5 unchanged sentences
We have an enterprise risk management group that manages this process, which includes our executive leadership team.
−Removed: Their activities include assessing the risks, prioritizing the risks, measuring the risks, implementing mitigation plans and auditing the results.
+Added: Their activities include assessing the risks, prioritizing the risks, measuring the risks, responding to an escalating risk or crisis by implementing mitigation plans and auditing the results.
Cybersecurity Risk Management.
5 unchanged sentences
We address cybersecurity risks and threats through a strategic program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
−Removed: Our dedicated cybersecurity team oversees and implements our cybersecurity
−Removed: management program, compliance with applicable legal and third-party data privacy requirements and our incident response and crisis management plans.
−Removed: We also implemented additional security measures following the previously disclosed cybersecurity incident of July 2023, such as stronger privileged access policies and enhanced and expanded multi-factor authentication to help prevent unauthorized access to our systems.
+Added: Our dedicated cybersecurity team oversees and implements our cybersecurity management program, compliance with applicable legal and third-party data privacy requirements and our incident responses.
+Added: Our team has a crisis management plan for security, communications and disaster recovery events.
+Added: We have also implemented additional security measures following the previously disclosed cybersecurity incident of July 2023, such as stronger privileged access policies and enhanced and expanded multi-factor authentication to help prevent unauthorized access to our systems.
We face ongoing risks from certain cybersecurity threats, and we cannot provide assurance that, if those risks materialize, our business strategy, results of operations or financial condition will not be materially affected in the future.
17 unchanged sentences
In that effort, the Board delegates these responsibilities to the Audit Committee.
−Removed: The Audit Committee receives a cybersecurity update at each of its quarterly meetings from our Senior Vice President, Chief Information Officer ("CIO") or management .
+Added: The Audit Committee receives a cybersecurity update at each of its quarterly meetings from our Executive Vice President, Chief Information Officer ("CIO") or management .
These updates address a range of topics, including updates on technology trends, policies and practices, and specific and ongoing efforts to prevent, detect and respond to internal and external critical threats.
1 unchanged sentence
Our CIO , as the leader of our IT organization, is responsible for executing enterprise, product and manufacturing cybersecurity programs with a focus on security architecture, vulnerability testing, cyber risk management, incident response, vulnerability management, intelligence, awareness and training and governance.
−Removed: Our CIO and IT management team meet regularly to develop and oversee strategies to protect our data, systems and technology across the organization.
+Added: Our CIO and IT management team meet regularly to develop and oversee strategies to protect our data, systems and technology across the
+Added: organization.
These strategies include reviewing security performance metrics, identifying security risks and assessing the status of approved security enhancements.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.