5 unchanged sentences
We routinely assess material risks from cybersecurity threats and regularly assess and update our cybersecurity risk management program in response to emerging trends and changes in our operations.
−Removed: Our risk management program includes, among other elements:
+Added: Our cybersecurity risk management program includes, among other elements:
Identification:
−Removed: We aim to proactively identify sources of risk, areas of impact, and relevant events that could give rise to cybersecurity risks, such as changes to our infrastructure, service providers, or personnel.
−Removed: We conduct periodic risk assessments to identify cybersecurity threats.
+Added: We aim to proactively identify sources of risk, areas of impact, and relevant events that could give rise to cybersecurity risks, such as changes to our infrastructure, service providers, personnel, or operational environment.
+Added: We conduct ongoing and continuous risk assessments to identify cybersecurity threats.
We also conduct likelihood and impact assessments with the goal of identifying reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.
−Removed: Following our risk assessments, we design and implement reasonable safeguards to address any identified gaps in our existing processes and procedures.
−Removed: Our employees participate in cybersecurity training and awareness upon hire and at least annually thereafter.
+Added: Following our risk assessments, management designs and implements reasonable risk response and reduction initiatives to address any identified security risks, including taking steps to address gaps in our existing controls, processes, and procedures.
+Added: Our employees participate in cybersecurity training and awareness upon hire and at least annually thereafter as part of management's ongoing risk mitigation efforts.
+Added: These training and awareness programs are continuously updated with learnings from our risk management practices and the evolution of the threat landscape.
We engage third parties, including consultants and auditors, to evaluate the effectiveness of our risk management program, control environment, and cybersecurity practices through security audits, penetration testing, and other engagements.
2 unchanged sentences
We believe these processes enable us to evaluate a third-party service provider’s security posture, identify risks that may arise out of our use of the third-party’s service, and make decisions regarding acceptable levels of risk and risk mitigation.
−Removed: For additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this annual report on Form 10-K.
+Added: For additional information regarding whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents and events, have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this Annual Report on Form 10-K.
Board and Management’s Role in Data Privacy and Cybersecurity Oversight
4 unchanged sentences
The full board of directors receives an annual information security update by our Chief Information Security Officer (“CISO”) and an annual privacy update, which covers, among other matters, our privacy and cybersecurity programs and risks.
−Removed: Our audit and risk committee receives updates, at least quarterly, on significant data privacy and security risks, including any significant incidents, relevant industry developments, threat vectors and significant risks identified in periodic penetration tests or vulnerability scans.
−Removed: The updates also include significant legal and legislative developments concerning data privacy and security, our approach to complying with applicable law, and significant engagement with regulators concerning data privacy and cybersecurity.
+Added: Our audit and risk committee receives updates, at least quarterly, on significant data privacy and security risks, including any significant incidents, relevant industry developments, threat vectors and significant risks identified in risk assessments, periodic penetration tests or vulnerability scans.
+Added: The board of directors also receives updates that include significant legal and legislative developments concerning data privacy and security, our approach to complying with applicable law, and significant engagement with regulators concerning data privacy and cybersecurity, including maturity of our cybersecurity common controls.
Our audit and risk committee provides regular updates to the board of directors on such reports.
2 unchanged sentences
Additionally, we have an incident response team and an incident response plan that outlines the roles and responsibilities of key personnel, including representatives from information security, compliance, and counsel, that are involved in responding to, remediating and escalating such incidents to the CISO, as appropriate.
−Removed: Our CISO reports directly to our Technology + Engineering Lead and indirectly to our audit and risk committee.
+Added: Our CISO reports directly to our Engineering Lead and indirectly to our Board's audit and risk Committee.
Our CISO provides updates on significant or potentially significant threats and incidents to our Block Head and leadership team, in addition to the audit and risk committee and our board of directors as appropriate and in accordance with the processes detailed in the prior paragraph.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.