4 unchanged sentences
Our enterprise risk management program considers cybersecurity threats as part of our overall risk assessment process.
−Removed: We perform these risk assessments to inform our risk mitigation strategies and prioritize cybersecurity initiatives.
+Added: We perform these risk assessments to inform our risk mitigation strategies and prioritize
+Added: cybersecurity initiatives.
Our cybersecurity risk assessment process includes network and endpoint monitoring, vulnerability assessments, and penetration testing, and we believe helps identify our cybersecurity threat risks by aligning our processes to standards set by the National Institute of Standards and Technology (“NIST”).
6 unchanged sentences
Our cross-functional risk management team evaluates cybersecurity risks alongside other operational, financial, and reputational risks, facilitating effective resource allocation and coordinated mitigation strategies.
−Removed: In 2021, we updated our Audit Committee charter to memorialize the Committee’s role in reviewing cybersecurity matters.
−Removed: The Audit Committee oversees the initial assessment of cybersecurity threats as well as the Company’s approach to management and mitigation of such risks, compliance with industry standards related to cybersecurity, and the Company’s public disclosures related to cybersecurity matters.
+Added: The Audit Committee oversees the Company's response to cybersecurity threats as well as the Company’s approach to management and mitigation of such risks, compliance with industry standards related to cybersecurity, and the Company’s public disclosures related to cybersecurity matters.
In addition, our Board of Directors devotes regular attention to oversight of cybersecurity risks.
8 unchanged sentences
Management continues to take steps to enhance our data security infrastructure and defenses.
−Removed: Our processes also address cybersecurity threat risks associated with using third-party service providers, including those in our supply chain or who have access to our customer and employee data, our information systems, or the facilities that house such systems or data.
+Added: Our processes also address cybersecurity threat risks associated with using third-party service providers, as appropriate, including those in our supply chain or who have access to our customer and employee data, our information systems, or the facilities that house such systems or data.
+Added: We have a third-party risk management process for key service providers based on our assessment of their criticality to our operations and respective risk profile.
We engage outside third-party experts, cybersecurity advisors, and auditors to conduct regular risk assessments, penetration testing, and vulnerability analyses.
6 unchanged sentences
It includes periodic scanning, risk assessment, and patch management to address system and network vulnerabilities and help ensure that our infrastructure remains resilient against evolving threats.
−Removed: As part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K, and in our MD&A at Item 7 of this Annual Report on Form 10-K, we describe whether and how risks from identified cybersecurity threats, including any previous incidents, have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: As part of our risk factor disclosures in Item 1A of this Annual Report on Form 10-K and in our "Management's Discussion and Analysis of Financial Condition and Results of Operations" in Item 7 of this Annual Report on Form 10-K, we describe whether and how risks from identified cybersecurity threats, including any previous incidents, have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
These disclosures are incorporated by reference herein.
There can be no assurance that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied with or effective in protecting our systems and information.
−Removed: Based on the information we have as of the date of this Annual Report on Form 10-K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: Based on the information we have as of the date of this Annual Report on Form 10-
+Added: K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
This includes penalties and settlements, of which there were none.
+Added: We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: See "Risk Factors - We are exposed to, and may be adversely affected by, interruptions to our computer and information technology systems and sophisticated cyber-attacks."
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.