13 unchanged sentences
● a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
+Added: ● simulated cyber-attack and penetration attempts along with phishing tests;
● a third-party risk management process for service providers, suppliers, and vendors.
8 unchanged sentences
Board members receive presentations on cybersecurity topics from our Head of IT, internal technology staff or external experts as part of the Board’s continuing education on topics that impact public companies.
−Removed: Certain members of our management team, including the Head of Risk Management and our General Counsel , are responsible for assessing and managing our material risks from cybersecurity threats .
−Removed: These individuals have primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Certain members of our management team, including our Head of IT who has more than 20 years experience in IT infrastructure and information security, are responsible for assessing and managing our material risks from cybersecurity threats.
+Added: These individuals have primary responsibility for our overall cybersecurity risk management program and supervise both our internal cybersecurity personnel and our retained external cybersecurity consultants.
Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel;
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.