1 unchanged sentence
Cybersecurity
−Removed: Cybersecurity
−Removed: Risk Management and Strategy
−Removed: We have implemented
−Removed: and maintain various information security processes designed to assess, identify and manage material risks from cybersecurity threats
−Removed: to our critical systems and information.
−Removed: Such processes are integrated into our overall risk management processes.
−Removed: For example, cybersecurity
−Removed: risk is addressed as a component of our enterprise risk management program and has historically been included as part of compliance reports
−Removed: provided to our audit committee.
−Removed: Our officers,
−Removed: contractors and third-party IT vendors help assess, identify and manage our cybersecurity threats and risks by monitoring and evaluating
−Removed: our threat environment and risk profile using various methods including, for example:
+Added: Cybersecurity Risk Management and Strategy
+Added: We have implemented and maintain various information security processes
+Added: designed to assess, identify and manage material risks from cybersecurity threats to our critical systems and information.
+Added: Such processes
+Added: are integrated into our overall risk management processes.
+Added: For example, cybersecurity risk is addressed as a component of our enterprise
+Added: risk management program and has historically been included as part of compliance reports provided to our audit committee.
+Added: Our officers, contractors and third-party IT vendors help assess,
+Added: identify and manage our cybersecurity threats and risks by monitoring and evaluating our threat environment and risk profile using various
+Added: methods including, for example:
through the use of automated tools;
−Removed: audits and threat assessments for internal and external threats;
+Added: conducting audits and threat assessments for internal and external
analyzing reports of threats and actors;
−Removed: evaluating our and our industry’s
−Removed: risk profile;
−Removed: and evaluating threats reported to us.
−Removed: and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate
−Removed: material risks from cybersecurity threats to our critical systems and information, including, for example:
−Removed: multi-factor authentication,
−Removed: encryption, anti-malware functionality, access controls and systems monitoring.
−Removed: We use third-party
−Removed: service providers to perform a variety of functions throughout our business, including but not limited to application providers and hosting
−Removed: All of our critical information is hosted by a third-party service provider.
−Removed: Further, we also rely upon such third-party service
−Removed: providers to both assist us in identifying cybersecurity threats , as well as to review and notify us of any data breach on their systems.
−Removed: For a description
−Removed: of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Part 1.
−Removed: Risk Factors in this 2024 10-K Report, including the risk factor captioned “We may not be able to maintain effective and efficient
−Removed: information systems or properly safeguard our information systems.” While to date we have not identified any breaches from known
−Removed: cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely
−Removed: to materially affect us, including our business strategy, results of operations, or financial condition, the sophistication of cybersecurity
−Removed: threats continues to increase, and the preventative actions we take to reduce the risk of cybersecurity incidents and protect our systems
−Removed: and information may be insufficient.
−Removed: Accordingly, no matter how well our program is designed or implemented, we will not be able to anticipate
−Removed: all security breaches, and we may not be able to implement effective preventive measures against such security breaches in a timely manner.
−Removed: We also carry cybersecurity insurance to protect the Company in the event of a cybersecurity breach and to provide resources if a cybersecurity
−Removed: breach occurs.
−Removed: Cybersecurity
−Removed: of directors considers cybersecurity risk as part of its risk oversight function.
−Removed: The audit committee of our board of directors bears
−Removed: primary responsibility for the board’s oversight of our cybersecurity risk.
−Removed: Periodically management updates our audit committee
−Removed: about various risks facing the Company, of which cybersecurity may be included.
−Removed: Our cybersecurity
−Removed: risk assessment and management processes are implemented and maintained by management and IT consultants .
−Removed: The IT consultants have relevant
−Removed: expertise, experience, education and training as well as knowledge of our company’s critical systems and information technology
−Removed: Our cybersecurity
−Removed: incident response processes are designed to escalate certain cybersecurity incidents to our chief executive officer , who would be responsible,
−Removed: along with third parties including our IT consultants, for assessing the materiality of, and mitigating and remediating, any cybersecurity
−Removed: incidents of which we are notified.
−Removed: In addition, our incident response processes include a procedure for reporting certain cybersecurity
−Removed: incidents to the board of directors.
+Added: evaluating our and our industry’s risk profile;
+Added: and evaluating threats reported
+Added: We implement and maintain various technical, physical, and organizational
+Added: measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our critical
+Added: systems and information, including, for example:
+Added: multi-factor authentication, encryption, anti-malware functionality, access controls
+Added: and systems monitoring.
+Added: We use third-party service providers to perform a variety of functions
+Added: throughout our business, including but not limited to application providers and hosting companies.
+Added: All of our critical information is
+Added: hosted by a third-party service provider.
+Added: Further, we also rely upon such third-party service providers to both assist us in identifying
+Added: cybersecurity threats , as well as to review and notify us of any data breach on their systems.
+Added: For a description of the risks from cybersecurity threats that may
+Added: materially affect us and how they may do so, see our risk factors under Part 1.
+Added: Risk Factors in this 2025 10-K Report, including
+Added: the risk factor captioned “We may not be able to maintain effective and efficient information systems or properly safeguard our
+Added: information systems.” While to date we have not identified any breaches from known cybersecurity threats, including as a result
+Added: of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business
+Added: strategy, results of operations, or financial condition, the sophistication of cybersecurity threats continues to increase, and the preventative
+Added: actions we take to reduce the risk of cybersecurity incidents and protect our systems and information may be insufficient.
+Added: no matter how well our program is designed or implemented, we will not be able to anticipate all security breaches, and we may not be
+Added: able to implement effective preventive measures against such security breaches in a timely manner.
+Added: We also carry cybersecurity insurance
+Added: to protect the Company in the event of a cybersecurity breach and to provide resources if a cybersecurity breach occurs.
+Added: Cybersecurity Governance
+Added: Our Board of Directors considers cybersecurity risk as part of its
+Added: risk oversight function.
+Added: The Audit Committee of our Board of Directors bears primary responsibility for the oversight of our cybersecurity
+Added: Periodically management updates our Audit Committee about various risks facing the Company, of which cybersecurity may be included.
+Added: Our cybersecurity risk assessment and management processes are implemented
+Added: and maintained by management and IT consultants .
+Added: The IT consultants have relevant expertise, experience, education and training as well
+Added: as knowledge of our company’s critical systems and information technology policies.
+Added: Our cybersecurity incident response processes are designed to escalate
+Added: certain cybersecurity incidents to our chief executive officer , who would be responsible, along with third parties including our IT consultants,
+Added: for assessing the materiality of, and mitigating and remediating, any cybersecurity incidents of which we are notified.
+Added: In addition, our
+Added: incident response processes include a procedure for reporting certain cybersecurity incidents to the Board of Directors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.