6 unchanged sentences
National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”).
−Removed: We have undertaken, on
−Removed: an annual basis, to conduct an assessment of our cyber risk management processes and controls to identify, quantify, and categorize material
−Removed: In addition, we have developed a risk mitigation plan to address such risks, and where necessary, remediate potential vulnerabilities
−Removed: identified through the annual assessment process.
+Added: We have undertaken an
+Added: assessment of our networking risk management processes and controls to identify, quantify, and categorize material risks.
+Added: we have developed a risk mitigation plan to address such risks, and where necessary, remediate potential vulnerabilities identified through
+Added: the annual assessment process.
In addition, we maintain policies over areas such
15 unchanged sentences
our cyber risk management program, and the emerging threat landscape and new cyber risks on at least an annual basis.
−Removed: This includes updates
−Removed: on Forza’s processes to prevent, detect, and mitigate cybersecurity incidents.
−Removed: In addition, cybersecurity risks are reviewed by
−Removed: our Board of Directors at least annually, as part of the Company’s corporate risk oversight processes.
+Added: In addition, cybersecurity
+Added: risks are reviewed by our Board of Directors at least annually, as part of the Company’s corporate risk oversight processes.
We face risks from cybersecurity threats that could
have a material adverse effect on our business, financial condition, results of operations, cash flows or reputation.
−Removed: We acknowledge
−Removed: that the risk of cyber incidents is prevalent in the current threat landscape and that a future cyber incident may occur in the normal
−Removed: course of its business.
+Added: We acknowledge that
+Added: the risk of cyber incidents is prevalent in the current threat landscape and that a future cyber incident may occur in the normal course
+Added: of its business.
To date, we have not had a cybersecurity incident.
−Removed: We proactively seek to detect and investigate unauthorized
−Removed: attempts and attacks against our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through
−Removed: changes or updates to internal processes and tools and changes or updates to service delivery;
−Removed: however, potential vulnerabilities to known
−Removed: or unknown threats will remain.
+Added: We proactively seek to detect and investigate unauthorized attempts
+Added: and attacks against our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through changes
+Added: or updates to internal processes and tools and changes or updates to service delivery;
+Added: however, potential vulnerabilities to known or
+Added: unknown threats will remain.
Further, there is increasing regulation regarding responses to cybersecurity incidents, including reporting
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.