20 unchanged sentences
The Company engages or otherwise collaborates with cybersecurity consultants, cybersecurity experts , energy sector leaders, and other third parties in connection with the Cybersecurity Plan.
−Removed: Unitil Corporation also is a member of the cyber committees of both the American Gas Association and the Edison Electric Institute.
+Added: Unitil Corporation is also a member of the cyber committees of both the American Gas Association and the Edison Electric Institute.
Third-party entities that provide hardware, software or related support services to the Company or hold the Company’s customer data represent material cybersecurity risks to the Company.
5 unchanged sentences
The Company’s cybersecurity management team is responsible for assessing and managing the Company’s material risks from cybersecurity threats, including implementing the Cybersecurity Plan.
−Removed: The team includes the Company’s Chief Technology Officer and Vice President of Information Technology (the “CTO”), the Director of Information Security and Cyber Operations, Manager of Cyber Security Operations and two Cyber Operations Engineers, all of whom have an educational background relevant to, professional experience in, or other expertise in cybersecurity.
−Removed: This team is supported by the Company’s Information Technology department.
−Removed: The CTO holds a Master of Business Administration and a Bachelor of Science in Electrical Engineering with over 30 years of professional experience in the utility industry with extensive management experience in engineering, operations and information technology.
−Removed: The CTO also assumes responsibilities as the Company’s Chief Information Security Officer and Chief Cyber Security Officer.
−Removed: The CTO has overall management responsibility for the Company’s cybersecurity.
−Removed: The CTO reports to the Company’s Chief Executive Officer.
−Removed: The Director of Information Security and Cyber Operations holds a Bachelor of Science in Computer Science and a Masters Certificate in Cyber Security with a concentration in Power Systems and has over 30 years of experience in the information technology field.
−Removed: The Director of Information Security and Cyber Operations has primary responsibility for the cyber security program including threat and vulnerability management, vendor security posture assessment, Industrial Control System (ICS) and SCADA infrastructure cyber security protection at electric substations and natural gas plants, as well as leading the Cyber Incident Response Team.
−Removed: The Manager of Cyber Security Operations has a Bachelor of Science in Information Technology and over 20 years of experience in various information technology and cyber roles.
+Added: The team includes the Company’s Senior Vice President of Shared Services and Director of Information Security and Infrastructure Operations, all of whom have an educational background relevant to, professional experience in, or other expertise in cybersecurity.
+Added: The Senior Vice President, Shared Services holds a Master of Business Administration and Bachelor of Arts with over 25 years of professional experience leading teams in Human Resources, Supply Chain and Information Technology.
+Added: The Senior Vice President of Shared Services has overall management responsibility for the Company’s cybersecurity.
+Added: The Senior Vice President of Shared Services reports to the Company’s President and Chief Administrative Officer .
+Added: The Director of Information Security and Cyber Operations holds CISSP and ITIL certifications, a Bachelor of Science in Computer Science and a Master’s Certificate in Cybersecurity with a concentration in Power Systems and has over 30 years of experience in the information technology field.
+Added: The Director of Information Security and Infrastructure Operations also assumes responsibilities as the Company’s Chief Information Security Officer (CISO).
+Added: The Director of Information Security and Infrastructure Operations has primary responsibility for the cybersecurity program including threat and vulnerability management , vendor security posture assessment, Industrial Control System (ICS) and SCADA infrastructure cybersecurity protection at electric substations and natural gas plants, as well as leading the Cyber Incident Response Team.
The Company’s cybersecurity management team assesses and manages the Company’s material risks from cybersecurity threats through or by:
6 unchanged sentences
• vendor security posture assessment;
−Removed: • Industrial Control System and Supervisory Control and Data Acquisition infrastructure cyber security protection at electric substations and natural gas plants;
+Added: • Industrial Control System and Supervisory Control and Data Acquisition infrastructure cybersecurity protection at electric substations and natural gas plants;
• leading the Company’s Cyber Incident Response Team.
In addition, the Company uses (i) a Security Operations Center vendor with 24x7 monitoring and response capabilities to identify any suspicious activity on the Company’s networks and (ii) a security consulting firm for assessments, penetration testing and incident response.
−Removed: In the event of a cybersecurity threat, the CTO and these parties would collaborate to assess and manage the risk with ultimate responsibility residing with the Board.
−Removed: Also, in the event of a cybersecurity threat or cybersecurity incident, the Company’s cybersecurity management team will investigate and perform impact analysis and, as necessary, the CTO will activate the Company’s Cyber Incident Response Team.
+Added: In the event of a cybersecurity threat, the CISO and these parties would collaborate to assess and manage the risk with ultimate responsibility residing with the Board.
+Added: Also, in the event of a cybersecurity threat or cybersecurity incident, the Company’s cybersecurity management team will investigate and perform impact analysis and, as necessary, the CISO will activate the Company’s Cyber Incident Response Team.
The Cyber Incident Response Team is a subset of the Company’s Crisis Response Team, which has responsibility for operational and business resilience, as well as tactical and strategic response.
A foundational aspect of the Crisis Response Team is prompt and comprehensive communications to all concerned parties, both internal and external, including direction for management to inform the Board about risks from cybersecurity threats.
−Removed: In the event that a cybersecurity incident occurs which results in damage to the Company’s data or infrastructure, the Cyber Incident Response Team would follow the Company’s Cyber Incident Response Plan.
−Removed: The Cyber Incident Response Plan was developed using the guidelines described in the National Institute of Standards and Technology Special Publication 800-61 Revision 2 Computer Security Incident Handling Guide, has been reviewed and assessed by outside experts, is updated
−Removed: annually, and is used to train for cybersecurity incidents.
−Removed: The Cyber Incident Response Plan details the identification, containment, eradication and recovery processes specific to the Company’s environment with prioritization of critical assets.
−Removed: The Cyber Incident Response Plan also details emergency actions required to isolate and protect industrial control system environments, should the incident pose a risk to electric or gas operations.
−Removed: The Company participates in annual industry drill exercises to test the Cyber Incident Response Plan.
The Company’s determination of the materiality of a cybersecurity incident would generally include an evaluation of the incident’s effect on the Company (including (i) its business strategy, results of operations, or financial condition, (ii) the integrity, confidentiality, resiliency, and security of the Company’s networks and systems, and (iii) the Company’s operations).
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.