1 unchanged sentence
CYBERSECURITY
−Removed: Cybersecurity Incident Impact
−Removed: We have experienced, and expect to continue to experience, cyber threats and incidents.
−Removed: As previously disclosed, on July 23, 2023, we experienced a cybersecurity incident affecting certain of our data and IT systems.
−Removed: As a result of the cybersecurity incident, we incurred $14.3 million of costs in connection with this event.
−Removed: Following a forensic investigation in connection with the incident, we concluded there was no material impact to our financial results for the year ended 2023.
−Removed: We also implemented additional security measures following the incident, such as stronger privileged access policies and enhanced and expanded multi-factor authentication to help prevent unauthorized access to our systems.
−Removed: We face ongoing risks from certain cybersecurity threats, and we cannot provide assurance that, if those risks materialize, our business strategy, results of operations or financial condition will not be materially affected in the future.
−Removed: See "Risk Factors" in ITEM 1A of this Annual Report on Form 10-K for more information on our cybersecurity related risks.
Risk Management and Strategy
4 unchanged sentences
Cybersecurity Risk Management.
−Removed: We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats, including risks relating to disruption of business operations or financial reporting systems, intellectual property theft;
−Removed: violation of privacy laws and other litigation and legal risk;
−Removed: and reputational risk, as part of our overall risk management system and processes.
+Added: We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats, including risks relating to disruption of business operations or financial reporting systems;
+Added: intellectual property theft;
+Added: violation of data privacy laws and other litigation and legal risk;
+Added: reputational risk;
+Added: and risks associated with our use of third-party service providers, as part of our overall risk management system and processes.
We address cybersecurity risks and threats through a strategic program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
−Removed: Our dedicated cybersecurity team oversees and implements our cybersecurity management program, compliance with applicable legal and third-party data protection and data privacy requirements, and our incident response and crisis management plans.
+Added: Our dedicated cybersecurity team oversees and implements our cybersecurity
+Added: management program, compliance with applicable legal and third-party data privacy requirements and our incident response and crisis management plans.
+Added: We also implemented additional security measures following the previously disclosed cybersecurity incident of July 2023, such as stronger privileged access policies and enhanced and expanded multi-factor authentication to help prevent unauthorized access to our systems.
+Added: We face ongoing risks from certain cybersecurity threats, and we cannot provide assurance that, if those risks materialize, our business strategy, results of operations or financial condition will not be materially affected in the future.
+Added: See "Risk Factors" in ITEM 1A of this Annual Report on Form 10-K for more information on our cybersecurity related risks.
Incident Response and Recovery Planning.
27 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.