threat risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps
+Added: management has taken to respond to such risks.
In such sessions, the Audit Committee and Board generally receive materials including a cybersecurity scorecard and other materials indicating current and emerging material cybersecurity threat risks, and describing the company’s ability to mitigate those risks, and discuss such matters with our Chief Information Security Officer.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.