4 unchanged sentences
Risk Management and Strategy
−Removed: We recognize that cybersecurity risks pose a significant threat to our business, customers, and stakeholders, and we have implemented a comprehensive cyber security program to address these risks.
+Added: We recognize that cybersecurity risks pose a significant threat to our business, clients, and stakeholders, and we have implemented a comprehensive cybersecurity program to address these risks.
We embed security considerations into every aspect of our operations, and our focus encompasses a proactive approach that involves continuous monitoring to swiftly detect and respond to emerging threats to ensure that our stakeholders' information remains secure in the face of evolving cybersecurity challenges.
−Removed: With a foundation grounded in industry best practices, including NIST 800-53, ISO 27001, CIS Top 20, and OWASP Top 10, we prioritize the identification and assessment of risks to create a protective shield around our customers' data.
+Added: With a foundation grounded in industry best practices, including NIST 800-53, ISO 27001, CIS Top 20, and OWASP Top 10, we prioritize the identification and assessment of risks to create a protective shield around our clients' data.
This guides our processes for assessing, identifying, and managing risks related to cybersecurity threats and incidents, as well as ensuring compliance with legal and contractual obligations.
Our risk management processes are integrated into our overall business strategy and operations.
−Removed: We use various methods and tools to identify and assess cybersecurity risks across all assets in our technical landscape, such as vulnerability scanning, penetration testing, threat intelligence, risk assessments, and audits from customers.
+Added: We use various methods and tools to identify and assess cybersecurity risks across all assets in our technical landscape, such as vulnerability scanning, penetration testing, threat intelligence, risk assessments, auditing our vendors and audits from clients.
We maintain robust cybersecurity incident response procedures, which includes escalating incidents to the appropriate level of management and Board of Directors, mitigation, remediation, and the assessment of materiality of cybersecurity incidents, or a series of related incidents, that may materially affect or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
−Removed: Furthermore, we conduct annual cybersecurity awareness training for our employees in order to provide them with the knowledge necessary to navigate the digital landscape securely.
−Removed: We understand that cybersecurity is not a static concept but a dynamic discipline, and our security and privacy notice reflects this by incorporating internal audits, penetration testing, active vulnerability scanning and a continuous improvement mindset.
+Added: Furthermore, we conduct annual cybersecurity awareness training for our employees to provide them with the knowledge necessary to navigate the digital landscape securely.
+Added: We understand that cybersecurity is not a static concept but a dynamic discipline, and our security and privacy notice reflect this by incorporating internal audits, penetration testing, active vulnerability scanning and a continuous improvement mindset.
As of the date of this Report, we are not aware of any cybersecurity incidents, or a series of related incidents, that have had or are reasonably likely to have a material impact on the Company’s results of operations or financial condition.
4 unchanged sentences
In the oversight of the program, the Board is focused on cybersecurity risk, including incident response planning, timely identification and assessment of incidents, incident recovery and business continuity considerations.
−Removed: We have engaged a third party consulting firm, VeraSafe, as our DPO.
−Removed: The DPO is responsible for ensuring that we have a Personal Data Protection program in place that is compliant with data privacy laws such as the EU GDPR, UK GDPR, China’s PIPL, and data privacy laws enacted at the state level, as applicable to us.
+Added: The Data Protection Officer ("DPO") is responsible for ensuring that we have a Personal Data Protection program in place that is compliant with data privacy laws such as the EU GDPR, UK GDPR, China’s PIPL, and data privacy laws enacted at the state level, as applicable to us.
Our corporate Personal Data Protection program includes policies, practices, and training directed to protecting personal data .
We have defined roles and responsibilities for the management of cybersecurity risks, including specific executive-level and management-level positions or committees.
−Removed: Our security program is overseen by our VP of Information Technology, supported by corporate leadership from legal and finance.
+Added: Our security program is overseen by our VP of Information Technology, supported by corporate leadership from legal, compliance and finance.
Our VP of Information Technology and the support team is accountable for the program.
−Removed: Our function and business unit executive leadership, acting in support of the VP of Information Technology and the Board, is responsible for ensuring organizational compliance with data protection regulations and controls across the organization.
−Removed: Our VP of Information Technology and Data Privacy Officer, are responsible for the design, implementation, and monitoring of the security and privacy policies, standards, procedures, and controls that govern our information systems and data processing activities.
+Added: Our functional area executive leadership, acting in support of the VP of Information Technology, the DPO and the Board, is responsible for ensuring organizational compliance with data protection regulations and controls across the organization.
+Added: Our VP of Information Technology and DPO, are responsible for the design, implementation, and monitoring of the security and privacy policies, standards, procedures, and controls that govern our information systems and data processing activities.
Our VP of Information Technology and support team also have a reporting responsibility to the executive leadership and the Board.
1 unchanged sentence
The Board receives regular reports from management on our cybersecurity program, risks and activity .
+Added: Our VP of Information Technology has more than 25 years of experience in IT infrastructure, cybersecurity operations, and software engineering.
We have established processes to ensure that management is informed about and monitors cybersecurity incident prevention, detection, mitigation, and remediation.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.