3 unchanged sentences
Our cybersecurity risk management strategy and processes are designed to identify, assess, and manage risks to the confidentiality, integrity, and availability of our information technology environment, systems, and information.
−Removed: The cybersecurity risk management process is managed centrally and is led by our global chief information security officer
−Removed: (“CISO”) who reports to our global chief information officer.
+Added: The cybersecurity risk management process is managed centrally and is led by our Chief Information Security Officer (“CISO”) who reports to our Chief Information Officer.
Our cybersecurity program takes a risk-based approach and is integrated with our global enterprise risk management program.
2 unchanged sentences
● a formal cybersecurity risk assessment is performed annually in collaboration with our enterprise risk management function, resulting in updates to plans and actions that are incorporated into improvement projects;
−Removed: ● our cybersecurity program maturity is benchmarked annually against industry standards and norms.
+Added: ● our cybersecurity program maturity is benchmarked annually against global industry standards and norms.
The result serves as a guide to identifying evolving risks, prioritizing improvements, and enhancing the program;
1 unchanged sentence
● annual security awareness trainings are required to be completed by employees, and monthly phishing campaigns and additional function-specific cybersecurity trainings are also conducted;
−Removed: ● security and risk metrics are reviewed monthly and reported to leadership quarterly;
+Added: ● security and risk metrics are reviewed monthly and reported to leadership regularly;
● external penetration tests are conducted annually by independent third parties and appropriate actions are taken to strengthen controls;
−Removed: ● a cybersecurity incident response charter and plan, and playbooks are maintained by the cybersecurity incident response team.
−Removed: The plan and playbooks are utilized during table-top exercises and trainings.
+Added: ● a cybersecurity incident response plan and governance charter are maintained by the cybersecurity incident response team.
+Added: The cybersecurity incident response plan and supporting playbooks are utilized during table-top exercises and trainings.
Participants may include information technology, business, corporate function, and external resources depending on the table-top scenario;
2 unchanged sentences
To date, we do not believe that any risks from cybersecurity threats, nor any previous cybersecurity incidents, have materially affected our business strategy, results of operations, or financial condition .
−Removed: However, the sophistication of cyber threats continues to increase, and the preventative actions we have taken and continue to take to reduce the risk of cyber incidents and protect our systems and information may not successfully protect against future cyber incidents, which could materially affect our business strategy, results of operations, or financial condition.
+Added: However, the sophistication of cybersecurity threats continues to increase, and the preventative actions we have taken and continue to take to reduce the risk of cybersecurity incidents and protect our systems and information may not successfully protect against future cybersecurity incidents, which could materially affect our business strategy, results of operations, or financial condition.
For additional information on certain risks associated with cybersecurity, refer to the risk factors related to cybersecurity and information technology systems in “Part I, Item 1A.
4 unchanged sentences
Our CISO has over 20 years of experience in information security leadership roles and over 9 years as our CISO.
−Removed: Nearly half of our board of directors have completed cybersecurity program trainings or have cybersecurity and information security industry experience.
−Removed: Cybersecurity incidents are evaluated by a cross-functional management team based on defined quantitative and qualitative criteria and communicated to leadership.
−Removed: We have cybersecurity and information technology third-party consultants to assist in performing forensic and technical analyses and advising leadership as needed.
+Added: He holds many industry certifications, including Certified Information Systems Security Professional (“CISSP”), and is an active member in professional organizations.
+Added: Also, certain members of our board of directors have completed cybersecurity program trainings, or have relevant industry experience .
+Added: Cybersecurity incidents are evaluated by a cross-functional team based on defined criteria and regularly communicated to leadership pursuant to criteria set forth in our incident response plan and related processes.
+Added: We have engaged cybersecurity and information technology third-party consultants to assist in cybersecurity incident response including forensics and technical analysis.
The cybersecurity committee of our board of directors has oversight responsibility for cybersecurity risks.
The CISO provides updates at least twice a year to the cybersecurity committee regarding matters related to information technology and cybersecurity risks including the state of our cybersecurity programs, emerging cybersecurity developments and threats, and our strategy to mitigate cybersecurity risk.
−Removed: Additionally, the full board of directors receives updates on our cybersecurity program twice a year as part of the enterprise risk management meetings.
+Added: Additionally, the full board of directors receives updates on cybersecurity risks twice a year as part of the enterprise risk management meetings .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.