1 unchanged sentence
Cybersecurity
−Removed: Like all companies that utilize technology, we
−Removed: are subject to threats of breaches of our technology systems.
−Removed: To mitigate the threat to our business, we will take a comprehensive approach
−Removed: to cybersecurity risk management.
−Removed: Our management actively oversees our risk management program, including the management of cybersecurity
−Removed: We intend to establish policies, standards, processes and practices for assessing, identifying, and managing material risks from
−Removed: cybersecurity threats, including those discussed in our Risk Factors.
−Removed: We intend to devote financial and personnel resources to implement
−Removed: and maintain security measures to meet regulatory requirements and stakeholder expectations, and we intend to continue to make investments
−Removed: to maintain the security of our data and cybersecurity infrastructure.
−Removed: We intend to establish and maintain a Cybersecurity Maturity Model
−Removed: Certification (“CMMC”) compliance program and will work to meet all applicable deadlines.
−Removed: While there can be no guarantee
−Removed: that our policies and procedures will be properly followed in every instance or that those policies and procedures will be effective,
−Removed: we believe that the Company’s investment in people and technologies will contribute to a culture of continuous improvement that
−Removed: will put the Company in a position to protect against potential compromises and we do not believe that risks from prior cybersecurity
−Removed: threats have materially affected our business to date.
−Removed: We can provide no assurance that there will not be incidents in the future or
−Removed: that past or future attacks will not materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: Risk Management and Strategy
−Removed: At a high level, the key objectives for the Company’s
−Removed: cybersecurity program are to implement and sustain effective security controls to stop intrusion attempts and to maintain and continuously
−Removed: improve its ability to respond to attacks and incidents.
−Removed: Success in achieving these objectives relies upon using quality technology solutions,
−Removed: cultivating and maintaining a team of skilled professionals, and improving processes continuously.
−Removed: Our cybersecurity program in particular
−Removed: will focus on the following key areas:
−Removed: Risk Assessment :
−Removed: At least annually, we
−Removed: will conduct a cybersecurity risk assessment that takes into account information from internal stakeholders, known information security
−Removed: vulnerabilities, and information from external sources, including reported security incidents that have impacted other companies, industry
−Removed: trends, and evaluations by third parties and consultants.
−Removed: The results of the assessment will be used to develop initiatives to enhance
−Removed: our security controls, make recommendations to improve processes, and inform a broader Company-wide risk assessment that are then reported
−Removed: to our members of management.
−Removed: Technical Safeguards :
−Removed: We will regularly
−Removed: assess and deploy technical safeguards designed to protect our information systems from cybersecurity threats.
−Removed: Such safeguards are regularly
−Removed: evaluated and improved based on vulnerability assessments, cybersecurity threat intelligence and incident response experience.
−Removed: Incident Response and Recovery Planning :
−Removed: We will establish a comprehensive incident response and recovery plans that guide our response in the event of a cybersecurity incident.
−Removed: We will continuously test and evaluate the effectiveness of those plans.
−Removed: Vendor Risk Management :
−Removed: We will implement
−Removed: a vendor risk management program for domestic vendors, which will be designed to identify and mitigate cybersecurity threats associated
−Removed: with our use of domestic third-party service providers.
−Removed: Such providers are subject to security risk assessments at the time of on-boarding,
−Removed: contract renewal, and upon detection of an increase in risk profile.
−Removed: We will use a variety of inputs in such risk assessments, including
−Removed: information supplied by providers in response to detailed questionnaires and meetings as well as information from third parties.
−Removed: we will require our domestic providers to meet appropriate security requirements, controls and responsibilities and investigate security
−Removed: incidents that have impacted our third-party providers, as appropriate.
−Removed: Education and Awareness :
−Removed: will require each of our employees to contribute to our data security efforts.
−Removed: We will regularly remind employees of the importance of
−Removed: handling and protecting data, including through annual privacy and security training to enhance employee awareness of how to detect and
−Removed: respond to cybersecurity threats.
−Removed: As part of that educational process, we will periodically simulate cybersecurity threats to the Company
−Removed: and review/assess employee responses.
−Removed: In this regard, the Company will implement policies and procedures for all employees including:
−Removed: (i) information security/cybersecurity policies, which are internally available for all employees, (ii) information security/cybersecurity
−Removed: awareness training;
−Removed: (iii) a clear escalation process which employees can follow in the event an employee notices something suspicious;
−Removed: and (iv) ensuring that information security/cybersecurity is part of the employee performance evaluation and/or disciplinary process.
+Added: Management and Strategy
+Added: all companies that utilize technology, we are subject to threats of breaches of our technology
+Added: To mitigate the threat to our business, we will take a comprehensive approach to
+Added: cybersecurity risk management.
+Added: Our management actively oversees our risk management program,
+Added: including the management of cybersecurity risks.
+Added: We intend to establish policies, standards,
+Added: processes and practices for assessing, identifying, and managing material risks from cybersecurity
+Added: threats, including those discussed in our Risk Factors.
+Added: We intend to devote financial and
+Added: personnel resources to implement and maintain security measures to meet regulatory requirements
+Added: and stakeholder expectations, and we intend to continue to make investments to maintain the
+Added: security of our data and cybersecurity infrastructure.
+Added: We intend to establish and maintain
+Added: a Cybersecurity Maturity Model Certification (“CMMC”) compliance program and
+Added: will work to meet all applicable deadlines.
+Added: While there can be no guarantee that our policies
+Added: and procedures will be properly followed in every instance or that those policies and procedures
+Added: will be effective, we believe that the Company’s investment in people and technologies
+Added: will contribute to a culture of continuous improvement that will put the Company
+Added: in a position to protect against potential compromises and we do not believe that risks from
+Added: prior cybersecurity threats have materially affected our business to date.
+Added: We can provide
+Added: no assurance that there will not be incidents in the future or that past or future attacks
+Added: affect us, including our business strategy, results of operations , or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.