16 unchanged sentences
training which includes phishing attack simulation testing.
−Removed: key element of the Company’s Cybersecurity System is to mature the program to align with the Center for Internet Security
−Removed: (CIS) Critical Security Controls security framework.
−Removed: The CIS controls are designed based on real-world data about cyber-attacks, to
−Removed: ensure that the measures are effective against current threats.
−Removed: The framework provides a prioritized set of actions, which enables
−Removed: the Company to focus its efforts on the most effective defensive measures first.
−Removed: This prioritization helps in optimizing the use of
−Removed: resources for maximum impact on security.
−Removed: This strategy provides a structured and effective approach to cybersecurity, helping the
−Removed: Company to protect its assets, comply with regulations, manage risks, and improve its overall security posture.
+Added: key element of the Company’s Cybersecurity System is to mature the program to align with the Center for Internet Security (CIS)
+Added: Critical Security Controls security framework.
+Added: CIS controls are designed based on real-world data about cyber-attacks, to ensure that
+Added: the measures are effective against current threats.
+Added: The framework provides a prioritized set of actions, which enables the Company to
+Added: focus its efforts on the most effective defensive measures first.
+Added: This prioritization helps in optimizing the use of resources for maximum
+Added: impact on security.
+Added: This strategy provides a structured and effective approach to cybersecurity, helping the Company to protect its assets,
+Added: comply with regulations, manage risks, and improve its overall security posture.
Company maintains cyber insurance coverage that may, subject to policy terms, conditions, and limitations, cover certain aspects of cybersecurity
6 unchanged sentences
oversight responsibility of information security risks to its Audit Committee.
−Removed: Matters determined to present potential material impacts to the Company’s financial
−Removed: results, operations, and/or reputation are reported by management to the Company’s Board of Directors or its Audit
−Removed: Committee, as appropriate, in accordance with its escalation framework.
−Removed: addition, the Company has established procedures to ensure that management personnel are informed in a timely manner of known
−Removed: cybersecurity risks and incidents that may materially impact the Company’s operations and that timely public disclosure is
−Removed: made as appropriate.
−Removed: The Company’s Cybersecurity System is led by the Chief Information Officer (“CIO”) in
−Removed: collaboration with a third-party virtual Chief Information Security Officer (“vCISO”) and other third-party
−Removed: cybersecurity service providers which in turn assist in monitoring the Company’s exposure from significant information
−Removed: technology suppliers, significant software as service providers and major vendors with access to the Company’s information
−Removed: technology systems.
−Removed: The Company’s CIO has 10 years of cybersecurity industry experience.
−Removed: Further, team members who support the
−Removed: Company’s cybersecurity program have relevant educational and industry experience through various roles involving information
−Removed: technology, security, auditing, compliance, systems, and programming, as well as cybersecurity certifications such as a Certified
−Removed: Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM).
−Removed: During the last three years, the Company has not experienced a material security breach and, as a
−Removed: result, the Company has not incurred any material expenses from such a breach.
−Removed: Furthermore, during such time, the Company has not
−Removed: been penalized or paid any amount under any information security breach settlement.
+Added: Matters determined to present potential material impacts
+Added: to the Company’s financial results, operations, and/or reputation are reported by management to the Company’s Board of Directors
+Added: or its Audit Committee, as appropriate, in accordance with its escalation framework.
+Added: addition, the Company has established procedures to ensure that management personnel are informed in a timely manner of known cybersecurity
+Added: risks and incidents that may materially impact the Company’s operations and that timely public disclosure is made as appropriate.
+Added: The Company’s Cybersecurity System is led by the Chief Information Officer (“CIO”) in collaboration with a third-party
+Added: virtual Chief Information Security Officer (“vCISO”) and other third-party cybersecurity service providers which in turn
+Added: assist in monitoring the Company’s exposure from significant information technology suppliers, significant software as service
+Added: providers and major vendors with access to the Company’s information technology systems.
+Added: The Company’s CIO has 10+ years
+Added: of cybersecurity industry experience.
+Added: Further, team members who support the Company’s cybersecurity program have relevant educational
+Added: and industry experience through various roles involving information technology, security, auditing, compliance, systems, and programming,
+Added: as well as cybersecurity certifications such as a Certified Information Systems Security Professional (CISSP) and Certified Information
+Added: Security Manager (CISM).
+Added: During the last three years, the Company has not experienced a material security breach and, as a result, the
+Added: Company has no t incurred any material expenses from such a breach.
+Added: Furthermore, during such time, the Company has not been penalized
+Added: or paid any amount under any information security breach settlement.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.