17 unchanged sentences
As part of the above processes, we regularly engage external auditors and consultants to assess our internal cybersecurity programs and compliance with applicable practices and standards.
−Removed: As of 2024, our Information Security Management System has been certified to conform to SOC 2 Type 2 and PCI, and are working to conform to ISO 27001.
+Added: Since 2024, our Information Security Management System has been certified to conform to SOC 2 Type 2 and PCI, and are working to conform to ISO 27001.
Our risk management program also assesses third -party risks, and we perform third -party risk management to identify and mitigate risks from third parties such as vendors, suppliers, and other business partners associated with our use of third -party service providers.
2 unchanged sentences
We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “If our security applications are breached by cyberattacks or are not adequate to address changing market conditions and customer concerns, we may incur significant losses and be unable to sell our services” included as part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K.
−Removed: The Board of Directors is responsible for overseeing the Company’s enterprise risk, and has established its Risk and Cybersecurity Committee with specific responsibility for overseeing cybersecurity threats, among other things.
−Removed: The Company’s cybersecurity organization is led by the CTO, who is responsible for assessing and managing material risks from cybersecurity threats and reports to Usio’s CEO, CAO, and Legal team, as well as to the Risk and Cybersecurity Committee .
+Added: The Board is responsible for overseeing the Company’s enterprise risk, and has established its Risk and Cybersecurity Committee with specific responsibility for overseeing cybersecurity threats, among other things.
+Added: The Company’s cybersecurity organization is led by the Chief Technology Officer, or CTO, who is responsible for assessing and managing material risks from cybersecurity threats and reports to Usio’s CEO, CAO, and Legal team, as well as to the Risk and Cybersecurity Committee.
The CTO has served in this role for 18 years, and more than 22 years with the Company developing, maintaining, and securing our corporate network and information technology systems.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.