1 unchanged sentence
Cybersecurity
−Removed: Our cybersecurity measure is primarily focused on ensuring the security and protection of computer systems and networks.
−Removed: We utilize a third-party service provider, as well as internal resources, to monitor and, as appropriate, respond to cybersecurity risks.
−Removed: We maintain various protections designed to safeguard against cyberattacks, including firewalls and virus detection software.
−Removed: We also periodically scan our environment for any vulnerabilities and perform penetration testing.
−Removed: In addition, to promote security awareness, we provide cybersecurity risk training to all employees at least annually.
−Removed: Oversight responsibility for information security matters is shared by the Board, Chief Financial Officer (“CFO”), VP of Internal Audit and our internal information technology (“IT”) resources.
−Removed: Our CFO and VP of Internal Audit oversee our cybersecurity risk management, including appropriate risk mitigation strategies, systems, processes, and controls, and receives quarterly updates from IT and the third-party IT service provider on cybersecurity and information security matters.
−Removed: The CFO communicates with the Board periodically regarding the state of our cybersecurity risk management, current and evolving threats and recommendations for changes.
−Removed: We have also implemented a cyber incident response plan that provides a protocol to report certain incidents to the CFO with the goal of timely assessment of such incidents, determining applicable disclosure requirements and communicating with the Board for timely and accurate reporting of any material cybersecurity incident.
−Removed: As of the date of this report, we are not aware of any material risks from cybersecurity threats, that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial condition.
+Added: Management and Strategy
+Added: Our cybersecurity measure
+Added: is primarily focused on ensuring the security and protection of computer systems and networks.
+Added: We primarily utilize an in-house IT service
+Added: provider, as well as external resources as a supplement, to monitor and, as appropriate, respond to cybersecurity risks.
+Added: We maintain various
+Added: protections designed to safeguard against cyberattacks, including firewalls and virus detection software.
+Added: We also periodically scan our
+Added: environment for any vulnerabilities and perform penetration testing.
+Added: In addition, to promote security awareness, we provide cybersecurity
+Added: risk training to all employees at least annually.
+Added: responsibility for information security matters is shared by the Board, Chief Financial Officer (“CFO”), management team and our internal information technology (“IT”) resources.
+Added: CFO and management team oversee our cybersecurity risk management, including appropriate risk mitigation strategies, systems,
+Added: processes, and controls, and receives quarterly updates from IT and the third-party IT service provider on cybersecurity and
+Added: information security matters.
+Added: communicates with the Board periodically regarding the state of our cybersecurity risk management, current and evolving threats and
+Added: recommendations for changes.
+Added: We have also implemented a cyber incident response plan that provides a protocol to report certain incidents to the CFO with the
+Added: goal of timely assessment of such incidents, determining applicable disclosure requirements and communicating with the Board for timely
+Added: and accurate reporting of any material cybersecurity incident.
+Added: On December 13, 2024, we experienced
+Added: a cybersecurity incident involving unauthorized access to one of our management systems.
+Added: The findings indicated that the unauthorized
+Added: access incurred due to leaked credentials of an employee from our partner studio.
+Added: We assessed the incident as having immaterial impact
+Added: and this unauthorized access did not result in significant data leaks.
+Added: The jeopardized content was limited to a few in-house created assets,
+Added: specifically storyboard animatics from the pre-production stage.
+Added: The amount and type of information involved a few storyboard files related
+Added: to the production.
+Added: The nature of the leak was user-driven, which made an instant identification challenging and the leak was detected
+Added: a few days after it occurred.
+Added: We immediately dispatched our Security Incident Response Team and identified the steps to be taken to mitigate
+Added: future risks:
+Added: including the urgent need to review Two Factor Authentication protocols and enhance our security controls.
+Added: broader network is protected by industry-standard cybersecurity tools, we concluded that some of our software as a Service (SaaS) platforms
+Added: require additional security improvements.
+Added: We have decided to invest approximately an additional $0.2 million in cybersecurity enhancements
+Added: to strengthen the security of our SaaS platforms (such as review and purchase of additional licenses) and to implement additional protective
+Added: measures across our systems.
+Added: One of our top priorities is safeguarding our assets while maintaining and protecting client trust through
+Added: robust security measures and risk management practices.
+Added: As of the date of this Annual
+Added: Report, we are not aware of any material risks from cybersecurity threats, that have materially affected or are reasonably likely to materially
+Added: affect us, including our business strategy, results of operations, or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.