18 unchanged sentences
based on recognized frameworks established by the National Institute of Standards and Technology.
−Removed: The Company has established controls and procedures, including an Incident
−Removed: Response Plan, that provide for the identification, analysis, notification, escalation, communication, and remediation of data security
−Removed: incidents at appropriate levels so that so that decisions regarding the public disclosure and reporting of such incidents can be made
−Removed: by management in a timely manner.
−Removed: In particular, the Company’s Incident Response Plan (i) is designed to identify and detect information
−Removed: security threats through various mechanisms, such as through security controls and third-party disclosures, and (ii) sets forth a process
−Removed: to (a) analyze any such threats detected within the Company’s IT environment or within a third-party’s IT environment, (b)
−Removed: contain cybersecurity threats under various circumstances, and (c) better ensure the Company can recover from cybersecurity incidents
−Removed: to a normal state of business operations.
−Removed: The Company has established and maintains other incident response and recovery plans that
−Removed: address the Company’s response to a cybersecurity incident.
+Added: The Company has established controls
+Added: and procedures, including an Incident Response Plan, that provide for the identification, analysis, notification, escalation, communication,
+Added: and remediation of data security incidents at appropriate levels so that so that decisions regarding the public disclosure and reporting
+Added: of such incidents can be made by management in a timely manner.
+Added: In particular, the Company’s Incident Response Plan (i) is designed
+Added: to identify and detect information security threats through various mechanisms, such as through security controls and third-party disclosures,
+Added: and (ii) sets forth a process to (a) analyze any such threats detected within the Company’s IT environment or within a third-party’s
+Added: IT environment, (b) contain cybersecurity threats under various circumstances, and (c) better ensure the Company can recover from cybersecurity
+Added: incidents to a normal state of business operations.
+Added: The Company has established and maintains other incident response and recovery plans
+Added: that address the Company’s response to a cybersecurity incident.
part of its cybersecurity program, the Company deploys measures to deter, prevent, detect, respond to and mitigate cybersecurity threats,
1 unchanged sentence
and physical security measures.
−Removed: The Company periodically assesses and tests the Company’s policies, standards,
−Removed: processes, and practices that are designed to address cybersecurity threats and incidents, including by assessing current threat intelligence,
−Removed: conducting tabletop exercises, and vulnerability and security testing,.
−Removed: The Company has a process to report material
−Removed: results of such testing and assessments to the board, and periodically adjusts the Company’s cybersecurity program
−Removed: based on these exercises.
−Removed: The Company engages third parties to conduct part of such testing The Company identifies and oversees cybersecurity risks presented by third parties and their systems from a risk-based
−Removed: perspective The Company also conducts cybersecurity
−Removed: training for employees (including mandatory training programs for system users).
+Added: The Company periodically assesses and tests the Company’s policies, standards, processes, and practices
+Added: that are designed to address cybersecurity (including artificial intelligence-related) threats and incidents, including by assessing
+Added: current threat intelligence, and conducting tabletop exercises and vulnerability and security testing.
+Added: The Company has a process to report
+Added: material results of such testing and assessments to the board, and periodically adjusts the Company’s cybersecurity program based
+Added: on these exercises.
+Added: The Company engages third parties to conduct part of such testing, including hiring consultants and third parties
+Added: to conduct our threat assessments and supplement the monitoring of such threats by utilizing online data tools .
+Added: The Company identifies
+Added: and oversees cybersecurity risks presented by third parties and their systems from a risk-based perspective .
+Added: The Company also conducts
+Added: cybersecurity training for employees (including mandatory training programs for system users).
of the Company’s IT systems operate with a hosted architecture or by third-party service providers, and if these third-party IT
2 unchanged sentences
vendor management process is an important part of our risk mitigation strategy.
−Removed: In particular, we obtain reports from our vendors handling sensitive data as to their efficacy and efficiency in managing cybersecurity
−Removed: issues and follow-up with them on any potential or actual issues.
−Removed: Notwithstanding, if there is a catastrophic event, such as an adverse weather condition, natural disaster, terrorist attack, security
−Removed: breach, or other extraordinary event, the Company, and our service providers, may be unable to provide our products or services for the
−Removed: duration of the event and/or a time thereafter.
+Added: In particular, we obtain reports from our vendors handling
+Added: sensitive data as to their efficacy and efficiency in managing cybersecurity issues and follow-up with them on any potential or actual
+Added: Notwithstanding, if there is a catastrophic event, such as an adverse weather condition, natural disaster, terrorist attack,
+Added: security breach, or other extraordinary event, the Company, and our service providers, may be unable to provide our products or services
+Added: for the duration of the event and/or a time thereafter.
the pervasive and increasing threat from cyberattacks, the board and the audit committee, with input from management, assess the Company’s
2 unchanged sentences
with management regarding ongoing cybersecurity initiatives, and requests management to report to the audit committee or the full board
−Removed: regularly on their assessment of the Company’s cybersecurity program and risks.
−Removed: Both the audit committee and the full board will
−Removed: receive regular reports from its senior management on cybersecurity risks, timely reports regarding any cybersecurity incident that meets
−Removed: established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: Our board has risk
−Removed: management experience.
−Removed: We hire consultant and third parties to conduct our threat assessments and supplement the monitoring of such threats
−Removed: by utilizing online data tools.
−Removed: addition, the Company’s information security and/cybersecurity program is managed by our Chief Technology Officer
−Removed: (“CTO”) a, whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards,
−Removed: architecture, and processes.
−Removed: The CTO provides periodic reports to our audit committee as well as our Co-Chief Executive Officers and
−Removed: Chief Financial Officer and other members of our senior management as appropriate.
−Removed: We have also established cross-functional teams
−Removed: to collaborate and communicate on cybersecurity-related issues.
−Removed: The reports to management include updates on the Company’s
−Removed: cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information
−Removed: security program, and the emerging threat landscape.
−Removed: Eliran Ben-Zikri served in the one of the most elite computer units of the Israeli Defense Force and has
−Removed: over 10 years of experience in the cloud technology, previously holding senior positions in leading Israeli technology companies, including
−Removed: eToro and SimilarWeb.
−Removed: of the date of this report, the Company is not aware of risks from cybersecurity threats that have materially
−Removed: affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or
−Removed: financial condition.
+Added: regularly on their assessment of the Company’s cybersecurity program and risks, including artificial intelligence.
+Added: Both the audit
+Added: committee and the full board receive regular reports from senior management on cybersecurity risks and timely reports regarding any cybersecurity
+Added: incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: Our board has risk management experience.
+Added: addition, the Company’s information security and/cybersecurity program is managed by our Chief Technology Officer (“CTO”),
+Added: whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
+Added: provides periodic reports to our audit committee as well as our Co-Chief Executive Officers and Chief Financial Officer and other members
+Added: of our senior management as appropriate.
+Added: We have also established cross-functional teams to collaborate and communicate on cybersecurity-related
+Added: The reports to management include updates on the Company’s cyber risks and threats, the status of projects to strengthen
+Added: our information security systems, assessments of the information security program, and the emerging threat landscape.
+Added: Ben-Zikri served in the one of the most elite computer units of the Israeli Defense Force and has over 10 years of experience in the
+Added: cloud technology, previously holding senior positions in leading Israeli technology companies, including eToro and SimilarWeb .
+Added: of the date of this report, the Company has no t identified any cybersecurity threats or incidents that have materially affected or are
+Added: reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: there can be no assurance that the Company, or its third-party business partners or service providers, will not experience a cybersecurity
+Added: threat or incident in the future that could materially adversely affect the Company, including its business strategy, results of operations,
+Added: or financial condition.
+Added: For further discussion of the risks related to cybersecurity, see the risk factors discussed under Item 1A.
+Added: Factors” in this report.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.