4 unchanged sentences
T o address cybersecurity threats to this information, the Company uses a risk-based approach to create and implement a detailed set of information security policies and procedures based on frameworks established by the National Institute of Standards and Technology.
−Removed: The Company’s Head of Information Security leads the Company’s cybersecurity efforts under the direct oversight of our Chief Technology Officer.
−Removed: Together, these individuals have over 50 years of experience involving information technology, including security, auditing, compliance, systems and programming.
+Added: The Company’s Head of Information Security manages the Company’s cybersecurity efforts and leads the cybersecurity team under the direct oversight of our Chief Technology Officer.
+Added: These individuals, including all members of the cybersecurity team, have an average of over 16 years of experience involving information technology, including security, auditing, compliance, systems, and programming.
Additionally, the Company engages in the use of external cybersecurity experts for training, contingency planning, consultation, and process documentation.
2 unchanged sentences
Both internal and third-party audits are performed routinely to verify that these controls are effective.
−Removed: Additionally, the Company has implemented trainings designed to provide best practices for protecting our network and systems, and also routinely leads exercises for employees to reinforce the risk and proper handling of targeted emails.
+Added: Additionally, the Company has implemented companywide security awareness training programs designed to provide best practices for protecting our network and systems, and routinely leads exercises for employees to reinforce the risk and proper handling of targeted emails.
The Company’s Head of Information Security is responsible for developing and implementing these controls and training exercises with support from our information technology department.
−Removed: The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks.
−Removed: This committee comprises members of management of the Company’s information technology, human resources, marketing, accounting, risk, procurement, training, finance and legal functions, and is focused on performing risk assessments to identify areas of concern and implement appropriate changes to enhance its
−Removed: cybersecurity and privacy policies and procedures.
+Added: The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks including risks associated with the Company’s use of artificial intelligence.
+Added: This committee comprises members of management of the Company’s information technology, human resources, marketing, accounting, risk, procurement, training, finance, and legal functions, and is focused on performing risk assessments to identify areas of concern and implement appropriate changes to enhance its cybersecurity and privacy policies and procedures.
The internal risk committee is informed of the Company’s risk prevention and mitigation efforts on a regular basis.
4 unchanged sentences
There can be no guarantee that our policies and procedures will be effective.
−Removed: Although our risk factors include further detail about the material cybersecurity risks we face and how a cybersecurity incident may affect our business strategy, results of operations or financial condition, we believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incident, have not materially affected our business to date.
+Added: Although our risk factors include
+Added: further detail about the material cybersecurity risks we face and how a cybersecurity incident may affect our business strategy, results of operations, or financial condition, we believe that risks from prior cybersecurity threats, including as a result of any prior cybersecurity incident, have not materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition to date .
We can provide no assurances that there will not be incidents in the future or that they will not materially affect us, including our business strategy, results of operations, or financial condition.
1 unchanged sentence
This delegation includes maintaining responsibility for overseeing the Company’s enterprise risk management program.
−Removed: As a part of this oversight role, the audit committee receives regular updates from management on cybersecurity and privacy risks impacting the Company, which includes benchmarking these risks versus our industry.
+Added: As a part of this oversight role, the audit committee receives regular updates from management on cybersecurity threats and privacy risks impacting the Company , which includes benchmarking these risks versus our industry.
Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events, receive training specific to cybersecurity risks and threats and regularly discuss any updates to our cybersecurity risk management and strategy programs.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.