18 unchanged sentences
We conduct an annual information security focused risk assessment, which leverages the process and control areas provided by the International Organization for Standardization (“ISO”) 27001.
−Removed: In September 2021, we received our ISO 27001 Information Security Management certification.
−Removed: In fiscal 2022 and 2023, management performed procedures to validate our continued conformity with the ISO 27001 standard and concluded that existing controls continued to operate effectively.
+Added: In 2024, we recertified our ISO 27001 Information Security Management certification to the new 2022 standard.
In addition, we assess our cybersecurity threat risks by conducting periodic internal and external risk assessments and annual external penetration testing, as well as maintaining an active vulnerability management program to assess threats at the network, systems and application levels.
2 unchanged sentences
• Perform an annual review of all of our policies related to cybersecurity;
−Removed: • Monitor emerging data protection laws and implement changes to our policies to remain compliant;
+Added: • Collaborate with the legal department for awareness of emerging data protection laws and implement changes to our policies to remain compliant;
• Run tabletop exercises with the cybersecurity incident response team, including executive team members, to simulate a response to a cybersecurity incident and use the findings to improve our processes and technologies;
−Removed: • Conduct regular phishing email simulations and quarterly security awareness trainings for all employees to enhance awareness and responsiveness to such possible threats;
+Added: • Conduct monthly phishing email simulations and quarterly security awareness trainings for all employees to enhance awareness and responsiveness to such possible threats;
• Require all employees to review and acknowledge the company’s information security policies upon hiring and annually thereafter;
+Added: • Send periodic company-wide communications to raise employee awareness of social engineering and other forms of attack and how to guard against those;
• Leverage the company’s incident response plan framework and a full set of cybersecurity technology tools, processes and procedures including, for example, security incident and cyber event management, endpoint detection and response, extended detection and response, e-mail gateway, and vulnerability management to monitor any cyber threats and to proactively detect, respond and recover when there is an actual or potential cybersecurity incident;
23 unchanged sentences
At least quarterly, management provides the I&T Committee with updates regarding our cybersecurity risks, threats, and efforts focused on mitigating those risks.
−Removed: These updates are provided by our Chief Technology Officer (“CTO”) and our CISO, and include recent developments in cybersecurity, the company’s actual experience with cybersecurity incidents, and the systems and processes in place to defend against cyberattacks.
+Added: These updates are provided by our Chief Digital Officer (“CDO”) and our CISO, and include recent developments in cybersecurity, the company’s actual experience with cybersecurity incidents, and the systems and processes in place to defend against cyberattacks.
Should a material or potentially material cybersecurity incident occur, the Board will immediately be notified of such event by the company’s CEO.
−Removed: Our CTO and CISO frequently communicate with affected business and finance leaders regarding any cybersecurity related event.
−Removed: Our cybersecurity risk management and strategy processes are led by our CTO and our CISO.
+Added: Our CDO and CISO frequently communicate with affected business and finance leaders regarding any cybersecurity related event.
+Added: Our cybersecurity risk management and strategy processes are led by our CDO and our CISO .
Such individuals have collectively over 25 years of prior work experience in various roles involving managing information security;
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.