6 unchanged sentences
integrity , and availability of our data.
−Removed: We have developed the following processes as part of our strategy for assessing, identifying,
−Removed: and managing material risks from cybersecurity threats.
−Removed: Managing Material Risks & Integrated
−Removed: Overall Risk Management
+Added: We maintain cybersecurity insurance coverage that provides protection against potential
+Added: losses arising from certain cybersecurity incidents.
+Added: In addition, we have developed the following processes as part of our strategy for
+Added: assessing, identifying, and managing material risks from cybersecurity threats.
+Added: Managing Material Risks and Integrated Overall
+Added: Risk Management
We have integrated cybersecurity risk management
9 unchanged sentences
factor authentication) process, protecting access to our banking and application systems.
−Removed: Moreover, our commitment to data security extends beyond industry standards
−Removed: through the implementation of advanced access controls.
−Removed: We have developed a sophisticated access control system, referred to as “dumb
−Removed: access controls,” which limits access to only specific vendors within a predefined range of costs.
−Removed: This system operates through
−Removed: a faceless entry point with a unique 4FA process, ensuring that access to sensitive banking or application systems is strictly controlled
−Removed: and virtually nonexistent for unauthorized entities.
−Removed: These comprehensive security measures not only protect our business transactional
−Removed: data but also uphold the integrity and confidentiality of our systems and information assets.
−Removed: Engaging Third-Parties on Risk Management
+Added: Moreover, our commitment to data security extends
+Added: beyond industry standards through the implementation of advanced access controls.
+Added: We have developed a sophisticated access control system,
+Added: referred to as “dumb access controls,” which limits access to only specific vendors within a predefined range of costs.
+Added: system operates through a faceless entry point with a unique 4FA process, ensuring that access to sensitive banking or application systems
+Added: is strictly controlled and virtually nonexistent for unauthorized entities.
+Added: These comprehensive security measures not only protect our
+Added: business transactional data but also uphold the integrity and confidentiality of our systems and information assets.
+Added: Engaging Risk Management Systems and Third-Party
Recognizing the complexity and evolving nature
−Removed: of cybersecurity threats, our Chief Experience Officer periodically evaluates and tests our risk management systems.
−Removed: Our Chief Experience
−Removed: Officer has specialized knowledge and insights, ensuring our cybersecurity strategies and processes remain at the forefront of industry
−Removed: best practices.
+Added: of cybersecurity threats, we use risk management systems developed and tested by external experts, including cybersecurity assessors,
+Added: consultants, and auditors.
+Added: These risk management systems enable us to leverage specialized knowledge and insights as part of our cybersecurity
+Added: strategies and processes.
+Added: These systems are assessed and maintained with the assistance of third-party service providers, including a
+Added: Technology Consultant engaged by the Company.
Overseeing Third-Party Risk
4 unchanged sentences
The monitoring
−Removed: includes regular assessments by our Chief Experience Officer.
+Added: includes regular assessments by our Chief Technology Officer.
This approach is designed to mitigate risks related to data breaches or
8 unchanged sentences
Management’s Role Managing Risk
−Removed: The Company’s Chief Experience Officer is
−Removed: primarily responsible for assessing, monitoring and managing our cybersecurity risks.
−Removed: The Chief Experience Officer must ensure that all
−Removed: industry standard cybersecurity measures are functioning as required to prevent or detect cybersecurity threats and related risks.
−Removed: Chief Experience Officer provides briefings on cybersecurity threats and related risks to our Chief Executive Officer on a regular basis.
−Removed: Our Chief Experience Officer has ten years of experience in the field of information technology.
−Removed: The Chief Experience Officer oversees
−Removed: and tests our compliance with standards, remediates known risks, and leads our employee training program.
−Removed: The Chief Experience Officer
−Removed: has extensive experience in cybersecurity and possesses the knowledge and skills and background and experience necessary, as described
−Removed: in his biography.
+Added: The Company’s Chief Technology Officer,
+Added: Chief Operating Officer, and Technology Consultant are primarily responsible for assessing, monitoring and managing our cybersecurity
+Added: Our Chief Technology Officer must ensure that all industry standard cybersecurity measures are functioning as required to prevent
+Added: or detect cybersecurity threats and related risks.
+Added: The Chief Technology Officer provides briefings on cybersecurity threats and related
+Added: risks to our Chief Executive Officer on a regular basis.
+Added: Our Chief Technology Officer has nine years of experience in the field of information
+Added: The Chief Technology Officer oversees and tests our compliance with standards, remediates known risks, and leads our employee
+Added: training program.
+Added: The Company’s Chief Technology Officer and Technology Consultant have extensive experience in cybersecurity and
+Added: possess the necessary knowledge, skills, background, and experience.
Monitoring Cybersecurity Incidents
−Removed: The Chief Experience Officer is continually informed
−Removed: about the latest developments in cybersecurity, including potential threats and innovative risk management techniques.
−Removed: The Chief Experience
−Removed: Officer implements and oversees processes for the regular monitoring of our information systems.
−Removed: This includes the deployment of industry-standard
−Removed: security measures and regular system audits to identify potential vulnerabilities.
−Removed: In the event of a cybersecurity incident, the Chief
−Removed: Experience Officer will implement an incident response plan.
−Removed: This plan includes immediate actions to mitigate the impact and long-term
−Removed: strategies for remediation and prevention of future incidents.
+Added: The Company’s Chief Technology Officer and
+Added: Technology Consultant are continually informed about the latest developments in cybersecurity, including potential threats and innovative
+Added: risk management techniques.
+Added: The Chief Technology Officer and Technical Consultant implement and oversee processes for the regular monitoring
+Added: of our information systems.
+Added: This includes the deployment of industry-standard security measures and regular system audits to identify
+Added: potential vulnerabilities.
+Added: In the event of a cybersecurity incident, the Chief Technology Officer and Technical Consultant will implement
+Added: an incident response plan.
+Added: This plan includes immediate actions to mitigate the impact and long-term strategies for remediation and prevention
+Added: of future incidents.
Reporting to Board of Directors
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.