6 unchanged sentences
This risk management process is led by our Manager’s Chief Compliance Officer and Cyber Security Committee (“CSC”).
+Added: Our Manager’s Chief Compliance Officer has 17 years of experience in regulatory compliance, risk management, and cybersecurity governance, with expertise in implementing and overseeing security policies in financial and REIT sectors.
+Added: [The CSC is composed of professionals with backgrounds in information security, IT risk management, and data protection, ensuring a well-rounded approach to cybersecurity oversight.
Our management, including our Manager’s Chief Compliance Officer and CSC , is authorized to take the appropriate steps deemed necessary to identify, assess, contain, mitigate, and resolve cybersecurity threats including by (a) maintaining (i) an Incident Response Plan in the event of an Incident and (ii) a Cybersecurity Policy which governs information technology security policies, (b) regularly monitoring our systems and user accounts for any suspected Incidents, (c) performing annual audits on certain of our systems, and (d) providing general cybersecurity awareness and data protection training.
In addition, depending on the circumstances of an Incident, we may engage third parties such as insurance carriers, outside legal counsel, forensic investigators, crisis communications or public relations firms, investor relations firms and response vendors and we may coordinate with regulators or law enforcement.
−Removed: We also assess third party risks when determining the selection and oversight of applicable third-party service providers.
+Added: We perform due diligence in order to identify and evaluate cyber risks of third party service providers.
+Added: Third party service providers processing sensitive data are contractually required to meet applicable legal and regulatory obligations to protect sensitive data against cybersecurity threats and unauthorized access to the sensitive data.
+Added: Third party service providers deemed critical undergo ongoing monitoring to ensure they continue to meet their security obligations and other potential cybersecurity threats.
Increased cybersecurity risk due to the diversification of our data across external service providers and cyber incidents may adversely affect our business by causing a disruption to our operations, compromise our confidential information and/or damage to our business relationships, all of which could negatively impact our financial results.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.