4 unchanged sentences
These processes, technologies and controls are part of Saia’s overall enterprise risk management process.
−Removed: Our cybersecurity program is based on the National Institute of Standards and Technology Cybersecurity Framework and is designed to ensure that our information systems are effective and are prepared for cybersecurity threats, including through regular oversight and mitigation of internal and external threats.
+Added: Our cybersecurity program is based on the National Institute of Standards and Technology Cybersecurity Framework version 2.0, and the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework.
+Added: The Saia cybersecurity program is designed to ensure that our information systems are effective and are prepared for cybersecurity threats, including through regular oversight and mitigation of internal and external threats.
We regularly perform evaluations of our information security program and our information technology infrastructure, including through the use of tools and services for network and endpoint monitoring, vulnerability assessments and penetration testing, among other things.
5 unchanged sentences
The annual cybersecurity training consists of threat avoidance when working remote, proper password construction techniques, identifying and reporting suspicious activity, social engineering and insider threats.
−Removed: Additionally, we have implemented a regular phishing assessment that provides feedback and additional training as needed to enhance the annual training program.
+Added: Additionally, we have implemented a regular phishing assessment that provides feedback and additional training to enhance the annual training program.
Our information technology professionals also receive additional training related to their position.
−Removed: There can be no guarantee that our policies and procedures will be effective.
−Removed: Although our risk factors include further detail about the material cybersecurity risks we face, we believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date.
−Removed: We can provide no assurance that there will not be incidents in the future or that they will not materially affect us, including our business strategy, results of operations or financial condition.
−Removed: For more information about the cybersecurity risks we face, see the risk factors entitled “We rely heavily on technology to operate our business and cybersecurity threats or other disruptions to our technology infrastructure could harm our business or reputation” and "We use AI in our business, and its use could result in reputational harm, competitive harm, cybersecurity risks and legal liability, which could have a material adverse effect on our results of operations" in Item 1A.
+Added: There can be no guarantee that our cybersecurity processes, technologies and controls will be effective.
+Added: Although our risk factors include further detail about the material cybersecurity risks we face, including the evolving risks from artificial intelligence, we believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date.
+Added: We can provide no assurance that there will not be cybersecurity incidents in the future or that they will not materially affect us, including our business strategy, results of operations or financial condition.
+Added: For more information about the cybersecurity risks we face, see the risk factors, including those entitled “We rely heavily on technology to operate our business, including through the use of third-party applications, and cybersecurity threats or other disruptions to our technology infrastructure could harm our business or reputation” and "We use artificial intelligence in our business, and its use could result in reputational harm, competitive harm, cybersecurity risks and legal liability, which could have a material adverse effect on our business" in Item 1A.
Risk Factors.
Management is responsible for the day-to-day assessment and management of cybersecurity risks .
−Removed: Saia’s Director of Information Security and Compliance, who reports to the Executive Vice President and Chief Information Officer, has primary oversight of our cybersecurity risk management and strategy processes.
−Removed: The Director of Information Security and Compliance has served in information security roles since 2001 and led the information security function for a large health care system prior to joining Saia.
+Added: Saia’s Director of Information Technology Security, who reports to the Executive Vice President and Chief Information Officer, has primary oversight of our cybersecurity risk management and strategy processes.
+Added: The Director of
+Added: Information Technology Security has served in information security roles since 2001 and led the information security function for a large health care system prior to joining Saia in 2021.
He has a Bachelor of Science degree in Information Technology with a Concentration in Information Assurance and Security.
−Removed: The Director of Information Security and Compliance assesses our cybersecurity readiness through internal assessment tools as well as third-party control testing, vulnerability assessments and evaluation against industry standards.
−Removed: We maintain compliance structures that are designed to elevate issues relating to cybersecurity to our Director of Information Security and Compliance and to our Executive Vice President and Chief Information Officer.
+Added: The Director of Information Technology Security assesses our cybersecurity readiness through internal assessment tools as well as third-party control testing, vulnerability assessments and evaluation against industry standards.
+Added: We maintain compliance structures that are designed to elevate issues relating to cybersecurity to our Director of Information Technology Security and to our Executive Vice President and Chief Information Officer.
The Board of Directors has oversight responsibility for Saia’s strategic and operational risks.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.