2 unchanged sentences
We operate through our subsidiaries and receive services through our intercorporate services agreement (“ISA”) with Contran (see Note 17 to our Consolidated Financial Statements).
−Removed: We recognize the importance of assessing, identifying, and managing material risks associated with cybersecurity threats.
+Added: We recognize the importance of proactively assessing, identifying, and managing material risks associated with cybersecurity threats.
These risks include, among other things:
−Removed: operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy
−Removed: or security laws.
−Removed: Our cybersecurity programs are built on operations and compliance foundations.
−Removed: Operations focus on continuous detection, prevention, measurement, analysis, and response to cybersecurity alerts and incidents and on emerging threats.
−Removed: Compliance establishes oversight of our cybersecurity programs by creating risk-based controls to protect the integrity, confidentiality, accessibility and availability of company data stored, processed or transferred.
−Removed: Our cybersecurity program is integrated within our overall risk management processes.
+Added: operational disruptions, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
+Added: Our cybersecurity programs are built on both operational and compliance foundations.
+Added: The operational component focuses on continuous detection, prevention, measurement, analysis, and response to cybersecurity alerts and incidents and on emerging threats.
+Added: The compliance component establishes oversight of our cybersecurity programs by creating risk-based controls to protect the integrity, confidentiality, accessibility and availability of company data stored, processed or transferred.
+Added: Our cybersecurity program is fully integrated into our enterprise-wide risk management framework.
Kronos and CompX each have their own cybersecurity programs.
−Removed: Our corporate cybersecurity program is led by our chief information officer (CIO) who is responsible for our overall information security strategy, policy, security engineering, operations and cyber threat detection and response.
+Added: Our corporate cybersecurity program is led by our chief information officer (“CIO”), who is responsible for developing and executing our overall information security
+Added: strategy, policy, security engineering, operations and cyber threat detection and response .
Our corporate information systems are owned and operated by Contran and provided to us through the ISA.
4 unchanged sentences
Cybersecurity risks at each company are also reviewed and tested annually through third-party assessments and internal and external information technology audits.
−Removed: Our, Kronos’ and CompX’s information technology teams review enterprise risk management level cybersecurity risks annually.
−Removed: We, Kronos and CompX continually enhance our security structure with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while simultaneously increasing our system resilience in an effort to minimize the business impact should an incident occur.
+Added: Our, Kronos’ and CompX’s information technology teams review cybersecurity risks at least annually, integrating findings into strategic risk assessments.
+Added: We, Kronos and CompX continually enhance our cyber defense strategy with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while simultaneously bolstering our system resilience in an effort to minimize the business impact should an incident occur.
Third parties also play a role in our cybersecurity.
−Removed: We, Kronos and CompX engage third-party services to conduct evaluations of our security controls through penetration testing, red team testing, consulting on best practices and to address new challenges.
+Added: We, Kronos and CompX engage reputable third-party security firms for consultation on industry best practices and regulatory standards and to conduct routine evaluations of our cybersecurity, such as through penetration testing and security audits;
these evaluations include testing both the design and operational effectiveness of security controls.
−Removed: All employees are required to complete cybersecurity training at least once a year and have access to more frequent cybersecurity training through online training.
−Removed: We also require employees in certain roles to complete additional role-based, specialized cybersecurity trainings.
+Added: All employees are required to complete cybersecurity training at least once a year and have access to more frequent cybersecurity training through periodic updates.
+Added: Employees in certain roles also receive additional role-based, specialized cybersecurity training.
We, Kronos and CompX each have a Cybersecurity Incident Disclosure and Controls Committee (“CIDAC”) which is central to the response and evaluation of cybersecurity incidents.
1 unchanged sentence
Security events and data incidents are evaluated, ranked by severity and prioritized for response and remediation.
−Removed: The IT teams are responsible for categorizing cybersecurity incidents, with incidents evaluated to be high or critical security risks brought to the CIDAC for review and evaluation.
−Removed: Incidents are evaluated to determine materiality as well as operational and business impact.
+Added: The IT teams are responsible for categorizing cybersecurity incidents, and those deemed high-risk or critical are escalated to the CIDAC for review and response coordination.
+Added: Incidents are evaluated to determine materiality and for operational, financial and reputational impact.
Our CIDAC, as well as the Kronos and CompX CIDAC, performs simulations and tabletop exercises at a management level to evaluate our readiness and response to cybersecurity incidents.
−Removed: External resources and advisors are incorporated as needed.
+Added: As needed, we collaborate with external cybersecurity experts and legal advisors to help ensure a robust response strategy.
Our board of directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help align our risk exposure with our strategic objectives.
−Removed: Senior leadership, including our chief financial officer and CIO, regularly brief the board of directors on our cybersecurity and information security posture, and our board of directors is apprised of cybersecurity incidents deemed to have a high or critical business impact, even if immaterial to us.
+Added: Senior leadership, including our chief financial officer and CIO, provides regular updates to the board of directors on our cybersecurity posture, emerging threats and our risk mitigation efforts.
+Added: Our board of directors is apprised of cybersecurity incidents deemed to have significant business impact, even if they are not material to us.
The board has delegated some of its primary risk oversight to board committees, including that our audit committee facilitates the board’s process of oversight of our overall risk management approach.
Our full board retains oversight of cybersecurity because of its importance to us and visibility with our customers.
−Removed: In the event of an incident, we intend to follow our detailed incident response playbook, which outlines the steps to be followed from incident detection to mitigation, recovery and notification.
−Removed: This includes notifying functional areas (such as legal and human resources), senior leadership and the board as appropriate.
+Added: In the event of an incident, we follow a structured incident response playbook, which outlines clear and defined steps to be followed from incident detection to mitigation, recovery and notification, including notifying functional areas (such as legal and human resources), senior leadership and the board, as appropriate.
+Added: We also conduct post-incident reviews to identify lessons learned and implement continuous improvements.
We, Kronos and CompX face a number of cybersecurity risks.
To date, such risks have not materially affected us, including our business strategy , results of operations or financial condition.
−Removed: While we have not experienced any breaches, we have encountered occasional attempts, albeit of minor significance, targeting our data and systems, including instances of malware and computer virus infiltration.
−Removed: Thus far all such incidents have been minor.
−Removed: For more information
−Removed: about the cybersecurity risks we face, see the risk factor entitled “Technology failures or cybersecurity breaches could have a material adverse effect on our operations.” in Item 1A- “Risk Factors”.
+Added: While we have not experienced any major breaches, we actively monitor and mitigate cyber threats, including phishing attempts, malware and targeted attacks.
+Added: Thus far all such incidents have been minor, isolated and promptly contained.
+Added: For more information about the cybersecurity risks we face, see the risk factor entitled “Technology failures or cybersecurity breaches could have a material adverse effect on our operations.” in Item 1A- “Risk Factors.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.