24 unchanged sentences
The Audit and Finance Committee of the Board is responsible for providing oversight of our information security program and cybersecurity risks.
−Removed: In connection with this oversight role, the Audit and Finance Committee receives information technology updates from management at least quarterly.
+Added: In connection with this oversight role, the Audit and Finance Committee receive information technology updates from management at least quarterly.
Cybersecurity risks facing the Company and updates on the Company’s practices and progress to mitigate such risks are also the subject of management reports to the Audit and Finance Committee on a more frequent basis, as necessary or appropriate.
Management’s Role in Assessing and Managing Risk
−Removed: The Company’s information security efforts are led by our Executive Vice President, Chief Technology Officer (“CTO”) and our Director of Information Security (“IT Director”) , supported by our executive management team.
+Added: The Company’s information security efforts are led by our Executive Vice President, Chief Technology Officer (“CTO”) and our Vice President, Cybersecurity and Chief Information Security Officer (“CISO”) supported by our executive management team.
These efforts are designed to address information security governance and risk, product security, identification and protection of critical assets, third-party risk, security awareness, cyber defense operations, artificial intelligence and data protection governance, and related risk management matters.
−Removed: Our CTO and IT Director have an average of over 25 years of prior work experience in various roles involving information technology, including security, auditing compliance, systems and programming.
+Added: Our CTO and CISO have an average of over 23 years of prior work experience in various roles involving information technology, cybersecurity strategy and governance, incident response, cyber intelligence, cybersecurity consulting, cyber audits, cyber compliance and national security and intelligence.
These individuals have relevant educational and industry experience, including holding similar positions at other large companies.
−Removed: Our CTO provides relevant cybersecurity and information technology reports to the Audit and Finance Committee, and to the executive and senior leadership teams.
−Removed: These reports are provided at quarterly Audit and Finance Committee meetings and at our Digital Quarterly Business Review (“Digital QBR”) meetings.
+Added: Our CTO and CISO provide relevant cybersecurity and cybersecurity technology reports to the Audit and Finance Committee, and to the executive and senior leadership teams.
+Added: These reports are provided at quarterly Audit and Finance Committee meetings, quarterly Cybersecurity Steering Committee meetings, and at our Digital Quarterly Business Review meetings.
These reports typically include analyses of recent significant cybersecurity threats and incidents at the Company and across the industry, as well as a review of our security controls, assessments and program maturity, top risks, risk mitigation status, and a review of our third-party service providers as appropriate.
Simpson’s information security roadmap and posture are also reviewed quarterly with members of the executive leadership team and the Audit and Finance Committee.
−Removed: In accordance with our information security program, any information security event is assessed and reviewed by our Digital Leadership team and members of the executive leadership team.
−Removed: Through the Digital QBR process, the executive leadership team is responsible for assessing and reviewing our information security program and the Company’s material risks from cybersecurity threats.
−Removed: Additional supervision and management is provided by our Digital Leadership team, comprised of our CTO;
−Removed: VP, Digital Infrastructure and Operations;
−Removed: VP, Digital Enterprise Applications;
−Removed: and International IT Director.
+Added: In accordance with our cybersecurity program, any cybersecurity incident is assessed and reviewed by our Digital Leadership team and members of the executive leadership team.
+Added: Through the Cybersecurity Steering Committee, executive leadership is responsible for assessing and reviewing our cybersecurity program and the Company’s material risks from cybersecurity threats.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.