7 unchanged sentences
The Audit Committee regularly reviews the measures implemented by the Company to identify and mitigate data protection and cybersecurity risks.
−Removed: As part of such reviews, the Audit Committee receives quarterly reports and presentations from members of the Company’s team responsible for overseeing the Company’s cybersecurity risk management, including the Chief Information Security Officer (CISO) , Chief Information Officer (CIO), and members of the legal team, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to the Company’s peers and third parties.
+Added: As part of such reviews, the Audit Committee receives quarterly reports and presentations from members of the Company’s team responsible for overseeing the Company’s cybersecurity risk management, including the Chief Information Security Officer (CISO) , Chief Information Officer (CIO), and members of the legal team, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and
+Added: information security considerations arising with respect to the Company’s peers and third parties.
The other members of the Board attend these quarterly reports and presentations to the Audit Committee by members of management.
6 unchanged sentences
The CISO is supported by experienced information security team members, each of whom is supported by a team of trained cybersecurity professionals.
−Removed: The individuals who report directly to the CISO include the Director of Cyber Security, who oversees the cybersecurity engineers, security operations center, and identity & access management team, and the Privacy and Compliance Manager, who oversees the global privacy and compliance analysts.
+Added: The Director of Compliance, Security and Consumer Data, who oversees the global privacy and compliance analysts, reports directly to the CISO.
+Added: The CISO is also supported by the Director of Cyber Security, who oversees the cybersecurity engineers, security operations center, and identity & access management team, and reports to the Company's Chief Legal Officer and Corporate Secretary.
In addition to internal cybersecurity capabilities, the Company also at times engages consultants or specialists to assist with assessing, identifying, and managing cybersecurity risks.
3 unchanged sentences
The Company conducts annual cyber-risk mitigation exercises including awareness outreach, annual IT Security Awareness training, periodic phishing simulations, and a variety of ongoing vulnerability scans.
−Removed: Over the past two years, the Company has
−Removed: implemented multiple new security tools designed to provide visibility and controls allowing the cybersecurity team to safeguard data against theft or loss.
+Added: Over the past four years, the Company has implemented multiple new security tools designed to provide visibility and controls allowing the cybersecurity team to safeguard data against theft or loss.
The Company maintains various role-based access controls to safeguard data and systems.
16 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.