7 unchanged sentences
We employ a range of methods to assess, identify and manage the risk of potential cybersecurity threats, including regular security audits, utilization of a third party service provider for security measures over our virtual environment, threat intelligence monitoring, and vulnerability assessments.
−Removed: Our risk management framework is designed to mitigate potential cyber risks through a blend of technological safeguards, employee training programs, and incident response protocols.
+Added: We assess risks associated with third-party providers as part of our overall cybersecurity risk management framework by reviewing system and organization controls reports, when available, and other independent reports.
+Added: We also generally require third parties to, among other things, maintain security controls to protect our confidential information and to promptly notify us of material breaches that may impact our data.
+Added: Our risk management framework is designed to mitigate potential cybersecurity risks through a blend of technological safeguards, employee training programs, and incident response protocols.
+Added: We devote resources to maintain and regularly update our systems and processes that are designed to protect the security of our computer systems, software, networks and other technology assets against attempts by unauthorized parties to obtain access to confidential information, destroy data, disrupt or degrade service, sabotage systems or cause other damage, and we have implemented certain review and approval procedures internally and with our banks;
+Added: and have implemented system-wide changes.
Cybersecurity Strategy and Investment
7 unchanged sentences
Management plays a critical role in implementing these policies and in the day-to-day management of cybersecurity risks.
−Removed: They are empowered with the maintenance, communication and enforcement of cybersecurity policies and employ proactive measures to improve cyber security through review of various third party cyber tools for potential implementation.
−Removed: Our Head of IT and CFO are responsible for overseeing the implementation of cybersecurity strategies and ensuring compliance with regulatory standards.
−Removed: In addition to our in-house expertise, the Company employs independent external auditors and an outsourced internal audit team, who regularly test and asses our cybersecurity controls.
+Added: They are empowered with the maintenance, communication and enforcement of cybersecurity policies and employ proactive measures to improve cybersecurity through review of various third party cyber tools for potential implementation.
+Added: Our Head of IT and Chief Financial Officer ("CFO") are responsible for overseeing the implementation of cybersecurity strategies and ensuring compliance with regulatory standards.
+Added: In addition to our in-house expertise, our independent external auditors and our outsourced internal audit team, regularly test and asses our cybersecurity controls.
Any cyber incidents that occur are escalated to the CFO to facilitate resolution.
−Removed: Any incident determined to be material is discussed with the Audit Committee and communicated to the company's internal and external auditors as well as the company's third party virtual environment service provider, when relevant).
+Added: Any incident determined to be material is discussed with the Audit Committee and communicated to our internal and external auditors as well as our third party virtual environment service provider, when relevant.
Material Effects of Cybersecurity Risks
−Removed: Our business strategy, results of operation and financial condition have been not been materially affected by risks from cybersecurity threats, nor did we experience any significant cybersecurity incidents in 2023.
+Added: Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats or incidents.
However, we cannot provide assurances that they will not be materially affected by such risks or material incidents in the future.
5 unchanged sentences
We intend to further enhance our cybersecurity measures in response to the dynamic cyber threat landscape.
−Removed: This includes investing in advanced security technologies, refining our risk assessment methodologies, and continuing our commitment to staff training and development in cybersecurity awareness and best practices.
+Added: This includes continuing to invest in advanced security technologies, refining our risk assessment methodologies, and continuing our commitment to staff training and development in cybersecurity awareness and best practices.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.