2 unchanged sentences
Cybersecurity
+Added: We recognize the importance of safeguarding our business operations, sensitive data, and intellectual property from cyber threats and other technological risks.
+Added: Our operations involve the use of various information technology systems, including those for production management, customer order management, and financial reporting.
+Added: As such, we are exposed to a range of cyber risks, including but not limited to data breaches, ransomware attacks, unauthorized access to proprietary data, and disruptions to our operations due to system failures.
+Added: We are committed to maintaining an appropriate level of cybersecurity to mitigate these risks.
Lendway’s cyber environment at December 31, 2024 consisted primarily of outsourced information technology (“IT”) operations.
−Removed: The outsourced provider has a cybersecurity framework which includes multiple products implemented to ensure the security of Lendway’s environment.
−Removed: Annual internal and external vulnerability scans are also completed to ensure we mitigate any risks proactively.
+Added: The outsourced providers have a cybersecurity framework which includes multiple products implemented to ensure the security of Lendway’s and Bloomia’s environments.
+Added: Our third-party service providers alert management, specifically the CFO and CEO of Bloomia , to incidents or other concerns.
+Added: Management reports significant incidents or concerns to the Audit Committee .
+Added: Annual internal and external vulnerability scans are completed to ensure we mitigate any risks proactively.
The Company’s internal operations are PC based and the PCs have up to date security software.
Regular phishing exercises are conducted, and employee awareness training is conducted annually by our outsourced provider .
−Removed: Our full Board of Directors and our Audit Committee provide oversight of our risk management program, which includes cybersecurity.
+Added: The Company relies on third-party service providers for services such as IT management and payroll .
+Added: These third-parties are also vulnerable to cybersecurity threats.
+Added: Management actively assesses its third-parties policies related to cyber risks, including obtaining System and Organization Controls (SOC) reports, when available.
+Added: Our full Board of Directors and our Audit Committee provide oversight of our risk management program, which includes cybersecurity and monitoring the performance of our third-party IT providers.
The Audit Committee, as part of its charter to review the Company’s practices with respect to risk assessment and risk management, receives updates on internal control, including those relating to IT general controls and cybersecurity.
−Removed: With the acquisition of Bloomia on February 22, 2024, the Company will include the IT environment of Bloomia in its cybersecurity processes and oversight at the corporate and board level.
−Removed: Bloomia’s cybersecurity is managed by a third party vendor.
−Removed: As of the date of this report, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
+Added: Management’s Role
+Added: As of the date of this report, we did not identify any cybersecurity threats, including as a result of previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect, the Company, including our business strategy, results of operations, or financial condition.
However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.