1 unchanged sentence
Cybersecurity
−Removed: Management and Strategy
+Added: Risk Management and Strategy
Our cybersecurity measure
8 unchanged sentences
risk training to all employees at least annually.
−Removed: responsibility for information security matters is shared by the Board, Chief Financial Officer (“CFO”), management team and our internal information technology (“IT”) resources.
−Removed: CFO and management team oversee our cybersecurity risk management, including appropriate risk mitigation strategies, systems,
−Removed: processes, and controls, and receives quarterly updates from IT and the third-party IT service provider on cybersecurity and
−Removed: information security matters.
−Removed: communicates with the Board periodically regarding the state of our cybersecurity risk management, current and evolving threats and
−Removed: recommendations for changes.
−Removed: We have also implemented a cyber incident response plan that provides a protocol to report certain incidents to the CFO with the
−Removed: goal of timely assessment of such incidents, determining applicable disclosure requirements and communicating with the Board for timely
+Added: Oversight responsibility for
+Added: information security matters is shared by our Board, our Chief Financial Officer (“CFO”), our management team and our internal
+Added: IT resources.
+Added: Our CFO and management team oversee our cybersecurity risk management program, including risk mitigation strategies, systems,
+Added: processes, and controls, and receive quarterly updates from IT on cybersecurity and information security matters.
+Added: The CFO communicates
+Added: with the Board periodically regarding the state of our cybersecurity risk management, current and evolving threats and recommendations
+Added: We have also implemented a cyber incident response plan that provides a protocol to report certain incidents to the CFO with
+Added: the goal of timely assessment of such incidents, determining applicable disclosure requirements and communicating with the Board for timely
and accurate reporting of any material cybersecurity incident.
−Removed: On December 13, 2024, we experienced
−Removed: a cybersecurity incident involving unauthorized access to one of our management systems.
−Removed: The findings indicated that the unauthorized
−Removed: access incurred due to leaked credentials of an employee from our partner studio.
−Removed: We assessed the incident as having immaterial impact
−Removed: and this unauthorized access did not result in significant data leaks.
−Removed: The jeopardized content was limited to a few in-house created assets,
−Removed: specifically storyboard animatics from the pre-production stage.
−Removed: The amount and type of information involved a few storyboard files related
−Removed: to the production.
−Removed: The nature of the leak was user-driven, which made an instant identification challenging and the leak was detected
−Removed: a few days after it occurred.
−Removed: We immediately dispatched our Security Incident Response Team and identified the steps to be taken to mitigate
−Removed: future risks:
−Removed: including the urgent need to review Two Factor Authentication protocols and enhance our security controls.
−Removed: broader network is protected by industry-standard cybersecurity tools, we concluded that some of our software as a Service (SaaS) platforms
−Removed: require additional security improvements.
−Removed: We have decided to invest approximately an additional $0.2 million in cybersecurity enhancements
−Removed: to strengthen the security of our SaaS platforms (such as review and purchase of additional licenses) and to implement additional protective
−Removed: measures across our systems.
−Removed: One of our top priorities is safeguarding our assets while maintaining and protecting client trust through
−Removed: robust security measures and risk management practices.
+Added: We face risks from cybersecurity
+Added: threats that could have a material adverse effect on our business, results of operations, financial condition, cash flows or reputation.
+Added: We acknowledge that the risk of a cyber incident is prevalent in the current threat landscape and that a future cyber incident may occur
+Added: in the normal course business.
+Added: However, prior cybersecurity incidents have not had a material adverse effect on our business, financial
+Added: condition, results of operations, or cash flows.
+Added: We proactively seek to detect and investigate unauthorized attempts and attacks against
+Added: our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through changes or updates to internal
+Added: processes and tools and changes or updates to service delivery;
+Added: however, potential vulnerabilities to known or unknown threats will remain.
+Added: Further, there is increasing regulation regarding responses to cybersecurity incidents, including reporting to regulators, investors,
+Added: and additional stakeholders, which could subject us to additional liability and reputational harm.
As of the date of this Annual
−Removed: Report, we are not aware of any material risks from cybersecurity threats, that have materially affected or are reasonably likely to materially
−Removed: affect us, including our business strategy, results of operations, or financial condition.
+Added: Report on Form 10-K, we are not aware of any material risks from cybersecurity threats, that have materially affected or are reasonably
+Added: likely to materially affect us, including our business, results of operations, financial condition, cash flows or reputation.
+Added: “Risk Factors” for more information on cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.