2 unchanged sentences
Risk Management and Strategy
−Removed: The Company maintains comprehensive policies, procedures, and controls to protect the Company’s information systems and related data from cybersecurity threats and incidents.
−Removed: The Company’s cybersecurity risk management program is aligned with the International Standards Organization (ISO 27001:2022) and mapped to National Institute of Standards
−Removed: Special Publication 800-53 Revision 5 (NIST 800-53).
+Added: Cybersecurity risk management is a critical component of the Company’s overall risk management.
+Added: The Company proactively addresses cybersecurity risk through a comprehensive cybersecurity program to identify, protect, respond to, and manage any reasonably foreseeable cybersecurity risks, threats and incidents.
+Added: The Company’s cybersecurity risk management program is aligned with the International Standards Organization (ISO 27001:2022) and mapped to National Institute of Standards Special Publication 800-53 Revision 5 (NIST 800-53).
The Company’s cybersecurity program is integrated into the Company’s overarching enterprise risk management program.
−Removed: The Company’s Chief Information Security Officer (CISO) is responsible for managing the Company’s cybersecurity program and reporting on cybersecurity matters to management, the Cyber Governance Committee, and the Company’s board of directors.
+Added: The Company’s Chief Information Security Officer (CISO) is responsible for developing and managing the Company’s cybersecurity program and reporting on cybersecurity matters to management, the Audit Committee and the Company’s Board of Directors.
The CISO has over twenty years of cybersecurity and technology experience, originating with cryptography and security experience as a military officer and progressing through senior management roles at prominent global audit and technology consulting corporations.
−Removed: The CISO leads the Company’s cybersecurity and information technology compliance department which is staffed with technical and compliance personnel with the appropriate experience and certifications required to accomplish the department’s mandates.
−Removed: The CISO is supervised by the Company’s Chief Technology Officer.
−Removed: The Company’s maintains a Cyber Governance Committee, which meets quarterly, and interfaces with other functional areas within the Company, including, but not limited to, legal, internal audit, accounting, risk management, human resources, as well as external third-party partners.
−Removed: The CISO serves as the chair of the committee, which has been tasked with providing governance and oversight of the Information Security and Management System and to provide governance during major cybersecurity incidents.
+Added: The CISO is supervised by the Company’s Chief Information Officer.
+Added: The Company has established and maintains a cross-functional Cyber Governance Committee that is responsible for helping the CISO prioritize and manage evolving cyber risks and reports to the Company’s Chief Information Officer.
+Added: The Cyber Governance Committee, which oversees the Company’s governance and oversight of information security, meets quarterly and interfaces with other functional areas within the Company, including, but not limited to, legal, internal audit, accounting, risk management, human resources, as well as external third-party partners.
+Added: The CISO serves as the chair of the Cyber Governance Committee.
+Added: The CISO also provides response and oversight during any significant cybersecurity incidents and informs the Cyber Governance Committee of all cybersecurity incidents that have been identified by the Company to date.
The Company engages third parties to assist with the monitoring components of the security infrastructure that we have deployed.
−Removed: As required, the Company engages consultants and third parties to assist with penetration testing, tabletop incident response exercises, or other activities necessary to comply with various standards and certifications that we require to operate as a business.
−Removed: The Company provides regular awareness training to our employees and consultants using our collaboration platforms, including periodic phishing tests, to help identify, avoid, and mitigate cybersecurity threats, as well as targeted security training for key departments dealing with sensitive data types.
−Removed: Where needed, the Company seeks appropriate certifications from vendors and contractually requires adherence to data privacy and security requirements from its vendors.
+Added: As required, the Company engages consultants and third parties to assist with penetration testing, tabletop incident response exercises, or other activities necessary to comply with various standards and certifications that are necessary for the Company’s business operations.
+Added: The Company provides regular awareness training to its employees and consultants using its collaboration platforms to help identify, avoid, and mitigate cybersecurity threats, as well as targeted security training for key departments that routinely process, store or handle sensitive data types.
Where service providers are materially utilized, the company obtains SOC1 or SOC2 reports and complies with complementary user entity controls to keep those attestations valid.
+Added: Where needed, the Company requires appropriate certifications and contractually requires adherence to data privacy and security requirements from its vendors.
The Company operates technologies that are exposed to the internet, and although robust cybersecurity programs, technologies, and safeguards are deployed to help protect the Company’s operations and assets, the Company, by nature, is exposed to material cybersecurity attacks that are either generally targeted at companies that operate on the internet, or the Company, by nature, remains exposed to attacks that are specifically directed at the Company’s technology systems exposed to the internet.
−Removed: The Company’s Board of Directors provide ultimate oversight of the Company’s cybersecurity risk management program.
−Removed: As reflected in the Audit Committee’s charter, the Board of Directors has specifically delegated responsibility for oversight of cybersecurity matters to the Audit Committee.
−Removed: The CISO presents quarterly updates to the Audit Committee on the Company’s cyber risks and threats, status of projects to strengthen the Company’s information security systems, and emerging threats.
−Removed: During the normal course of business, the Company has experienced and expects to continue to experience cyber-based attacks and other attempts to compromise our information systems, although none, to our knowledge, has had a material adverse effect on our business, financial condition or results of operations.
−Removed: The Company does not believe that any risks from cybersecurity threats, nor any previous cybersecurity incidents, have materially affected the Company.
+Added: The Company’s Board of Directors recognizes the importance of cybersecurity and has ultimate oversight of the Company’s cybersecurity risk management program.
+Added: As reflected in the Audit Committee’s charter, the Audit Committee of the Company’s Board of Directors has been delegated certain cybersecurity oversight responsibility and, among other things, monitors the Company’s cybersecurity risk profile, receives periodic updates from management on all matters related to cybersecurity and reports to the full Board of Directors.
+Added: The CISO presents quarterly updates to the Audit
+Added: Committee on the Company’s cyber risks and threats, status of projects to strengthen the Company’s information security systems, and emerging threats.
+Added: During the normal course of business, the Company has experienced and expects to continue to experience cyber-based attacks and other attempts to compromise its information systems.
+Added: Based on the information that the Company had as of the end of the fiscal year covered by this Annual Report on Form 10-K, the Company does not believe that it has experienced any cybersecurity incidents that have materially affected the Company.
However, the sophistication of cyber threats continues to increase, and the preventative actions the Company has taken and continues to take to reduce the risk of cyber incidents and protect its systems and information may not successfully protect against all cyber incidents.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.