2 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: Our cybersecurity risk management is based on
−Removed: recognized cybersecurity industry frameworks and standards, including those of the National Institute of Standards and Technology, the
−Removed: Center for Internet Security Controls, and the International Organization for Standardization.
−Removed: This does not imply that we meet any particular
−Removed: technical standards, specifications, or requirements, only that we use the aforementioned frameworks and standards as a guide to help
−Removed: us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: We use these frameworks, together with information collected
−Removed: from internal assessments, to develop policies for the use of our information assets (for example, TI business information and information
−Removed: resources such as mobile phones, computers and workstations), access to specific intellectual property or technologies, and protection
−Removed: of personal information.
−Removed: We protect these information assets through industry-standard techniques, by strong Identity and Access Management
−Removed: framework, such as Role Based Access Control, principle of Least Privilege, multi factor authentication as obligatory second factor to
+Added: cybersecurity framework (which includes management of related risks), is based on recognized cybersecurity industry frameworks and standards,
+Added: including those of the National Institute of Standards and Technology, the Center for Internet Security Controls, and the International
+Added: Organization for Standardization.
+Added: We do not certify that we meet any particular technical standards, specifications, or requirements,
+Added: but we use the aforementioned frameworks and standards as a guide to help us identify, assess, and manage cybersecurity risks relevant
+Added: to our business.
+Added: We use these frameworks, together with information collected from internal assessments, to develop policies for the
+Added: use of our information assets (e.g., IT business information and information resources such as mobile phones, computers and workstations),
+Added: access to specific intellectual property or technologies, and protection of personal information.
+Added: We protect these information assets
+Added: through industry-standard techniques, by strong Identity and Access Management framework, such as Role Based Access Control, Attribute
+Added: Based Access Control, principle of Least Privilege, Need-to-Know access and multi factor authentication as obligatory second factor to
our core resources.
−Removed: We also thoroughly improved our endpoint protection by deploying an endpoint detection and response tool.
−Removed: mission is to defend our endpoints and systems against the newest malware, rootkits, spywares and ransomware.
−Removed: We also work with internal
−Removed: stakeholders across the company to integrate foundational cybersecurity principles throughout our organization’s operations, including
−Removed: the employment of multiple layers of cybersecurity defenses, restricted access based on business needs, and integrity of our business
−Removed: Throughout the year, we also regularly train our employees on cybersecurity awareness on social engineering attacks, confidential
−Removed: information protection, emerging threats and simulated phishing attacks to improve self-awareness of our employees.
−Removed: We have standing engagements with incident response
−Removed: experts and external counsel through our cyber insurance.
−Removed: We frequently collaborate with industry experts and cybersecurity practitioners
−Removed: at other companies to exchange intelligence about potential cybersecurity threats, best practices and trends.
−Removed: We also have our own incident
−Removed: response team who is engaged in dealing with security events triggered by our Security Information and Event Management (SIEM) system.
−Removed: Our cybersecurity risk management extends to
−Removed: risks associated with our use of third-party service providers.
−Removed: For instance, we conduct risk and compliance assessments of third-party
−Removed: service providers by checking on a permanent basis every new vendor that is going to cooperate with the Company.
−Removed: The aim is to verify
−Removed: if vendors due diligence and risks associated with it are within our risk tolerance set by management.
−Removed: Our cybersecurity risk management is an important
−Removed: part of our comprehensive business continuity program and enterprise risk management.
−Removed: Our global information security team periodically
−Removed: engages with a cross-functional group of subject matter experts and leaders to assess and refine our cybersecurity risk posture and preparedness.
−Removed: For example, we regularly evaluate and update contingency strategies for our business in the event that a portion of our information
−Removed: resources were to be unavailable due to a cybersecurity incident.
−Removed: We practice our response to potential cybersecurity incidents through
−Removed: regular tabletop exercises, threat hunting and red team exercises.
−Removed: We also verify the resilience of our security
−Removed: posture by regularly conducting vulnerability management programs, where we test on potential vulnerabilities of our systems, endpoints
−Removed: connected to the company perimeter and remediate it to stay free from any software or configuration holes.
+Added: We also enhance our endpoint protection by deploying an endpoint detection and response tool.
+Added: Its core mission is
+Added: to defend our endpoints and systems against new malware, rootkits, spywares and ransomware.
+Added: We also work with internal stakeholders across
+Added: the Company to integrate foundational cybersecurity principles throughout our operations, including the employment of multiple layers
+Added: of cybersecurity defenses, restricted access based on business needs, and integrity of our business information.
+Added: We routinely train our
+Added: employees on cybersecurity awareness on social engineering attacks, confidential information protection, emerging threats and simulated
+Added: phishing attacks to improve self-awareness of our employees.
+Added: have standing engagements with incident response experts and external counsel, including through our cyber insurance.
+Added: We frequently collaborate
+Added: with industry experts and cybersecurity practitioners at other companies to exchange intelligence about potential cybersecurity threats,
+Added: best practices and trends.
+Added: We continuously monitor and collect insights on the latest vulnerabilities and attack patterns (TTPs) released
+Added: by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST).
+Added: annual “Threat Landscape” report published by the European Union Agency for Cybersecurity (ENISA) each October serves as
+Added: a key strategic intelligence source supporting the hardening and protection of our infrastructure.
+Added: This report offers a comprehensive
+Added: perspective on prevalent attack types, mapped across threat vectors and industry domains, accompanied by actionable defense strategies
+Added: that support effective risk reduction to levels aligned with our organizational tolerance.
+Added: It allows for the deployment of tailored security
+Added: measures, enhancing Zedge’s ability to withstand evolving cyber risks.
+Added: also have our own incident response team who is engaged in dealing with security events triggered by our Security Information and Event
+Added: Management (SIEM) system.
+Added: Continuous monitoring of our infrastructure — from endpoint devices to virtual clusters — helps
+Added: detect potential interception of internal communications, preventing the leakage of business-critical data.
+Added: cybersecurity risk management extends to risks associated with our use of third-party service providers.
+Added: For instance, we conduct risk
+Added: and compliance assessments of third-party service providers by checking on a permanent basis every new vendor that is going to cooperate
+Added: with the Company.
+Added: The aim is to verify if vendors due diligence and risks associated with it are within our risk tolerance set by management.
+Added: cybersecurity risk management is an important part of our comprehensive business continuity program and enterprise risk management.
+Added: global information security team periodically engages with a cross-functional group of subject matter experts and leaders to assess and
+Added: refine our cybersecurity risk posture and preparedness.
+Added: For example, we regularly evaluate and update contingency strategies for our
+Added: business in the event that a portion of our information resources were to be unavailable due to a cybersecurity incident.
+Added: our response to potential cybersecurity incidents through regular tabletop exercises, threat hunting and red team exercises.
+Added: vulnerability management program involves regular scanning and testing of systems, endpoints, virtual environments, and cloud-based assets
+Added: to identify potential software flaws, misconfigurations, or exposure points.
+Added: Once vulnerabilities are detected, we prioritize remediation
+Added: based on risk impact and business criticality, ensuring that all gaps are addressed in a timely and effective manner.
+Added: This proactive
+Added: approach enables us to maintain a hardened infrastructure, reduce attack surface, and align with industry best practices and regulatory
+Added: expectations.
+Added: part of our secure development lifecycle (SDLC), we conduct both automated and manual code reviews to ensure that the applications we
+Added: deliver to our users are resilient against exploitation and designed to prevent data leakage.
+Added: By embedding security controls throughout
+Added: the development process — from design to deployment — we uphold confidentiality, integrity, and reliability.
+Added: This approach
+Added: not only protects sensitive user data, but also reinforces trust in our platform and supports long-term compliance with regulatory frameworks.
+Added: response to the growing use of AI, by bad actors, we adapt our internal policies, procedures, and control mechanisms to address AI-driven
+Added: threats, including:
+Added: phishing campaigns and deepfake content used for impersonation or fraud.
+Added: code generation via large language models.
+Added: ● Adversarial
+Added: attacks that manipulate input data to bypass security algorithms.
+Added: ● AI-assisted
+Added: vulnerability scanning and exploitation of system weaknesses.
+Added: multi-layered defense strategy includes:
+Added: monitoring and anomaly detection powered by machine learning to identify AI-driven attack
+Added: SDLC with static and dynamic code analysis to detect AI-generated vulnerabilities.
+Added: training on AI-related risks, such as synthetic media, prompt injection, and suspicious automation.
+Added: ● Third-party
+Added: risk assessments that evaluate the AI capabilities of vendors and partners to prevent external
+Added: response playbooks tailored to AI-specific scenarios, such as automated botnet coordination
+Added: or synthetic identity fraud.
+Added: practices ensure our organization remains agile, secure, and prepared for the evolving AI-driven threat landscape.
Governance of Cybersecurity Risk Management
−Removed: The board of directors, as a whole, has oversight
−Removed: responsibility for our strategic and operational risks and sets associated risk parameters and tolerance levels.
+Added: board of directors, as a whole, has oversight responsibility for our strategic and operational risks and sets associated risk parameters
+Added: and tolerance levels.
+Added: The audit committee assists the board of directors with this responsibility by reviewing and discussing the defined
+Added: risks, its assessment and proposed mitigation strategies, including cybersecurity risks, with members of management.
The audit committee,
−Removed: assists the board of directors with this responsibility by reviewing and discussing the defined risks, its assessment and proposed mitigation
−Removed: strategies, including cybersecurity risks, with members of management.
−Removed: The audit committee, in turn, periodically reports on its review
−Removed: with the board of directors.
−Removed: Management is responsible for day-to-day assessment and management
−Removed: of cybersecurity risks and reports regularly to the audit committee.
−Removed: Zedge’s Cybersecurity risk governance has several components
−Removed: that can help our organization understand and implement cybersecurity governance practices achieve long-term cybersecurity goals beyond
−Removed: the day-to-day information security tasks, align with legal and regulatory compliance, and the direction of the Company through:
−Removed: ● Developing a mature cybersecurity culture which ensures that
−Removed: all employees understand they are stakeholders in cybersecurity.
−Removed: Employees not only engage
−Removed: with cybersecurity controls but must be proactive in risk mitigation and remediation.
−Removed: ● Cyber risk assessments which identify cybersecurity business
−Removed: risks and the Company’s cybersecurity gaps and vulnerabilities.
−Removed: Using agreed-upon key
−Removed: performance indicators (KPIs), stakeholders can measure the Company’s cybersecurity
−Removed: capabilities clearly and objectively.
−Removed: This facilitates our ability to audit the effectiveness
−Removed: of future vulnerabilities and remediation activities.
−Removed: ● An Accountability Framework which measures performance across
−Removed: departments and systems and ensures that those identified as responsible for meeting objectives
−Removed: are aware of the results and work with the cyber risk governance team leader to achieve and
−Removed: enhance them.
−Removed: With consistent feedback and the ability to reference established metrics,
−Removed: we can successfully monitor, review, and enforce cyber risk governance plans.
−Removed: In turn, through
−Removed: these processes, we improve our framework, remediate serious issues, and update organizational
−Removed: cyber risk governance roadmaps accordingly.
+Added: in turn, periodically reports on its review with the board of directors.
+Added: is responsible for day-to-day assessment and management of cybersecurity risks and reports regularly to the audit committee.
+Added: Cybersecurity risk governance has several components that can help our organization understand and implement cybersecurity governance
+Added: practices achieve long-term cybersecurity goals beyond the day-to-day information security tasks, align with legal and regulatory compliance,
+Added: and the direction of the Company through:
+Added: a mature cybersecurity culture which ensures that all employees understand they are stakeholders in cybersecurity.
+Added: Employees not
+Added: only engage with cybersecurity controls but must be proactive in risk mitigation and remediation.
+Added: risk assessments which identify cybersecurity business risks and the Company’s cybersecurity gaps and vulnerabilities.
+Added: agreed-upon key performance indicators (KPIs), stakeholders can measure the Company’s cybersecurity capabilities clearly and
+Added: This facilitates our ability to audit the effectiveness of future vulnerabilities and remediation activities.
+Added: Accountability Framework which measures performance across departments and systems and ensures that those identified as responsible for
+Added: meeting objectives are aware of the results and work with the cyber risk governance team leader to achieve and enhance them.
+Added: With consistent
+Added: feedback and the ability to reference established metrics, we can successfully monitor, review, and enforce cyber risk governance plans.
+Added: In turn, through these processes, we improve our framework, remediate serious issues, and update organizational cyber risk governance
+Added: roadmaps accordingly.
+Added: ● Embedding cybersecurity within the broader enterprise risk
+Added: management (ERM) strategies to evaluate cyber risks alongside financial, operational, and reputational risks, enabling executive leadership
+Added: to make informed decisions.
+Added: ● Leveraging external threat intelligence and collaborating
+Added: with industry peers, regulatory bodies, and national cybersecurity agencies to adapt to emerging threats.
+Added: ● Embedding security into software development through deployment,
+Added: with regular code reviews, SDLC checkpoints, and secure architecture principles.
+Added: ● Reviewing governance practices, incorporating lessons learned
+Added: from incidents, audits, and tabletop exercises to refine policies, controls, and strategic priorities.
+Added: ● Providing transparent cyber risk metrics and governance outcomes
+Added: to the Board of Directors, ensuring alignment with strategic priorities and positioning cybersecurity as a business enabler.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.