6 unchanged sentences
The board of directors and audit committee periodically review the measures implemented by us to identify and mitigate risks from cybersecurity threats.
−Removed: As part of such reviews, the board of directors and audit committee receive reports and presentations from those responsible for overseeing our cybersecurity risk management, including the Partner, Chief Information Security Officer & Head of Information Technology (“CISO”) and our Legal team, which may address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to
−Removed: our peers, industry participants, service providers and other third parties.
+Added: As part of such reviews, the board of directors and audit committee receive reports and presentations from those responsible for overseeing our cybersecurity risk management, including the Partner, Chief Information Security Officer & Head of Information Technology (“CISO”) and our Legal team, which may address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers, industry participants, service providers and other third parties.
The CISO also periodically presents to the board of directors and audit committee, including to describe our information security infrastructure and improvements made, and to report on any significant developments.
28 unchanged sentences
We conduct annual penetration testing performed by a rotating group of third-party security firms to test our technical controls and security response.
−Removed: Our internal audit team has also conducted a cybersecurity assessment to test our preparedness.
+Added: Our internal audit team also facilitates periodic cybersecurity risk assessments and conducts audits relating to cybersecurity to review our processes and controls designed to mitigate cybersecurity risks.
In addition to our internal cybersecurity capabilities and third-party penetration testing, we also, at times, engage consultants or other third parties to assist with assessing, identifying, and managing cybersecurity risks.
1 unchanged sentence
Due to evolving cybersecurity threats, it has and will continue to be difficult to prevent, detect, mitigate, and remediate cybersecurity incidents.
−Removed: To date, based on information available as of the date of this annual report, we have not identified any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that we believe have materially affected, or are reasonably likely to materially affect, us, including our business strategy, results of operations, or financial condition, but we face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to have such an effect and there can be no assurance that we will not be subject to future cybersecurity attacks, threats or incidents that may materially affect our business strategy, results of operations or financial condition.
+Added: Based on information available as of the date of this annual report, we have not identified any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that we believe have materially affected, or are reasonably likely to materially affect, us, including our business strategy, results of operations, or financial condition, but we face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to have such an effect, and there can be no assurance that we will not be subject to future cybersecurity attacks, threats or incidents that may materially affect our business strategy, results of operations or financial condition.
Additional information on cybersecurity risks we face can be found in Part I, Item 1A “Risk Factors” of this Report under the heading “Cybersecurity risks and cybersecurity incidents could adversely affect our business by causing a disruption to our operations, which could adversely affect our financial condition and results of operations.”, which should be read in conjunction with the foregoing information.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.