9 unchanged sentences
The other members of the Board attend these quarterly reports and presentations to the Audit Committee by members of management.
−Removed: The Company has protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported promptly to the Board and Audit Committee, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: The Company has protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated to management and, where appropriate, reported promptly to the Board and Audit Committee, as well as ongoing updates regarding any such incident until it has been addressed.
At the management level, the CISO, who has extensive cybersecurity knowledge and skills gained from over 16 years of work experience at the Company and elsewhere , heads the cross-functional team responsible for implementing, monitoring, and maintaining cybersecurity and data protection practices across the business and reports directly to the CIO, who reports directly to the Chief Executive Officer.
The CISO receives reports on cybersecurity threats from a number of experienced information security team members, each of whom is responsible for various parts of the business on an ongoing basis and, in conjunction with management, regularly reviews risk management measures implemented by the Company to identify and mitigate data protection and cybersecurity risks.
−Removed: The CISO works closely with the legal team to oversee compliance with legal, regulatory and contractual security requirements.
+Added: The CISO collaborates closely with the legal team to oversee compliance with legal, regulatory and contractual security requirements.
Internal Cybersecurity Team
6 unchanged sentences
The Company maintains a Privacy Policy that describes the personal information that it collects about its customers, including how the Company may use such information and when it shares such information with third parties.
−Removed: The Company conducts annual cyber-risk mitigation exercises including awareness outreach, annual IT Security Awareness training, monthly phishing tests, and a variety of ongoing vulnerability scans.
−Removed: Over the past two years, the Company has implemented multiple new security tools designed to provide visibility and controls allowing the cybersecurity team to safeguard data against theft or loss.
+Added: The Company conducts annual cyber-risk mitigation exercises including awareness outreach, annual IT Security Awareness training, periodic phishing simulations, and a variety of ongoing vulnerability scans.
+Added: Over the past two years, the Company has
+Added: implemented multiple new security tools designed to provide visibility and controls allowing the cybersecurity team to safeguard data against theft or loss.
The Company maintains various role-based access controls to safeguard data and systems.
1 unchanged sentence
Access is periodically reviewed and updated.
−Removed: In addition, an external consultant in conjunction with the Company conducted a cybersecurity gap assessment in November 2023 to review and confirm that the Company has appropriate measures in place to assess, identify and manage cybersecurity risks, and the Company is implementing the recommendations made as a result of the gap assessment.
−Removed: The cybersecurity, legal, and Executive Leadership teams also participated in a data security incident tabletop exercise in December 2023 to simulate responses to a ransomware attack and use the findings to improve the Company’s processes and technologies.
+Added: The Company measures its security posture through several third-party score-based cybersecurity tools.
+Added: Scores from these tools are reviewed weekly and measure the Company's posture regarding securing applications, infrastructure, data and other assets from theft or loss, both internally and externally.
+Added: Thresholds are in place for escalation to management.
The Company maintains cybersecurity insurance coverage to help defray any financial losses suffered by the Company in the event of an information security breach.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.