Unresolved Staff Comments
−Removed: Cybersecurity - Risk Management, Strategy and Governance
+Added: Cybersecurity
Cybersecurity Strategy, Policy and Procedures
1 unchanged sentence
These risks include, among other things, operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
−Removed: We utilize information technology (“IT”) that enables our teams to access both operational and financial performance data in real time, while at the same time, identifying and preventing cybersecurity threats and risks.
+Added: We utilize information technology (“IT”) that enables our teams to access both operational and financial performance data in real time, while at the same time, helping to identify and prevent cybersecurity threats and risks.
Risk Management and Strategy
2 unchanged sentences
We assess and identify cybersecurity risk to the organization by:
−Removed: Tab l e of Contents
• Employing a cybersecurity policy that sets forth a protocol for assessing, testing, identifying and preventing security risks;
−Removed: • Conducting assessments of risk likelihood and magnitude from unauthorized access, use, disclosure, disruption, modification or destruction of IT systems and the related information processes, stored, or transmitted;
+Added: • Conducting assessments of risk likelihood and magnitude from unauthorized access, use, disclosure, disruption, modification or destruction of IT systems and the related information processes, storage, or transmission;
• Training personnel on security risks and how to identify and prevent such risks;
1 unchanged sentence
• Overseeing and identifying any risk from cyber threats associated with any third-party service provider ;
−Removed: • Ensuring security controls are assessed for effectiveness, are implemented correctly, operating as intended;
−Removed: • Continuously scanning for vulnerabilities and remedying all vulnerabilities in accordance with the associated risk.
+Added: • Ensuring security controls are assessed for effectiveness, implemented correctly and operating as intended;
+Added: • Continuously scanning for vulnerabilities and remedying vulnerabilities in accordance with the associated risk.
Cybersecurity is among the risks identified for Board-level oversight, with the Audit Committee of our Board of Directors responsible for overseeing our policies, practices, and assessments with respect to cybersecurity.
−Removed: Our Audit Committee and Board of Directors receive regular updates throughout the year on cybersecurity from our Finance, Risk and Sustainability (the “FRS”) Committee, which is tasked with risk management, data protection, and monitoring compliance with our cybersecurity policy.
+Added: Our Audit Committee and Board of Directors receive regular updates throughout the year on cybersecurity from our Finance, Risk and Sustainability (the “FRS”) Committee, which is tasked with risk management, data protection, and monitoring compliance with our cybersecurity policy and also responsible for assessing and managing material risks from cybersecurity threats.
The FRS Committee is comprised of our Chief Financial Officer, Chief Legal Officer, Chief Operating Officer, Senior Vice President of IT, and VP of Corporate Development.
−Removed: Each of our Board of Directors and Audit Committee member separately receives an annual report on cybersecurity matters and related risk exposures, and when the report is covered during an Audit Committee meeting, the chair of the Audit Committee reports on its related matters to our Board of Directors.
+Added: Our cybersecurity risk management and strategy processes are led by our Senior Vice President of IT and our Chief Legal Officer , who collectively have extensive prior work experience and expertise over multiple decades developing and managing information security and cybersecurity strategy and programs and managing operational risk and incident response strategies.
+Added: Each member of our Board of Directors and Audit Committee also receives a quarterly report on cybersecurity matters and related risk exposures, and when the report is discussed during an Audit Committee meeting, the chair of the Audit Committee reports on related matters to our Board of Directors.
Our Audit Committee also receives regular updates on our cybersecurity posture throughout the year, as appropriate.
−Removed: In accordance with our cybersecurity policy, we have established a continuous monitoring strategy and program which includes:
+Added: In accordance with our cybersecurity policy, we have established a monitoring strategy and program which includes:
• Defined security metrics to be monitored;
• Performance of security control assessments on an ongoing basis;
−Removed: • Engaging third party security consultants to, among other things, conduct a review of our cybersecurity program which is overseen by the FRS Committee for identifying any cybersecurity threats;
−Removed: • Addressing results of analysis and reporting security status to the executive team;
+Added: • Engaging third party security consultants to, among other things, conduct periodic reviews of our cybersecurity program, which is overseen by the FRS Committee, for identifying any cybersecurity threats ;
+Added: • Addressing results of both internal and third-party cybersecurity analyses and reporting security status to the executive team;
• Monitoring information systems to detect attacks and indicators of potential attacks;
1 unchanged sentence
Data Protection
−Removed: We have also implemented procedures set forth in our cybersecurity policy that secure sensitive data protected by us, which include:
+Added: We have also implemented procedures set forth in our cybersecurity policy that secure sensitive data in our possession, which include:
• Establishing policies governing data security;
3 unchanged sentences
• Designing and implementing systems to include backup and recoverability principles, such as periodic data backups and safeguards in the case of a disaster.
−Removed: Tab l e of Contents
Incident Management Plan
Our cybersecurity policy includes an incident management plan (“IMP”), which consists of the following processes:
−Removed: • The development, documentation, review and testing of security procedures and incident management procedures, which are continually re-assessed, updated and tested;
+Added: • The development, documentation, review and testing of security procedures and incident management procedures, which are regularly re-assessed, updated and tested;
• The FRS Committee reviews any identified matters by assessment, verification and classification of incidents to determine affected stakeholders and appropriate parties for contact;
−Removed: • The FRS Committee notifies the Board of Directors and the Audit Committee to validate that the response is being addressed appropriately;
+Added: • The FRS Committee notifies the Board of Directors and the Audit Committee;
• The FRS Committee consults with outside experts, if determined that the incident rises to a significant level;
3 unchanged sentences
• The FRS Committee reviews the closure of each incident and conducts a “lessons learned” analysis to improve prevention and ensure the IMP and cybersecurity plans are more efficient and effective.
−Removed: We face several cybersecurity risks in connection with just conducting business.
−Removed: Although such risks have not materially affected us, including our business strategy, results of operations or financial condition, to date, we have, from time to time, experienced threats to and breaches of our data and systems, including malware and computer virus attacks.
+Added: We have faced and continue to face cybersecurity risks in connection with the conduct of our business.
+Added: Although we do not believe such risks have materially affected us, including our business strategy, results of operations or financial condition, to date, we have, from time to time, experienced threats to and breaches of our data and systems, including malware and computer virus attacks.
Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.