6 unchanged sentences
We have also engaged third party advisors and consultants to conduct periodic testing of our processes and systems.
−Removed: Before contracting with certain third parties, such as those that have access to our IT networks, we have a process to conduct diligence on those third parties , which includes a security assessment.
+Added: Before contracting with certain third parties, such
+Added: as those that have access to our IT networks, we have a process to conduct diligence on those third parties , which includes a security assessment.
We have also implemented a process for employees to undergo cybersecurity training during onboarding, and thereafter, on an annual basis as part of our larger compliance training program.
−Removed: We have established monitoring procedures in our effort to mitigate risks related to cybersecurity incidents.
−Removed: As part of our cybersecurity risk management, we have adopted a business continuity and incident response plan, which is designed
−Removed: to establish our processes for identifying and responding to significant events that may lead to a business disruption or crisis, including those arising from or related to cybersecurity threats.
+Added: We have established monitoring procedures in our effort to mitigate risks related to cybersecurity incidents and data breaches.
+Added: As part of our cybersecurity risk management, we have adopted a business continuity and incident response plan, which is designed to establish our processes for identifying and responding to significant events that may lead to a business disruption or crisis, including those arising from or related to cybersecurity threats.
Our board of directors holds oversight responsibility over our strategy and risk management, including risks related to cybersecurity.
The board’s oversight of cybersecurity risk management is supported by the Audit Committee , which has responsibility for discussing with management significant cybersecurity risks and the measures we have implemented to monitor and control such cyber risk exposures.
−Removed: The Audit Committee receives quarterly updates from our Vice President, Information Technology (“IT Officer”) relating to IT and cybersecurity matters, including cybersecurity risks and threats.
+Added: The Audit Committee receives quarterly updates from our Director, Information Technology (“IT Officer”) relating to IT and cybersecurity matters, including cybersecurity risks and threats.
The Audit Committee provides periodic updates to our board of directors on cybersecurity matters discussed at such meetings.
1 unchanged sentence
Our IT Officer oversees the day-to-day management of the Company’s cybersecurity risk management program.
−Removed: Our IT Officer has over 15 years of experience in IT leadership and has managed IT for our company for approximately 10 years.
−Removed: Our IT Officer reports to our Chief Operating Officer and Chief Financial Officer and is a member of our Compliance Committee.
+Added: Our IT Officer has over 30 years of experience in IT operations and spent the previous 11 years consulting for the Company and has managed IT for the Company for approximately 1 year.
+Added: Our IT Officer reports to our Chief Operating Officer and Chief Financial Officer.
Our IT Officer coordinates with our legal department and relevant third parties, such as consultants and external legal advisors, to assess and manage material risks from cybersecurity threats.
−Removed: Our IT Officer is also supported by a cross-functional incident response team, which is empowered to review, assess, report, monitor and take action to mitigate or remedy any cybersecurity incidents pursuant to our business continuity and incident response plan.
−Removed: Our IT department further supports and has dedicated resources to assist our IT Officer in monitoring, preventing, detecting, mitigating, and remediating any cybersecurity incidents pursuant to our policies and procedures.
+Added: Our IT Officer is also supported by a cross-functional incident response team, which is empowered to review, assess, report, monitor and take action to mitigate or remedy any cybersecurity incidents or data breaches pursuant to our business continuity and incident response plan.
+Added: Our IT department further supports and has dedicated resources to assist our IT Officer in monitoring, preventing, detecting, mitigating, and remediating any cybersecurity incidents or data breaches pursuant to our policies and procedures.
We have also established a Disclosure Committee, which regularly reviews relevant information related to potential public disclosure of critical business risks and material events.
−Removed: We have not identified any cybersecurity incidents or threats that have materially affected our information or system or are reasonably likely to materially affect our information and systems, including our business strategy, results of operations, or financial condition .
+Added: We have not identified any cybersecurity incidents, data breaches or threats that have materially affected our information or system or are reasonably likely to materially affect our information and systems, including our business strategy, results of operations, or financial condition .
However, like other companies in our industry, we and our third-party vendors have from time to time experienced threats and security incidents that could affect our information or systems.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.