6 unchanged sentences
The Information Security Program also addresses cybersecurity risks associated with our use of third-party service providers through systems and processes that are designed to assess, identify, and reduce the potential likelihood and impact of a cybersecurity incident at our third-party service providers.
+Added: However, we rely on our third-party partners to implement effective information security programs commensurate with the risk associated with the nature of their business relationships to us and cannot ensure in all circumstances their efforts will be successful.
The Information Security Program is based on Center for Internet Security (“CIS”) Controls, a cybersecurity framework that is acknowledged worldwide and is designed to comply with applicable laws and guidelines.
−Removed: We also have adopted a cybersecurity incident response and recovery plan to enable us to properly respond to cybersecurity incidents that may affect the function and security of the Company, our IT assets, customer and employee data, information resources, and business operations.
−Removed: We have adopted cyber and data security policies, which address matters including user access, incident response, third-party compliance, personal devices, and data privacy.
−Removed: These policies are reviewed
−Removed: annually, including by our independent auditor.
+Added: We also have adopted a cybersecurity incident response and recovery plan to enable us to respond to cybersecurity incidents that may affect the function and security of the Company, our information technology assets, customer and employee data, information resources, and business operations.
+Added: We have adopted cyber and data security policies, that address matters including user access, incident response, third-party compliance , personal devices, and data privacy.
+Added: These policies are reviewed annually.
We also maintain insurance covering certain costs that may be incurred in connection with cybersecurity incidents, should they occur.
2 unchanged sentences
We also provide employees with educational materials about emerging cybersecurity threats and update employees when our information security policies are amended.
−Removed: We regularly evaluate our Information Security Program based on software vendor assessments and reports, insurance underwriter evaluations, and internal and external audits, including, without limitation, customer audits.
+Added: We regularly evaluate our Information Security Program based on software vendor assessments and reports, insurance underwriter evaluations, and internal and external audits, including customer audits.
We also periodically engage third parties to review the effectiveness of its Information Security Program.
To date, these engagements have included third-party penetration testing, risk identification, and a fiscal year 2023 comprehensive evaluation of the maturity of our Information Security Program.
−Removed: Management has determined that no cybersecurity incidents that we have experienced to date have resulted in, or are reasonably likely to result in, a material impact to its financial condition, results of operations, or business strategy.
−Removed: For additional information on risks from cybersecurity threats and potential related impacts on the Company, please see Item 1A – Risk Factors.
+Added: Management has determined that no cybersecurity incidents that we have experienced to date have resulted in, or are reasonably likely to result in, a material adverse effect on our financial condition, results of operations, or business strategy.
+Added: For additional information on risks from cybersecurity threats and potential related impacts on the Company, please see Item 1A.
+Added: “Risk Factors.”
Cybersecurity Governance
Board Oversight
−Removed: The Board of Directors is ultimately responsible for our Information Security Program, and it has delegated to the Audit Committee primary oversight responsibility for this program.
+Added: The Board of Directors is ultimately responsible for our Information Security Program, and it has delegated to the Audit Committee primary oversight responsibility for this information security and technology (including cybersecurity) risk management program.
The Audit Committee periodically reviews the program and information security, cybersecurity, and technology risks.
3 unchanged sentences
Management Oversight
−Removed: The Information Security Program is overseen by our Information Security Steering Team, which provides cross-functional program oversight and maintenance and includes members from the Information Technology, Internal Audit, Legal, and Risk Management Departments.
−Removed: This team is also responsible for developing, implementing, and maintaining our information security policies and procedures.
−Removed: Our Chief Information Officer and Corporate Director of Information Technology Security, in coordination with our Information Technology Department and other appropriate personnel, are responsible for assessing and managing our risks from cybersecurity threats.
−Removed: The Chief Information Officer has served in various roles in information technology and information security for over 25 years, has been in his current role for more than 10 years, and holds a degree in Computer Science.
−Removed: The Corporate Director of Information Technology Security has served in various roles in information technology and information security for over 30 years, has been in his current role for more than 15 years, and has been trained in multiple cybersecurity subjects.
+Added: Our Information Security Program is a comprehensive framework of policies, procedures, and guidelines designed to ensure the security, availability, and confidentiality of our systems.
+Added: Our Chief Information Officer (CIO) and Corporate Director of Information Technology Security (CDIS) , in coordination with our Information Technology Department and other appropriate personnel, are responsible for assessing and managing our risks from cybersecurity threats.
+Added: The CIO has served various roles in information technology and information security for over 25 years, including Corporate Director, Technology & IS Strategy and Director of Applications and Technology, has been in his current role for more than 10 years, and holds a BS degree in Computer Science.
+Added: Our CIO has various industry certifications, including being a Microsoft Certified Professional (MCP) and holding the Project Management Professional (PMP) certification, offered by the Project Management Institute (PMI).
+Added: The program is led by our CDIS, who operates under the direction of the CIO.
+Added: With over 30 years of experience in IT and cybersecurity, the CDIS heads our global Information Security team and the Security Steering team.
+Added: This multidisciplinary team comprises experts from IT, Infosec, Legal, Audit, and Risk.
+Added: The CDIS brings extensive expertise across a diverse array of platforms, services, and technologies.
A third-party security operations center, which is in operation at all times, is responsible for monitoring all logs, events, and alerts from our Endpoint Detection & Response (“EDR”) platforms and cloud deployed services.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.