1 unchanged sentence
Cybersecurity.
−Removed: Company employs internal resources and third-party service providers to manage, operate and administer our day-to-day operations, business
−Removed: and affairs, subject to the direction and supervision of the Board.
−Removed: The Board recognizes the critical importance of maintaining the trust
−Removed: and confidence of our business partners.
−Removed: The Board plays an active role in overseeing management of our risks, and cybersecurity represents
−Removed: an important component of the Company’s overall approach to risk management and oversight.
−Removed: The Company and its management are committed
−Removed: to protecting the confidentiality of all non-public information related to the Company’s clients, shareholders and their personnel.
Management and Strategy
−Removed: Company relies on its Management and employees to execute its comprehensive cybersecurity program, and has adopted a written information
−Removed: security program, which is designed to address applicable requirements under Regulation S-P and the FTC Safeguards Rule .
−Removed: Consequently,
−Removed: the Company also relies on the processes for assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: The processes
−Removed: include, among other things, maintaining secure digital or physical access to information assets, using manual and automated detection
−Removed: methods for malicious code, due diligence of third-party vendors, and engaging a leading provider of cybersecurity services to assess
−Removed: and manage cybersecurity risk.
−Removed: For third-party service vendors that perform a variety of important functions for our business, we seek
−Removed: to engage reliable, reputable service vendors that maintain cybersecurity programs.
−Removed: of the Company’s officers and employees are subject to its policies and procedures.
−Removed: The Company utilizes both internal and third-party
−Removed: cybersecurity services, including threat detection and response, vulnerability assessment and monitoring, security incident response
−Removed: and recovery and general cybersecurity education and awareness.
−Removed: We engage in periodic assessment and training regarding the policies,
−Removed: standards and practices designed to address cybersecurity threats and incidents.
−Removed: Our cybersecurity risk management is integrated into
−Removed: our overall enterprise risk management and shares common methodologies, reporting channels and governance processes that apply across
−Removed: our enterprise risk management.
−Removed: date, we have not experienced any cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially
−Removed: affected the Company and we are not aware of any cybersecurity threats that are reasonably likely to affect the Company, including its
+Added: Company has implemented a written information security program designed to address the confidentiality, integrity, and availability of
+Added: information systems and the non-public personal information the Company holds on behalf of its clients and business partners.
+Added: is designed to comply with applicable requirements under Regulation S-P and the Federal Trade Commission Safeguards Rule.
+Added: Company’s cybersecurity risk management program includes the following key elements:
+Added: Detection and Response:
+Added: The Company uses a combination of automated tools and manual procedures to detect, contain, and respond
+Added: to cybersecurity threats, including malicious code detection, network monitoring, and security incident response protocols
+Added: Vulnerability
+Added: The Company engages a third-party cybersecurity service provider it believes is qualified to conduct periodic vulnerability
+Added: assessments, penetration testing, and risk evaluations of the Company’s information systems.
+Added: Vendor Risk Management:
+Added: Before engaging service providers that will access, transmit, or store Company or client data, management
+Added: performs due diligence to evaluate their cybersecurity practices.
+Added: The Company seeks to engage vendors that maintain cybersecurity
+Added: programs reasonably consistent with the Company’s own standards.
+Added: Training and Awareness:
+Added: All officers and employees are subject to the Company’s information security policies and procedures
+Added: and are required to participate in periodic cybersecurity education and awareness training.
+Added: with Enterprise Risk Management:
+Added: The Company’s cybersecurity risk management program
+Added: is integrated into its broader enterprise risk management framework and utilizes the same
+Added: common reporting channels and governance processes and the broader framework.
+Added: ● Third-Party
+Added: The Company engages an external cybersecurity services provider to assist
+Added: in assessing and managing cybersecurity risks.
+Added: This provider supports threat monitoring,
+Added: incident response planning, and periodic assessments of the effectiveness of the Company’s
+Added: security controls.
+Added: Cybersecurity Incidents.
+Added: To date, the Company has not experienced any cybersecurity incident
+Added: that has materially affected, or is reasonably likely to materially affect, the Company’s
business strategy, results of operations, or financial condition.
−Removed: oversees the Company’s cybersecurity risk management process.
−Removed: Management has adopted a charter that provides to periodically review
−Removed: and discuss with the Board the guidelines and policies with respect to risk assessment and risk management of cybersecurity and other
−Removed: risk exposures relevant to the Company’s computerized information system controls and security.
−Removed: Management may receive additional
−Removed: training in cybersecurity and data privacy matters to enable its oversight of such risks.
−Removed: Management will report to the Board on the
−Removed: substance of such reviews and discussions and, as necessary, recommend to the Board such actions as management deems appropriate.
−Removed: noted above, the Company relies on our internal Information Systems in connection with the Company’s day-to-day operations.
−Removed: Company relies on the internal processes for assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: Company’s Chief Financial Officer, Chief Legal Officer, and Head of IT work collaboratively with other employees of the Company
−Removed: to ensure protection of the Company’s Information Systems from cybersecurity threats and to promptly respond to any cybersecurity
−Removed: These members of the Company’s management team monitor the prevention, detection, mitigation and remediation of cybersecurity
−Removed: threats and incidents and report such threats and incidents to the board when appropriate.
−Removed: They have gained relevant knowledge, skills
−Removed: and experience in information technology and cybersecurity risk management, including overseeing third-party vendors in such areas, over
−Removed: their careers at the Company or other organizations.
+Added: However, we cannot guarantee
+Added: that future incidents will not occur or will not be material.
+Added: See Part I, Item 1A., “Risk
+Added: Factors––Risks Related to Legal Proceedings and Regulatory Compliance––An
+Added: interruption in, or breach of security of, our information systems could adversely affect
+Added: Board of Directors recognizes that cybersecurity is an important component of the Company’s overall risk management framework.
+Added: The Board has delegated primary oversight responsibility for cybersecurity risk to management, which periodically briefs the Board
+Added: on the status of the cybersecurity program, material developments, and the threat environment.
+Added: Management reviews and
+Added: discusses with the Board the guidelines and policies with respect to risk assessment and risk management of cybersecurity and other
+Added: relevant risks related to the Company’s information systems.
+Added: The Board receives updates from management on cybersecurity
+Added: matters as needed or when a significant incident or emerging risk warrants attention.
+Added: Responsibility
+Added: responsibility for the cybersecurity program is managed by Jeremy Robinson, the Company’s Vice President of Information Technology,
+Added: who oversees the design, implementation, and maintenance of the Company’s information security program , including:
+Added: the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents;
+Added: relationships with third-party cybersecurity service providers;
+Added: material cybersecurity threats or incidents to the Chief Executive Officer and, where appropriate, to the Board.
+Added: Company believes that Mr.
+Added: Robinson has developed relevant knowledge, skills, and experience in information technology and cybersecurity
+Added: risk management through his career in the information technology sector, including his experience overseeing third-party vendors, evaluating
+Added: security controls, and responding to information security risks.
+Added: The Chief Executive Officer is responsible for ensuring that material
+Added: cybersecurity matters are escalated to the Board in a timely manner , although Mr.
+Added: Robinson may also report material cybersecurity threats
+Added: or incidents to the Board.
+Added: Company maintains cybersecurity incident response procedures that provide a framework for identifying, assessing, containing, and remediating
+Added: cybersecurity incidents, including procedures for timely reporting to the Board and, where required, to regulators and affected individuals
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.