3 unchanged sentences
We have developed and maintain a Material Cyber Incident Disclosure Program.
−Removed: The program includes processes for the identification, review and assessment of materiality of cyber events, notification of our senior leadership and Board of Directors of such events, and financial reporting disclosure where applicable.
+Added: The program includes processes for the identification, review and assessment of materiality of cyber events, notification of our senior leadership and Board of Directors of such events, and financial reporting disclosures where applicable.
As part of the program, we also engage in due diligence regarding the cybersecurity capabilities of our current and potential third-party vendors in accordance with industry best practices.
7 unchanged sentences
We have implemented comprehensive cybersecurity initiatives for our employees, including education, training, and testing.
−Removed: These measures are conducted annually to ensure our employees remain up-to-date with the latest security practices, complementing our continuously improving processes and systems.
−Removed: Our Chief Information Officer is responsible for developing and implementing our information security program.
+Added: These measures are conducted at least annually to ensure our employees remain up-to-date with the latest security practices, complementing our continuously improving processes and systems.
+Added: Our Chief Information Security Officer ( “CISO”) is responsible for developing and implementing our information security program.
Our Information Security team monitors our exposure to external cybersecurity threats, leveraging automated tools and manual processes to ensure cybersecurity risk is effectively mitigated on a continuous basis.
−Removed: This team leverages internal IT resources, a managed security service provider, and additional third-party security software and technology services.
−Removed: When a specific incident has been identified, the Information Security team leverages our Cyber Incident Response Plan in conjunction with established Information Security policies to begin assessment of the incident.
+Added: To achieve this, the Information Security team leverages internal IT resources, a managed security service provider, and additional third-party security software and technology services.
+Added: When a specific incident has been identified, the Information Security team leverages our Cyber Incident Response Plan in conjunction with established Information Security policies to begin the assessment of the incident.
Depending on the type and/or severit y of the incident, our Information Security team will determine (in compliance with our Cyber Incident Response Plan) whether third party expertise or consultation is necessary.
1 unchanged sentence
As part of its review of incidents, our Information Security team considers the risk exposure, potential impact, severity and implications with respect to our information technology systems.
−Removed: Our Information Security team is responsible for escalating incidents which are determined to be higher risk to our Cyber Event Disclosure Committee.
+Added: Our CISO is responsible for escalating incidents which are determined to be higher risk to our Cyber Event Disclosure Committee.
The Cyber Event Disclosure Committee will work with our General Counsel to determine the materiality of the incident and any required disclosure.
2 unchanged sentences
The oversight, monitoring, and testing of the program occurs under our Sarbanes-Oxley entity-level control reviews and the program is integrated into our Enterprise Risk Management processes.
−Removed: The Cyber Event Disclosu re Committee convenes, at least monthly, to review recent developments in cybersecurity and in the cybersecurity risk landscape.
+Added: The Cyber Event Disclosu re Committee convenes, at least quarterly, to review recent developments in cybersecurity and in the cybersecurity risk landscape.
The Cyber Event Disclosure Committee is comprised of representatives with relevant expertise for assessing and managing the applicable risks.
Our Board of Directors is presented with updates on an annual, or as needed, basis regarding our cybersecurity preparedness.
−Removed: Additionally, our Board of Directors is provided with a comprehensive cyber training from our Chief Information Security Officer at least annually.
+Added: Additionally, at least annually, our Board of Directors is provided with a comprehensive cyber training from our CISO.
Our Board of Directors annually reviews our cybersecurity program and the Audit Committee of our Board of Directors is specifically responsible for oversight of cybersecurity risk, which it regularly reviews with Company leadership.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.