17 unchanged sentences
Our Audit Committee receives quarterly presentations and reports on developments in the cybersecurity space, including risk management practices, recent developments, vulnerability assessments, third-party and independent reviews, the threat environment, and information security issues encountered by other public companies.
−Removed: The Senior Director of IT acts as the Incident Manager and meets regularly with our Incident Response Team, including members of Financial Risk Management, IT Security and Human Resources senior management to discuss the necessary measures to take prior to and during an incident.
−Removed: In the event of an incident, the Incident Manager meets regularly with the executive leadership team and keeps them apprised of the status of any incident during the incident response.
−Removed: Our Board and the Audit Committee also receive prompt and timely information from the Senior Director of IT and executive leadership regarding any cybersecurity risks that meet certain reporting thresholds, as well as ongoing updates regarding any such risk.
−Removed: Finally, the Incident Response Manager briefs corporate leadership on lessons learned from the incident during or after the recovery phase.
−Removed: The Senior Director of IT, in collaboration with a team of IT professionals, our legal counsel and Human Resources, are tasked with implementing a program designed to protect our information systems from cybersecurity threats and manage material risks.
−Removed: The Senior Director of IT has served in various roles in information technology and information security for over 20 years.
−Removed: The Senior Director of IT and senior management are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time and report such threats and incidents to the Audit Committee when appropriate.
+Added: In addition to these oversight activities, the Audit Committee and the Board play a pivotal role in ensuring the Company’s cybersecurity strategy aligns with its overall risk management framework.
+Added: They are responsible for reviewing and approving major cybersecurity policies, monitoring the effectiveness of the Company’s risk mitigation efforts, and staying informed about significant incidents or threats that may impact business operations.
+Added: The Board also ensures that management has the resources and authority needed to implement cybersecurity initiatives and provides guidance on prioritizing investments in information security.
+Added: The Senior Director of IT acts as the Incident Manager and meets regularly with our Incident Response Team, including members of Financial Risk Management, IT Security, legal counsel, Internal Control and Human Resources senior management to discuss the necessary measures to take prior to and during an incident.
+Added: Management’s responsibilities extend to the day-to-day administration of cybersecurity policies, processes, and practices.
+Added: This includes proactively monitoring for threats, conducting vulnerability assessments, responding to incidents, and providing regular training to employees.
+Added: In the event of an incident, the Incident Manager collaborates closely with executive leadership, keeping them informed of the incident’s status and coordinating response actions.
+Added: Management is also tasked with continuously improving the Company’s cybersecurity posture by learning from past incidents and adapting policies and procedures accordingly.
+Added: Furthermore, management ensures compliance with recognized frameworks such as the NIST Cybersecurity Framework and oversees the engagement of third-party providers for independent risk assessments.
+Added: The Board and the Audit Committee receive prompt updates from management regarding any cybersecurity risks that meet reporting thresholds and are briefed on lessons learned after the recovery phase, reinforcing their role in strategic oversight and accountability.
+Added: The Senior Director of IT, in collaboration with a team of IT professionals, legal counsel, Internal Control, and Human Resources,
+Added: implements programs designed to protect information systems from cybersecurity threats and manage material risks.
+Added: With over 20 years of experience, the Senior Director of IT is responsible for overseeing the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents in real time.
+Added: Senior management monitors these activities and reports significant threats and incidents to the Audit Committee.
+Added: Management’s operational responsibilities are complemented by the Board’s strategic oversight, ensuring that the Company stays ahead of evolving cybersecurity risks and maintains a comprehensive risk management strategy.
Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to materially affect our Company, including our business strategy, results of operations, or financial condition as of December 31, 2025 .
For more information, please see the risk factor disclosures included in Item 1A of this Annual Report on Form 10-K.
+Added: This ongoing assessment and communication between management and the Board ensures that cybersecurity risks are managed effectively and that both operational and strategic responses are aligned with the Company’s objectives.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.