1 unchanged sentence
Cybersecurity
−Removed: We recognize the critical importance of maintaining the safety and security of our systems and data and have a holistic process for assessing, identifying, and managing material risks from cybersecurity threats.
+Added: We recognize the critical importance of maintaining the safety and security of our systems and data and have a holistic process designed to assess, identify, and manage material risks from cybersecurity threats.
This process is supported by both management and our Board of Directors.
−Removed: To prevent, detect, mitigate, and remediate information security threats, including a cybersecurity incident and/or threat, we maintain a cyber risk management process managed by our Senior Vice President, Operations (“SVP, Operations”) who reports to our CEO.
−Removed: The SVP, Operations works with the Vice President, Deputy General Counsel (“Legal”) on cybersecurity strategy, policy, training, standards, architecture, and processes.
+Added: To prevent, detect, mitigate, and remediate information security threats, including a cybersecurity incident and/or threat, we maintain a cyber risk management process managed by our Senior Vice President, Operations (“SVP, Operations”) who reports to our CEO and has seven years of experience overseeing information technology processes and procedures, including cybersecurity matters.
+Added: The SVP, Operations works with the Company’s Legal team on cybersecurity strategy, policy, training, standards, architecture, and processes.
We have invested, and expect to continue to invest, in resources for the protection and safeguarding of our information technology systems, including, but not limited to, networks, applications, and outsourced technology services in connection with the operation of our business.
−Removed: These resources are designed to detect and respond to cyber incidents that may result in unauthorized access to, ransomware, damages, or destruction of, our information and systems.
+Added: We have implemented cybersecurity systems and controls based on industry best practices and the U.S.
+Added: National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”).
+Added: This does not imply that we meet any particular technical standards, specifications or requirements, only that we use such standards as a guide to help us identify, assess and manage cybersecurity risks relevant to our business.
+Added: These resources are designed to detect and respond to cyber incidents that may result in unauthorized access to, ransomware, damages, or destruction of, our information systems.
Risk Management and Strategy
−Removed: Cybersecurity risk is a direct responsibility of management and the Company’s information technology (“IT”) team.
−Removed: Working cross-functionally with Legal, our SVP, Operations oversees the IT team that regularly monitors and assesses cybersecurity risks, implements measures designed to mitigate such risks and their associated effects on the Company and personal data collected, stored, and processed in our systems, and manages our information security training and cybersecurity awareness program.
+Added: Cybersecurity risk is a direct responsibility of management and the Company’s information technology (“IT”) team, including our Director, IT who has over 15 years of experience building, implementing, and managing information systems, developing cybersecurity programs, and deploying risk mitigation strategies for such systems.
+Added: Working cross-functionally with our Legal team, our SVP, Operations oversees the IT team that regularly monitors and assesses cybersecurity risks, implements measures designed to mitigate such risks and their associated effects on the Company and personal data collected, stored, and processed in our systems, and manages our information security training and cybersecurity awareness program.
We consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework.
3 unchanged sentences
From time to time, we engage third-party consultants or other advisors to assist in assessing, identifying, and/or managing cybersecurity threats.
−Removed: We also periodically use our internal audit partner to conduct additional reviews and assessments.
+Added: We also periodically use third-parties to conduct additional reviews and assessments.
• Insider Threats – We maintain organizational controls such as limited access, and access removal for terminated employees, designed to minimize insider threats, and address potential risks from within our Company.
13 unchanged sentences
Management reports to the NERM Committee and/or the Board of Directors in between meetings as appropriate regarding any significant cyber events.
−Removed: To date we have not identified any cybersecurity threat or incident that has materially affected the Company or our financial position, results of operations and/or cash flows, but we face certain ongoing cybersecurity risk threats that, if realized, are reasonably likely to materially affect us.
+Added: Since the beginning of the last fiscal year, we have not identified any cybersecurity threat or incident that has materially affected the Company or our financial position, results of operations and/or cash flows, but we face certain ongoing cybersecurity risk threats that, if realized, are reasonably likely to materially affect us.
We continue to invest in the cybersecurity and resiliency of our networks and enhance our internal controls and processes, which are designed to help protect our systems and infrastructure, and the information they contain.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.