8 unchanged sentences
Key enterprise-level cybersecurity risks are incorporated into the Risk Management Committee’s framework and are assessed throughout the year.
−Removed: In addition, internal and external auditors assess our information technology general controls on an annual basis.
+Added: In addition, our information technology general controls are assessed on an annual basis.
Furthermore, we have a set of Company-wide policies and procedures concerning cybersecurity matters, which include an IT Security Policy and Cyber Incident Response Plan, as well as other policies that directly or indirectly relate to cybersecurity, non-public information and the use of the internet, social media, email, and wireless devices.
4 unchanged sentences
We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises at a management level and incorporate external resources and advisors as needed.
−Removed: All employees with computer access are asked to complete cybersecurity training at least once per year and have access to more frequent cybersecurity trainings through online trainings.
−Removed: We conduct employee phishing tests on a quarterly basis and also require employees in certain roles to complete additional role-based, specialized cybersecurity trainings.
+Added: All employees with computer access are asked to complete cybersecurity training at least once per year and have access to more frequent cybersecurity training through an online training platform.
+Added: We conduct employee phishing tests on a quarterly basis and also require employees in certain roles to complete additional role-based, specialized cybersecurity training.
We have continued to expand investments in IT security, including additional end-user training, using layered defenses, identifying and protecting critical assets, strengthening monitoring and alerting, and engaging experts.
3 unchanged sentences
Further, we conduct periodic external penetration tests and maturity testing to assess our processes and procedures and the threat landscape.
−Removed: These tests and assessments are useful tools for maintaining a robust cybersecurity program to protect our investors, customers, employees and vendors.
+Added: These tests and assessments are useful for maintaining a robust cybersecurity program to protect our investors, customers, employees and vendors.
In addition to assessing our own cybersecurity preparedness, we also consider and evaluate cybersecurity risks associated with use of third-party service providers.
2 unchanged sentences
If a third-party vendor is not able to provide a SOC 1 or SOC 2 report, we take additional steps to assess their cybersecurity preparedness and assess our relationship on that basis.
+Added: Our program also incorporates continuous monitoring of critical SaaS and Cloud providers.
Our assessment of risks associated with use of third-party providers is part of our overall cybersecurity risk management framework.
2 unchanged sentences
The Audit Committee’s annual review also includes review of recent enhancements to the Company’s defenses and management’s progress on its cybersecurity strategic roadmap.
−Removed: In addition, the Board receives updates from the Chief Information Officer throughout the year.
+Added: In addition, the Board receives formal updates from the Chief Information Officer throughout the year.
Further, at least annually, the Board receives updates on the Company’s Crisis Management Guide, including its relation to our Cybersecurity Incident Response Plan.
3 unchanged sentences
Although such risks have not materially affected us, our business strategy, results of operations or financial condition, to date, we have, from time to time, experienced threats to and breaches of our data and systems, including malware and computer virus attacks.
−Removed: For more information about the cybersecurity risks we face, see the risk factor entitled “We are dependent on information technology systems (our own and those of our service providers such as Amazon Web Services), and these systems contain non-public data about our business, employees, suppliers and customers” in Item 1A “ Risk Factors .”
+Added: For more information about the cybersecurity risks we face, see the risk factor entitled “We are dependent on information technology systems (our own and those of our service providers), and these systems contain non-public data about our business, employees, suppliers and customers” in Item 1A “ Risk Factors .”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.