12 unchanged sentences
Our Board of Directors has overall responsibility for risk oversight and oversees the implementation and continuous improvement of our cybersecurity program and compliance with disclosure requirements.
−Removed: The Board of Directors receives regular reports and periodic briefings from the Chief Executive Officer (in view of the absence of a Chief Financial Officer) on cybersecurity matters, including key risks to the Company, recent developments, and risk mitigation activities.
−Removed: Our cybersecurity program is overseen by the Chief Executive Officer (in view of the absence of a Chief Financial Officer) in conjunction with a third-party service provider.
+Added: The Board of Directors receives regular reports and periodic briefings from the Chief Financial Officer on cybersecurity matters, including key risks to the Company, recent developments, and risk mitigation activities.
+Added: Our cybersecurity program is overseen by the Chief Financial Officer in conjunction with a third-party service provider.
The third-party service provider has the primary responsibility for the Company’s cybersecurity risk management program.
1 unchanged sentence
Incident Disclosure
−Removed: To date, the Company has been subject to cyber related incidents , as previously disclosed in the Company’s Quarterly Report for the quarters ended June 30, 2023 and September 30, 2023 and within this Annual Report.
−Removed: Since the identification of these incidents, we have implemented additional safeguards designed to detect and prevent cybersecurity events that may have a material adverse effect on the Company.
+Added: To date, the Company has been subject to cyber related incidents , as previously disclosed in the Company’s Quarterly Report for the quarters ended June 30, 2023, September 30, 2023, September 30, 2024, March 31, 2025, June 30, 2025, September 30, 2025 and as disclosed in its Form 10-K for the year ended December 31, 2024 and within this Annual Report.
+Added: The Company identified a ransomware incident early in 2025 in which the Company recovered the Company’s operating systems and no ransom was paid by the Company.
+Added: The Company, together with a third-party consulting firm, investigated such incident and our investigation determined in the first quarter of 2026 that the incident resulted in the exfiltration of some employee information, including names, addresses, and Social Security numbers.
+Added: The process of notifying affected individuals is ongoing.
+Added: While we have not experienced a material impact on our operations to date, with our systems being back online in a relatively short period of time and most out-of-pocket expenses covered by cyber insurance, the incident may expose us to regulatory inquiries or litigation.
+Added: We have implemented additional safeguards designed to detect and prevent cybersecurity events in the future.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.