4 unchanged sentences
however, future cyber incidents may occur and the Company has implemented processes to manage, mitigate, and respond to cybersecurity threats.
−Removed: We maintain policies and controls over areas such as information security, access on/offboarding, and access and account management, to help govern the processes put in place by management designed to protect our IT assets, data, and services from threats and vulnerabilities.
−Removed: We partner with third-party information technology (“IT”) providers leveraging third-party technology and expertise.
+Added: We maintain policies and controls over areas such as information security, access on/offboarding, and access and account management, to help govern the processes put in place by management designed to protect our information technology (“IT”) assets, data, and services from threats and vulnerabilities.
+Added: We partner with third-party IT providers leveraging third-party technology and expertise.
These partners, including consultants and other third-party service providers, are a key part of Theriva’s cybersecurity risk management strategy and infrastructure and provide services including, maintenance of an IT assets inventory, periodic vulnerability scanning, identity access management controls including restricted access of privileged accounts, network integrity safeguarded by employing web-based software, including endpoint protection, endpoint detection and response, and remote monitoring management on all devices, industry-standard encryption protocols, critical data backups, infrastructure maintenance, incident response, and cyber risk advisory, assessment and remediation.
−Removed: As part of its review of the adequacy of our system of internal controls over financial reporting and disclosure controls and procedures, management and the Audit Committee oversees cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks.
+Added: As part of its review of the adequacy of our system of internal controls over financial reporting and disclosure controls and procedures, management and the Audit Committee oversee cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks.
Theriva’s management team is responsible for oversight and administration of cybersecurity risk management strategies, and for informing the Board and other relevant stakeholders regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.