2 unchanged sentences
Risk Management and Strategy
−Removed: We regularly assess risks from cybersecurity threats;
−Removed: monitor our information systems for potential vulnerabilities;
−Removed: and test those systems pursuant to our information technology policies, processes, and practices, which are integrated into our overall risk management program.
−Removed: To protect our information systems from cybersecurity threats, we use various security tools that are designed to help identify, escalate, investigate, resolve, and recover from security incidents in a timely manner.
+Added: We regularly assess risks from cybersecurity threats, including through periodic risk assessments aligned with recognized cybersecurity risk management frameworks, and monitor our information systems for potential vulnerabilities.
+Added: These activities are integrated into our enterprise risk management program and are designed to identify, escalate, investigate, resolve, and recover from cybersecurity incidents in a timely manner.
The Company’s Chief Information Officer is responsible for developing and implementing our information security program and reporting on cybersecurity matters to the Board.
1 unchanged sentence
We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises at a management level and engage external resources and advisors as needed.
−Removed: All employees are required to complete cybersecurity trainings each month through online trainings and simulations.
+Added: All employees are required to complete regular cybersecurity training through online courses and simulated exercises.
We collaborate with third parties to assess the effectiveness of our cybersecurity prevention and response systems and processes.
These include cybersecurity assessors, consultants, and other external cybersecurity experts to assist in the identification, verification, and validation of cybersecurity risks, as well as to support associated mitigation plans when necessary.
−Removed: We have also developed a third -party cybersecurity risk management process to conduct due diligence on external entities, including those that perform cybersecurity services.
+Added: We have developed a third -party cybersecurity risk management process that applies a risk-based approach to due diligence and oversight of external entities, including vendors and service providers with access to Company systems or sensitive data.
To date, risks from cybersecurity threats, including those resulting from any previous cybersecurity incidents, have not materially affected our Company, including our business strategy, results of operations, or financial condition.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.