5 unchanged sentences
Our ERM processes consider cybersecurity threat risks alongside other company risks as part of our overall management activities.
−Removed: Cybersecurity risks related to our business are identified and managed though a multi-faceted approach utilizing various systems, controls, and processes.
+Added: Cybersecurity risks related to our business are identified and managed through a multi-faceted approach utilizing various systems, controls, and processes .
+Added: Our cybersecurity systems, controls and processes are overseen by our cybersecurity information technology team which is managed by our CISO.
We maintain a layered security architecture as a key part of our infrastructure design and utilize our employees and managed third-party service providers to help ensure a secure environment and safeguard against a variety of threats including malware, systems intrusions, unauthorized access, data loss and other security risks.
15 unchanged sentences
It also incorporates various event, incident and response teams that comprise the Company's information security, risk management, compliance, legal and other functions as needed in response to any cybersecurity incidents.
−Removed: Our incident response protocol also provides for reporting mechanisms to senior management and our Board of Directors in the event of a material cybersecurity incident.
+Added: Our incident response protocol also provides for reporting mechanisms to senior management and our Board of Directors ("Board") in the event of a material cybersecurity incident.
We have not had a cybersecurity incident that has materially affected, or was reasonably likely to, materially affect, our business strategy, results of operations or financial condition.
There are risks from cybersecurity threats that if they were to occur could materially affect our business strategy, results of operations or financial condition which are further discussed in Item 1A.
−Removed: “Risk Factors—Risks Related to our Industry, Business and Operations— We and our third-party service providers rely on numerous technology systems and any business interruption, security breach, or system failure could negatively impact our business and profitability ” of this Annual Report on Form 10-K, which should be read in conjunction with the information in this section.
+Added: “Risk Factors—Risks Related to our Industry, Business and Operations— We and our third-party service providers
+Added: rely on numerous technology systems and any business interruption, security breach, or system failure could negatively impact our business and profitability ” of this Annual Report on Form 10-K, which should be read in conjunction with the information in this section.
Cybersecurity Governance
−Removed: Our Board of Directors ("Board") oversees our risk management processes, including our risks from cybersecurity threats.
+Added: Our Board oversees our risk management processes, including our risks from cybersecurity threats.
As part of its ongoing responsibilities, the Board receives recurring reports from management on the Company’s cybersecurity risk environment and regularly meets with management to review the risk landscape and discuss the steps taken by management to monitor and mitigate cyber exposures.
1 unchanged sentence
The Company maintains an Enterprise Risk Committee (“ERC”), comprising the Company executives who lead day-to-day risk management, and whose efforts are supplemented by specific risk-related committees or teams.
−Removed: The ERC is a cross-
−Removed: functional committee that focuses on identifying and managing operational risk throughout the organization, including cybersecurity threats.
+Added: The ERC is a cross-functional committee that focuses on identifying and managing operational risk throughout the organization, including cybersecurity threats.
The ERC has integrated cybersecurity into key elements of the Company’s ERM framework, including our BCDR planning program and service provider management policy, and personnel from our information security, risk management, compliance and legal groups are a part of the assessment and response team for cybersecurity incidents and the evaluation of third-party cybersecurity risk.
−Removed: Our cybersecurity systems, controls and processes are overseen by our cybersecurity information technology team which is managed by our CISO.
−Removed: Our CISO has over 25 years of experience in the information technology and cybersecurity field and is a Certified Information Systems Security Professional.
We lease our principal offices, which are located at One Financial Plaza, Hartford, CT 06103.
−Removed: In addition, we lease office space in California, Connecticut, Florida, Georgia, Illinois, Massachusetts, New Jersey, New York, Texas, Singapore and the UK.
+Added: In addition, we lease office space in California, Connecticut, Florida, Georgia, Illinois, Massachusetts, New Jersey, New York, Texas, Singapore and the U.K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.