1 unchanged sentence
Cybersecurity.
−Removed: Risk management and strategy
−Removed: We understand the importance of preventing, assessing, identifying, and managing material risks associated with cybersecurity threats.
−Removed: Processes to manage risks from cybersecurity threats have been incorporated as a part of our overall risk assessment process.
−Removed: Our cybersecurity risks include theft of business data, fraud or extortion, lack of access to our information systems, harm to employees, harm to business partners, violation of privacy laws, potential reputational damage, and litigation or other legal risk if a cybersecurity incident were to occur.
−Removed: It is difficult to assign a monetary materiality assessment to these risks or to the impact if we were to sustain a breach of our systems.
+Added: management and strategy
+Added: understand the importance of preventing, assessing, identifying, and managing material risks associated with cybersecurity threats.
+Added: to manage risks from cybersecurity threats have been incorporated as a part of our overall risk assessment process.
+Added: Our cybersecurity
+Added: risks include theft of business data, fraud or extortion, lack of access to our information systems, harm to employees, harm to business
+Added: partners, violation of privacy laws, potential reputational damage, and litigation or other legal risk if a cybersecurity incident were
+Added: It is difficult to assign a monetary materiality assessment to these risks or to the impact if we were to sustain a breach
+Added: of our systems.
Our approach is based on the premise that any cybersecurity incident could result in material harm to our company.
−Removed: We utilize a seasoned and mature artificial intelligence-based security system that learns and monitors the actions of individuals that have access to our networks and systems, including location of access (notably from international locations), email, and SAAS platforms that we don’t host.
−Removed: The system not only protects based off of the specific rules implemented, it also takes action based on user activity (including remote access to our systems by our employees) that is outside their normal behavior pattern.
−Removed: Additionally, our employees go through cybersecurity awareness training as part of their onboarding procedures.
−Removed: If a threat is detected, our system automatically notifies our internal information systems management (“ISM”) team of all activities and ranks those activities based on their level of threat to the system and/or deviation of behavior from normal.
−Removed: Severe threats notify the ISM team via text message, regardless of hours of operation.
−Removed: In addition to the notification, the system will automatically take action to secure the system, up to and including blocking user accounts and access.
−Removed: The ISM team will then review the notification, assess the action that was taken against the actual threat, and then clear the condition or take further action.
−Removed: To mitigate risk, we periodically evaluate and assess the threat landscape and our security controls, through assessments, regular network and endpoint monitoring.
−Removed: We also have processes to oversee and identify material cybersecurity risks associated with our use of third-party service providers, including performing diligence on certain third parties that have access to our systems, data or facilities that store such systems or data, continually monitoring cybersecurity threat risks identified through such diligence
−Removed: Under our framework, cybersecurity
−Removed: issues, including those involving vulnerabilities introduced by our use of third-party software, are analyzed by subject matter experts
−Removed: for potential financial, operational, and reputational risks, based on, among other factors, the nature of the matter and breadth of impact.
−Removed: As of the date of this Report, there
−Removed: have been no cybersecurity threats that have materially affected or are reasonably likely to materially affect our business, operations,
−Removed: or financial condition.
+Added: utilize a seasoned and mature artificial intelligence-based security system that learns and monitors the actions of individuals that
+Added: have access to our networks and systems, including location of access (notably from international locations), email, and SAAS platforms
+Added: that we do not host.
+Added: The system not only protects based off of the specific rules implemented, it also takes action based on user activity
+Added: (including remote access to our systems by our employees) that is outside their normal behavior pattern.
+Added: Additionally, our employees
+Added: go through cybersecurity awareness training as part of their onboarding procedures.
+Added: a threat is detected, our system automatically notifies our internal information systems management (“ISM”) team of all activities
+Added: and ranks those activities based on their level of threat to the system and/or deviation of behavior from normal.
+Added: Severe threats notify
+Added: the ISM team via text message, regardless of hours of operation.
+Added: In addition to the notification, the system will automatically take
+Added: action to secure the system, up to and including blocking user accounts and access.
+Added: The ISM team will then review the notification, assess
+Added: the action that was taken against the actual threat, and then clear the condition or take further action.
+Added: mitigate risk, we periodically evaluate and assess the threat landscape and our security controls, through assessments, regular network
+Added: and endpoint monitoring.
+Added: We also have processes to oversee and identify material cybersecurity risks associated with our use of third-party
+Added: service providers, including performing diligence on certain third parties that have access to our systems, data or facilities that store
+Added: such systems or data, continually monitoring cybersecurity threat risks identified through such diligence
+Added: our framework, cybersecurity issues, including those involving vulnerabilities introduced by our use of third-party software, are analyzed
+Added: by subject matter experts for potential financial, operational, and reputational risks, based on, among other factors, the nature of
+Added: the matter and breadth of impact.
+Added: of the date of this Report, there have been no cybersecurity threats that have materially affected or are reasonably likely to materially
+Added: affect our business, operations, or financial condition.
determined to present potential material impacts to our financial results, operations, and/or reputation would immediately be reported
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.