9 unchanged sentences
identify, escalate, investigate, resolve and recover from identified vulnerabilities and security incidents in a timely manner, including, but not limited to, internal reporting, monitoring and detection tools and a vulnerability identification program.
−Removed: Recognizing the complexity and evolving nature of cybersecurity threats, Wayfair engages with a range of external experts, including cybersecurity assessors, consultants and auditors in evaluating and testing our risk management systems.
−Removed: Working with these external experts enables us to leverage specialized knowledge and insights, with a goal of ensuring our cybersecurity strategies and processes remain at the forefront of industry best practices.
−Removed: Our collaboration with these third parties includes regular audits, threat assessments and consultation on security enhancements .
+Added: Recognizing the complexity and evolving nature of cybersecurity threats, Wayfair engages with a range of experts, including external cybersecurity assessors and consultants and internal auditors in evaluating and testing our risk management systems.
+Added: Working with these experts enables us to leverage specialized knowledge and insights, with a goal of ensuring our cybersecurity strategies and processes remain at the forefront of industry best practices.
+Added: Our collaboration with these experts includes regular audits, threat assessments and consultation on security enhancements .
In order to mitigate data or security incidents that may originate from third party vendors or suppliers, we conduct both privacy and security assessments to properly identify, prioritize, assess and remediate any third party risks, and require security and privacy addenda to our contracts where applicable.
4 unchanged sentences
Our Board has delegated responsibility for oversight of cybersecurity risks to the Audit Committee.
−Removed: The Audit Committee is composed of board members with diverse expertise including risk management, technology and finance, equipping them to oversee cybersecurity risks effectively.
+Added: The Audit Committee is composed of board members with diverse expertise including risk management, technology and finance, which we believe equips them to oversee cybersecurity risks effectively.
Our Audit Committee is charged with reviewing and discussing our policies with respect to risk assessment and risk management, which includes overseeing our major financial, privacy, security, cybersecurity and technology risk exposures and the steps our management has taken to monitor and control these exposures.
−Removed: At the management level, our Head of Cybersecurity and the cybersecurity teams are primarily responsible for identifying, assessing, monitoring and managing our cybersecurity.
−Removed: Our current Head of Cybersecurity has 20 years of industry experience, including serving as an enterprise Chief Information Security Officer for many years and having extensive experience in developing and leading risk management programs.
+Added: At the management level, our Head of Cybersecurity and cybersecurity teams are primarily responsible for identifying, assessing, monitoring and managing our cybersecurity.
+Added: Our current Head of Cybersecurity has over 20 years of industry experience, including serving as an enterprise Chief Information Security Officer for many years and having extensive experience in developing and leading risk management programs.
Additionally, our Head of Cybersecurity holds multiple industry standard security certifications, including CISSP (Certified Information Systems Security Professional) and CISM (Certified Information Security Manager).
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.