4 unchanged sentences
Risk Management and Strategy
−Removed: Global cybersecurity threats and incidents can pose risks to UEI, impacting data security, operational efficiency, and financial stability.
−Removed: Our business requires collection, processing, and retention of large volumes of Company and sensitive and confidential third party data, including personally identifiable information in various information systems that we maintain and in those maintained by third parties with whom we contract, including in areas such as customer product servicing, human resources outsourcing, website hosting, and various forms of electronic communications.
−Removed: Cybersecurity incidents risk disclosure of sensitive information and disruption of our operations.
−Removed: Financial consequences include recovery costs, fines, and potential legal repercussions.
−Removed: Such incidents could result in losses, severely damage our reputation or expose us to the risks of litigation and liability.
−Removed: Cybersecurity is managed as part of the Company's enterprise risk management program.
+Added: Cybersecurity is managed as part of our enterprise risk management program.
We have integrated cybersecurity risk management into our enterprise-wide risk assessment through evaluations of IT infrastructure, compliance audits and aligning cybersecurity goals with overall business objectives.
5 unchanged sentences
We collaborate with external cybersecurity consultants and auditors for independent audits and vulnerability assessments of our existing processes and systems.
−Removed: Our third-party cyber risk assessment program is designed to oversee certain third parties and have those third parties adhere to cybersecurity standards.
+Added: Our third-party cybersecurity risk assessment program is designed to oversee certain third parties and have those third parties adhere to cybersecurity standards.
This program has measures to help further manage and attempt to mitigate potential cybersecurity risks arising from third-party engagements, including security audits, compliance checks for cybersecurity standards, risk evaluation procedures for certain third parties, contractual security requirements in certain third party agreements and monitoring tools.
We conduct cybersecurity training with our employees as appropriate based on their roles within the Company.
−Removed: Our Board of Directors plays a role in guiding and overseeing our cybersecurity strategies.
−Removed: Our Audit Committee maintains responsibility for cybersecurity oversight by setting policies, reviewing risk management strategies and reviewing compliance with legal and regulatory requirements.
−Removed: The Audit Committee, as appropriate, briefs the broader Board of Directors on cybersecurity matters.
+Added: Our Board of Directors plays a role in guiding and overseeing our cybersecurity strategies and has tasked our Audit Committee with the responsibility for cybersecurity oversight by setting policies, reviewing risk management strategies and reviewing compliance with legal and regulatory requirements.
+Added: The Audit Committee, as appropriate, briefs the Board of Directors on cybersecurity matters.
Management is also responsible for upholding our cybersecurity processes.
−Removed: Our Vice President of IT Infrastructure is responsible for cybersecurity oversight and for developing strategies to mitigate cyber risks, monitoring policy compliance and educating staff on security practices.
−Removed: Our Cybersecurity Management team, led by our Vice President of IT Infrastructure, reports to the Audit Committee of the Board of Directors on cybersecurity matters, including incident reports, compliance status and updates on cybersecurity initiatives.
−Removed: The Audit Committee aims to meet at least once each fiscal quarter to specifically address cybersecurity matters, but convenes as necessary to fulfill its cybersecurity oversight responsibilities.
−Removed: To date, management has not identified risks from cybersecurity incidents, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
−Removed: While we work to maintain our cybersecurity processes, there can be no assurance that such actions will be sufficient to prevent cybersecurity incidents or mitigate all potential risks to such systems, networks, and data or those of our third-party providers.
+Added: To this end, we have established a global cybersecurity management team, led by our Vice President, Cybersecurity .
+Added: Our Vice President, Cybersecurity reports directly to our Senior Vice President and CFO and is primarily responsible for cybersecurity oversight and for developing strategies to mitigate risks from cybersecurity threats, monitoring policy compliance and educating staff on security practices.
+Added: In carrying out his duties, our Vice President, Cybersecurity provides periodic reports to the Director of our Internal Audit Department, who, in turn, briefs the Audit Committee of the Board of Directors on the contents of such reports, including incident reports, compliance status and updates on cybersecurity initiatives.
+Added: Our Vice President, Cybersecurity has extensive experience assessing and managing risks from cybersecurity threats, including more than 20 years of experience in information technology and information security positions;
+Added: serving in information technology leadership positions at the Company for more than 7 years;
+Added: and has other significant experience in the areas of risk management, information technology and information security, including the following industry certifications:
+Added: MCSE, MCDBA and CISSP.
+Added: To date, management has not identified risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: While we work to maintain our cybersecurity processes, there can be no
+Added: assurance that such actions will be sufficient to prevent cybersecurity incidents or mitigate all potential risks or threats to such systems, networks, and data or those of our third-party providers.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.