4 unchanged sentences
The Program is designed to identify, prevent, or mitigate the risks from cybersecurity threats.
−Removed: The Program leverages recognized security frameworks, such as the National Institute of Standards and Technology (NIST), Financial Services Information Sharing and Analysis Center (FS-ISAC), Federal Financial Institutions Examination Council (FFIEC), and Ransomware Self-Assessment Tool (R-SAT), to organize, improve, and assess the program and to better manage and reduce cybersecurity risk.
+Added: The Program leverages recognized security frameworks, such as the National Institute of Standards and Technology (NIST), Financial Services Information Sharing and Analysis Center (FS-ISAC), and Federal Financial Institutions Examination Council (FFIEC) to organize, improve, and assess the program and to better manage and reduce cybersecurity risk.
The Program is assessed and updated annually and as needed.
14 unchanged sentences
The Board of Directors is actively engaged in the oversight of the Company’s continuous efforts to reinforce and enhance its operational resilience and receives education to enhance their oversight efforts to accommodate for the ever-evolving information and cybersecurity threat landscape.
−Removed: The Information Security Officer (“ISO”) regularly updates the Board, management and any appropriate committees on the information and cybersecurity risks, threats, exposures, and mitigation measures.
+Added: The Information Security Officer (“ISO”) reports regularly to the Board, management and any appropriate committees on the information and cybersecurity risks, threats, exposures, and mitigation measures.
The Company’s incident response process is periodically tested and includes cybersecurity scenarios.
The Chief Operating Officer (COO) along with the ISO are responsible for developing and implementing our Program and reporting on cybersecurity matters to the Board.
−Removed: Our COO and ISO have over 25 years of combined related experience.
+Added: Our COO and ISO have over 25 years of combined related
We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises and incorporate external resources and advisors as needed.
1 unchanged sentence
The Company’s Board of Directors monitors the Program including policies and practices.
−Removed: The Company’s Compliance Committee and Information Security Committee along with the company’s Board of Directors oversee areas
−Removed: of operational risk such as information technology activities;
+Added: The Company’s Compliance Committee and Information Security Committee along with the company’s Board of Directors oversee areas of operational risk such as information technology activities;
risks associated with development, infrastructure, and cybersecurity;
1 unchanged sentence
and disaster recovery, business continuity, and incident response process.
−Removed: The ISO also provides periodic cybersecurity updates to the Board of Directors.
+Added: The COO also provides periodic cybersecurity updates to the Board of Directors.
We face a number of cybersecurity risks in connection with our business.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.