6 unchanged sentences
The board of directors and audit committee periodically review the measures implemented by us to identify and mitigate risks from cybersecurity threats.
−Removed: As part of such reviews, the board of directors and audit committee receive reports and presentations from those responsible for overseeing our cybersecurity risk management, including the Managing Director, Head of Information Technology (“Head of IT”) and our Legal team, which may address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers, industry
−Removed: participants, service providers and other third parties.
−Removed: The Head of IT also periodically presents to the board of directors and audit committee, including to describe our information security infrastructure and improvements made, and to report on any significant developments.
+Added: As part of such reviews, the board of directors and audit committee receive reports and presentations from those responsible for overseeing our cybersecurity risk management, including the Partner, Chief Information Security Officer & Head of Information Technology (“CISO”) and our Legal team, which may address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to
+Added: our peers, industry participants, service providers and other third parties.
+Added: The CISO also periodically presents to the board of directors and audit committee, including to describe our information security infrastructure and improvements made, and to report on any significant developments.
From time to time, external legal advisers provide education to the board of directors and/or audit committee in respect of information security related developments and to provide training in respect of directors’ responsibilities.
We have a framework under which certain cybersecurity incidents are escalated and, where appropriate, reported to the board of directors or audit committee in a timely manner.
−Removed: We have a cybersecurity working group composed of members of the Information Technology (including Information Security), Legal and Compliance departments, including the Head of IT, Chief Legal Officer, Chief Compliance Officer, and a number of their respective team members.
+Added: We have a cybersecurity working group composed of members of the Information Technology (including Information Security), Legal and Compliance departments, including the CISO, Chief Technology Officer, Chief Legal Officer, Chief Compliance Officer, and a number of their respective team members .
The working group meets regularly to identify and mitigate data protection and cybersecurity risks, implement information security governance mechanisms, discuss developments in information security, and discuss and respond to any significant cyber incidents.
10 unchanged sentences
Cybersecurity and significant information security matters are to be brought before the ERMC or certain of its members, and matters of primary significance are to be further escalated and reported to our Global Executive Committee and the audit committee of our board of directors, as appropriate.
−Removed: At the management level, the Head of IT, who has extensive cybersecurity knowledge and skills gained from over 20 years of work experience at the Company and elsewhere, heads the team responsible for implementing, monitoring and maintaining cybersecurity and data protection practices and reports directly to the President and Co-Chief Operating Officer.
−Removed: The Head of IT receives reports on cybersecurity threats from his team and external service providers on an ongoing basis and, in conjunction with management, reviews risk management measures implemented by us to identify and mitigate data protection and cybersecurity risks.
−Removed: The Head of IT works closely with our Legal and Compliance departments to oversee compliance with legal, regulatory and contractual security requirements and to develop reports and presentations to the board of directors and its audit committee.
−Removed: The Head of IT is responsible for providing training to employees in respect of information security.
+Added: At the management level, the CISO, who has extensive cybersecurity knowledge and skills gained from over 20 years of work experience at the Company and elsewhere, heads the team responsible for implementing, monitoring and maintaining cybersecurity and data protection practices and reports directly to the President and Co-Chief Operating Officer.
+Added: The CISO receives reports on cybersecurity threats from his team and external service providers on an ongoing basis and, in conjunction with management, reviews risk management measures implemented by us to identify and mitigate data protection and cybersecurity risks.
+Added: The CISO works closely with our Legal and Compliance departments to oversee compliance with legal, regulatory and contractual security requirements and to develop reports and presentations to the board of directors and its audit committee.
+Added: The CISO is responsible for providing training to employees in respect of information security.
Risk Management and Strategy
12 unchanged sentences
Due to evolving cybersecurity threats, it has and will continue to be difficult to prevent, detect, mitigate, and remediate cybersecurity incidents.
−Removed: To date, we have not identified any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that we believe have materially affected, or are reasonably likely to materially affect, us, including our business strategy, results of operations, or financial condition, but we face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to have such an effect.
+Added: To date, based on information available as of the date of this annual report, we have not identified any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that we believe have materially affected, or are reasonably likely to materially affect, us, including our business strategy, results of operations, or financial condition, but we face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to have such an effect and there can be no assurance that we will not be subject to future cybersecurity attacks, threats or incidents that may materially affect our business strategy, results of operations or financial condition.
Additional information on cybersecurity risks we face can be found in Part I, Item 1A “Risk Factors” of this Report under the heading “Cybersecurity risks and cybersecurity incidents could adversely affect our business by causing a disruption to our operations, which could adversely affect our financial condition and results of operations.”, which should be read in conjunction with the foregoing information.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.