1 unchanged sentence
Cybersecurity
−Removed: Cybersecurity Risk Management and Strategy
−Removed: We have implemented and maintain various information security processes
−Removed: designed to assess, identify and manage material risks from cybersecurity threats to our critical systems and information.
−Removed: Such processes
−Removed: are integrated into our overall risk management processes.
−Removed: For example, cybersecurity risk is addressed as a component of our enterprise
−Removed: risk management program and has historically been included as part of compliance reports provided to our audit committee.
−Removed: Our officers, contractors and third-party IT vendors help assess, identify
−Removed: and manage our cybersecurity threats and risks by monitoring and evaluating our threat environment and risk profile using various methods
−Removed: including, for example:
+Added: Cybersecurity
+Added: Risk Management and Strategy
+Added: We have implemented
+Added: and maintain various information security processes designed to assess, identify and manage material risks from cybersecurity threats
+Added: to our critical systems and information.
+Added: Such processes are integrated into our overall risk management processes.
+Added: For example, cybersecurity
+Added: risk is addressed as a component of our enterprise risk management program and has historically been included as part of compliance reports
+Added: provided to our audit committee.
+Added: Our officers,
+Added: contractors and third-party IT vendors help assess, identify and manage our cybersecurity threats and risks by monitoring and evaluating
+Added: our threat environment and risk profile using various methods including, for example:
through the use of automated tools;
−Removed: conducting audits and threat assessments for internal and external threats;
+Added: audits and threat assessments for internal and external threats;
analyzing reports of threats and actors;
−Removed: conducting vulnerability assessments to identify vulnerabilities;
evaluating our and our industry’s
1 unchanged sentence
and evaluating threats reported to us.
−Removed: We implement and maintain various technical, physical, and organizational
−Removed: measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our critical
−Removed: systems and information, including, for example:
−Removed: multi-factor authentication, encryption, anti-malware functionality, access controls
−Removed: and systems monitoring.
−Removed: We use third-party service providers to perform a variety of functions
−Removed: throughout our business, including but not limited to application providers and hosting companies.
−Removed: All of our critical information is
−Removed: hosted by a third-party service provider.
−Removed: We have a vendor management program to assess cybersecurity risks associated with our use of
−Removed: these providers.
−Removed: Further, we also rely upon such third-party service providers to both assist us in identifying cybersecurity threats,
−Removed: as well as to review and notify us of any data breach on their systems.
−Removed: For a description of the risks from cybersecurity threats that may
−Removed: materially affect us and how they may do so, see our risk factors under Part 1.
−Removed: Risk Factors in this 2023 10-K Report, including
−Removed: the risk factor captioned “We may not be able to maintain effective and efficient information systems or properly safeguard our
−Removed: information systems.” While to date we have not identified any breaches from known cybersecurity threats, including as a result
−Removed: of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business
−Removed: strategy, results of operations, or financial condition, the sophistication of cybersecurity threats continues to increase, and the preventative
−Removed: actions we take to reduce the risk of cybersecurity incidents and protect our systems and information may be insufficient.
−Removed: no matter how well our program is designed or implemented, we will not be able to anticipate all security breaches, and we may not be
−Removed: able to implement effective preventive measures against such security breaches in a timely manner.
−Removed: Cybersecurity Governance
−Removed: Our board of directors considers cybersecurity risk as part of its
−Removed: risk oversight function.
−Removed: The audit committee of our board of directors bears primary responsibility for the board’s oversight of
−Removed: our cybersecurity risk.
−Removed: Periodically management updates our audit committee about various risks facing the Company, of which cybersecurity
−Removed: may be included.
−Removed: Our cybersecurity risk assessment and management processes are implemented
−Removed: and maintained by management and IT consultants.
−Removed: The IT consultants have relevant expertise, experience, education and training as well
−Removed: as knowledge of our company’s critical systems and information technology policies.
−Removed: Our cybersecurity incident response processes are designed to escalate
−Removed: certain cybersecurity incidents to our chief executive officer, who would be responsible, along with third parties including our IT consultants,
−Removed: for assessing the materiality of, and mitigating and remediating, any cybersecurity incidents of which we are notified.
−Removed: In addition, our
−Removed: incident response processes include a procedure for reporting certain cybersecurity incidents to the board of directors.
+Added: and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate
+Added: material risks from cybersecurity threats to our critical systems and information, including, for example:
+Added: multi-factor authentication,
+Added: encryption, anti-malware functionality, access controls and systems monitoring.
+Added: We use third-party
+Added: service providers to perform a variety of functions throughout our business, including but not limited to application providers and hosting
+Added: All of our critical information is hosted by a third-party service provider.
+Added: Further, we also rely upon such third-party service
+Added: providers to both assist us in identifying cybersecurity threats , as well as to review and notify us of any data breach on their systems.
+Added: For a description
+Added: of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Part 1.
+Added: Risk Factors in this 2024 10-K Report, including the risk factor captioned “We may not be able to maintain effective and efficient
+Added: information systems or properly safeguard our information systems.” While to date we have not identified any breaches from known
+Added: cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely
+Added: to materially affect us, including our business strategy, results of operations, or financial condition, the sophistication of cybersecurity
+Added: threats continues to increase, and the preventative actions we take to reduce the risk of cybersecurity incidents and protect our systems
+Added: and information may be insufficient.
+Added: Accordingly, no matter how well our program is designed or implemented, we will not be able to anticipate
+Added: all security breaches, and we may not be able to implement effective preventive measures against such security breaches in a timely manner.
+Added: We also carry cybersecurity insurance to protect the Company in the event of a cybersecurity breach and to provide resources if a cybersecurity
+Added: breach occurs.
+Added: Cybersecurity
+Added: of directors considers cybersecurity risk as part of its risk oversight function.
+Added: The audit committee of our board of directors bears
+Added: primary responsibility for the board’s oversight of our cybersecurity risk.
+Added: Periodically management updates our audit committee
+Added: about various risks facing the Company, of which cybersecurity may be included.
+Added: Our cybersecurity
+Added: risk assessment and management processes are implemented and maintained by management and IT consultants .
+Added: The IT consultants have relevant
+Added: expertise, experience, education and training as well as knowledge of our company’s critical systems and information technology
+Added: Our cybersecurity
+Added: incident response processes are designed to escalate certain cybersecurity incidents to our chief executive officer , who would be responsible,
+Added: along with third parties including our IT consultants, for assessing the materiality of, and mitigating and remediating, any cybersecurity
+Added: incidents of which we are notified.
+Added: In addition, our incident response processes include a procedure for reporting certain cybersecurity
+Added: incidents to the board of directors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.