4 unchanged sentences
Our Chief Technology Officer (“CTO”), as well as the security operations, engineering, risk management and legal functions help identify, assess and manage the Company’s cybersecurity threats and risks.
−Removed: Tab le o f Contents
−Removed: operations team monitors and identifies potentially material cybersecurity threats and risks, implements and maintains the Company’s incident management policies and plans.
+Added: Our security operations team monitors and identifies potentially material cybersecurity threats and risks, and implements and maintains the Company’s incident management policies and plans.
Our security operations team leads our efforts to identify and assess risks from cybersecurity threats by monitoring and evaluating our threat environment using various methods including, for example, subscribing to reports and services that identify cybersecurity threats, monitoring incident notifications from stakeholders, conducting threat assessments, managing software vulnerabilities and patches, conducting tabletop incident response exercises, and, in connection with our legal function, coordinating with law enforcement concerning threats.
9 unchanged sentences
Our assessment and management of material risks from cybersecurity threats are integrated into the Company’s overall risk management processes.
−Removed: For example, our information security function works with management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business, and our senior management evaluates material risks from cybersecurity threats against our overall business objectives and provides an annual cybersecurity update to each of the board of directors and the audit committee.
+Added: For example, our information security function works with management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business, and our senior management evaluates material risks from
+Added: cybersecurity threats against our overall business objectives and provides an annual cybersecurity update to each of the board of directors and the audit committee.
We use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example professional services firms including legal counsel, threat intelligence service providers, cybersecurity consultants, cybersecurity software providers, managed cybersecurity service providers, forensic investigators, and penetration testing firms.
10 unchanged sentences
Our board of directors addresses the Company’s cybersecurity risk management as part of its general oversight function.
−Removed: The board of directors’ audit committee is responsible for overseeing Company’s cybersecurity risk management processes, including oversight, mitigation, and disclosure of risks from cybersecurity threats.
+Added: The board of directors’ audit committee is responsible for overseeing the Company’s cybersecurity risk management processes, including supervision, mitigation, and disclosure of risks from cybersecurity threats.
Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including our CTO and members of our legal and cybersecurity teams.
5 unchanged sentences
In addition, the Company’s incident response process includes reporting material incidents to the audit committee of the board of directors.
−Removed: Tab le o f Contents
The audit committee and the full board receive annual reports from senior management concerning the Company’s significant cybersecurity threats and risk and the processes the Company has implemented to address them.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.