10 unchanged sentences
Our processes and technologies include firewalls, email security software and encryption, endpoint detection and response, access controls, backup and recovery procedures, system patches and updates, vulnerability scanning, penetration testing by third party vendors, incident response procedures, and internal and external audits of our information systems.
+Added: For example, in October 2025, we engaged an external auditor to perform a System and Organization Controls 2 (SOC 2) examination of the design of our security controls.
Through these internal and external assessments, we continuously identify areas for remediation and opportunities to improve the security of our information systems, including by evaluating our program against industry standards and best practices, such as the Cybersecurity Framework established by the National Institute of Standards and Technology (NIST) and the CIS Critical Security Controls established by the Center for Internet Security.
2 unchanged sentences
Cybersecurity Governance
−Removed: The Audit Committee of our Board of Directors oversees the adequacy and effectiveness of our internal controls, policies and procedures regarding cybersecurity, information security and data protection, and compliance with applicable laws and
−Removed: regulations concerning privacy.
+Added: The Audit Committee of our Board of Directors oversees the adequacy and effectiveness of our internal controls, policies and procedures regarding cybersecurity, information security and data protection, and compliance with applicable laws and regulations concerning privacy.
Our Chief Information Officer (“CIO”) , in turn, is responsible for managing the Company’s cybersecurity risk management program and incident response procedures.
−Removed: On a quarterly basis, and more frequently as circumstances warrant, our CIO briefs the Audit Committee on our cybersecurity risks, our strategies for preventing, detecting, responding to and mitigating such risks, including the effectiveness of our incident response procedures, and our information security controls.
+Added: On a quarterly basis, and more frequently as circumstances warrant, our CIO briefs the Audit Committee on our cybersecurity risks, our strategies for preventing, detecting, responding to and mitigating such risks, including the results of our SOC 2 audits, the effectiveness of our incident response procedures, and our information security controls.
Our CIO has extensive knowledge and expertise regarding our information systems and security, having served in a variety of senior information technology positions across our organization for more than thirty years, and as an executive officer of the Company since 2006.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.