7 unchanged sentences
Our Chief Information Officer,
−Removed: Chief Executive Officer, Vice President of Human Resources and Vice President of Operations help identify, assess and manage the Company’s
−Removed: cybersecurity threats and risks.
−Removed: They will identify and assess risks from cybersecurity threats by monitoring and evaluating our threat
−Removed: environment using various methods including, for example manual and automated tools, subscribing to reports and services that identify
−Removed: cybersecurity threats, conducting scans of the threat environment, evaluating threats reported to us, internal and external audits, conducting
−Removed: threat assessments for internal and external threats, third-party threat assessments and conducting vulnerability assessments to identify
−Removed: vulnerabilities.
+Added: Chief Legal Officer, Chief Executive Officer, Chief Financial Officer and Chief Administrative Officer help identify, assess and manage
+Added: the Company’s cybersecurity threats and risks.
+Added: They will identify and assess risks from cybersecurity threats by monitoring and
+Added: evaluating our threat environment using various methods including, for example manual and automated tools, subscribing to reports and
+Added: services that identify cybersecurity threats, conducting scans of the threat environment, evaluating threats reported to us, internal
+Added: and external audits, conducting threat assessments for internal and external threats, third-party threat assessments and conducting vulnerability
+Added: assessments to identify vulnerabilities.
Depending on the environment,
6 unchanged sentences
our Information Security Management committee will evaluate material risks from cybersecurity threats against our overall business objectives
−Removed: and reports to the audit committee of the board of directors, which evaluates our overall enterprise risk.
+Added: and report to the audit committee of the board of directors, which evaluates our overall enterprise risk.
We use third-party service
providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example,
−Removed: professional services firms, including legal counsel, cybersecurity consultants, cyber security software providers and penetration testing
+Added: professional services firms, including legal counsel, cybersecurity consultants, cybersecurity software providers and penetration testing
We use third-party service
4 unchanged sentences
we gather, store or use could harm our reputation and subject us to claims or litigation.”
−Removed: Our board of directors addresses
−Removed: the Company’s cybersecurity risk management as part of its general oversight function.
−Removed: The board of directors’ audit committee
−Removed: is responsible for overseeing Company’s cybersecurity risk management processes, including oversight of mitigation of risks from
−Removed: cybersecurity threats.
+Added: The Audit Committee assists
+Added: our board of directors in addressing the Company’s cybersecurity risk management as part of its general oversight function.
+Added: board of directors’ Audit Committee is responsible for overseeing Company’s cybersecurity risk management processes, including
+Added: oversight of mitigation of risks from cybersecurity threats.
+Added: The Audit Committee regularly reviews and discusses the Company’s cybersecurity
+Added: risks with management, including the Company’s Chief Information Officer, General Counsel, Vice President of Human Resources and
+Added: Vice President of Operations.
Our Vice President of Information
1 unchanged sentence
overall risk management strategy, and communicating key priorities to relevant personnel.
−Removed: The Chief Financial Officer is responsible
−Removed: for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments
+Added: The Chief Financial Officer is responsible for
+Added: approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments
and other security-related reports.
3 unchanged sentences
incidents of which they are notified .
−Removed: In addition, the Company’s incident response Policy will include reporting to the audit committee
−Removed: of the board of directors for certain cybersecurity incidents.
+Added: In addition, the Company’s incident response policy will include reporting certain cybersecurity
+Added: incidents to the Audit Committee of the board of directors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.