3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: We recognize the importance of assessing, identifying, and managing material risks associated with cyber security threats, as such term is defined in Item 106(a) of Regulation S-K.
−Removed: We have established internal procedures for assessing, identifying and managing cyber security risks, which are built into our overall information technology function and are designed to help protect our information assets and operations from internal and external cyber threats, and protect employee information from unauthorized access or attack, as well as secure our networks and systems.
−Removed: Such processes include physical, procedural and technical safeguards and routine review of our policies and procedures to identify risks and refine our practices.
−Removed: We consider the internal risk oversight programs of third-party service providers before engaging them in order to help protect us from any related vulnerabilities.
−Removed: We have not encountered cyber security challenges that have materially impaired our operations or financial condition.
−Removed: Additional information regarding risks from cyber security threats is provided at “Item 1A.
−Removed: Risk Factors.”
+Added: We recognize the importance of assessing, identifying and managing material risks to our business associated with cybersecurity threats, as such term is defined in Item 106(a) of Regulation S-K.
+Added: To address these risks, we have engaged a qualified third-party information technology and cybersecurity services provider to manage and oversee our cybersecurity program.
+Added: We believe that outsourcing these functions to a dedicated third-party provider allows us to access cybersecurity expertise and capabilities that are commensurate with the risks we face, notwithstanding our size and resources as a smaller reporting company.
+Added: Our third-party IT and cybersecurity provider is responsible for the day-to-day management of our cybersecurity risk program, which includes the following principal elements:
+Added: Risk identification and assessment.
+Added: Our third-party provider conducts ongoing monitoring and periodic assessments of our information technology environment to identify cybersecurity vulnerabilities and threats, including risks arising from our use of cloud-based platforms, remote access systems, and third-party software applications.
+Added: Assessments consider both internal risks and external threat intelligence relevant to our industry and operational profile.
+Added: Technical and procedural safeguards .
+Added: Our third-party provider has implemented and maintains a combination of technical controls, including access controls, network monitoring, endpoint protection, data backup and recovery procedure, and procedural safeguards governing acceptable use, credential management, and data protection.
+Added: Our provider periodically reviews and updates these controls as our technology environment and the broader threat landscape evolve.
+Added: Third-party and vendor risk.
+Added: Our third-party IT provider assists us in evaluating the cybersecurity practices of vendors and service providers that have access to our systems or data prior to engagement.
+Added: We seek appropriate representations from key service providers regarding their security practices;
+Added: however, we may have limited ability to verify such representations or to compel remediation in the event a third-party provider experiences a security incident that affects our data or operations.
+Added: Incident response.
+Added: Our third-party IT provider maintains incident response procedures designed to detect, contain and remediate cybersecurity events.
+Added: These procedures include defined escalation protocols to ensure that any significant cybersecurity incident is promptly communicated to our senior management and, where appropriate, to the Audit Committee of our Board.
+Added: We have not experienced any cybersecurity incidents that have materially impaired our operations or financial condition.
+Added: However, there can be no assurance that we will not be subject to such incidents in the future, including incidents affecting our third-party IT provider or other vendors.
+Added: Our reliance on a third-party provider means that we are dependent on that provider's continued performance, financial stability and operational integrity.
+Added: A failure by our third-party IT provider to adequately perform its responsibilities, or a cybersecurity incident affecting the provider itself, could expose us to risks that we may not be able to detect or remediate in a timely manner.
+Added: Additional information regarding risks arising from cybersecurity threats is provided under the risk factor captioned "The risk of loss of the Company's intellectual property, trade secrets or other sensitive business information or disruption of operations could negatively impact on the Company's financial results" in Item 1A of this Annual Report.
Board Oversight
−Removed: The Audit Committee of our Board provides direct oversight over cyber security risk and provides updates to the Board of Directors regarding such oversight, when and if appropriate.
−Removed: Management provides periodic updates to the Audit Committee regarding cyber security matters including significant new cyber security threats or incidents, when and if appropriate.
+Added: The Audit Committee of our Board is responsible for oversight of cybersecurity risk as part of its broader risk oversight function.
+Added: Management provides periodic updates to the Audit Committee regarding the state of our cybersecurity program, including material developments reported by our third-party IT provider, any significant threats or incidents, and any recommended changes to our cybersecurity posture.
+Added: The Audit Committee reports to the full Board on cybersecurity matters as appropriate.
+Added: At the management level, our senior management team maintains primary responsibility for our relationship with our third-party IT and cybersecurity provider, including reviewing the scope of services provided, evaluating the provider's performance, and ensuring that cybersecurity matters are escalated appropriately within the organization.
+Added: While we do not employ a dedicated Chief Information Security Officer , we rely on the expertise of our third-party provider to supply the specialized knowledge and experience necessary to manage our cybersecurity risks effectively.
+Added: We periodically assess whether the scope and capabilities of our third-party provider remain appropriate given the evolution of our business and the threat environment, and we engage additional specialists on an as-needed basis to address specific risks or conduct targeted assessments.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.