8 unchanged sentences
Any deviations from our IT security policies and standards are assessed by our IT security team.
−Removed: Any critical and high-risk levels are identified, documented and reported to relevant key stakeholders.
+Added: Any critical and high-risk levels are identified, documented, addressed and reported to relevant key stakeholders.
We have established an Incident Response Plan that defines and documents procedures for assessing, identifying, and managing a cybersecurity incident.
1 unchanged sentence
The IT Security Manager is responsible for communicating incidents to the Vice President - IT and the other members of management as appropriate.
−Removed: If a cybersecurity incident is determined to be material by our management team, they would notify our Board of Directors.
+Added: If a cybersecurity incident is determined to be material by our management team, they would notify the Board .
Our Vice President - IT and IT Security manager have developed expertise in cybersecurity, data protection, compliance, enterprise architecture and design, data analytics, and digital transformation through years of experience in the information technology space.
13 unchanged sentences
In addition, our third-party experts work with us to conduct cybersecurity tabletop exercises and internal phishing awareness campaigns.
−Removed: We use the findings of these exercises to improve our practices, procedures, and technologies.
+Added: We use the findings of these exercises to improve our practices, training, procedures, and technologies.
We also engage third party security experts to support our cybersecurity threat and incident response management and maintain information security risk insurance coverage.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.