4 unchanged sentences
Our Board has extensive cybersecurity experience, including two members of the Audit Committee who have received a certificate in cybersecurity oversight from the Carnegie Mellon University Software Engineering Institute.
−Removed: Cybersecurity risk also is monitored, assessed and managed as part of the Company’s integrated Enterprise Risk Management program on an ongoing basis.
−Removed: A cybersecurity governance council, comprised of executive leaders, meets at least quarterly to review the Company’s cybersecurity program and its effectiveness.
+Added: Cybersecurity risk also is monitored, assessed and managed as part of the Company’s integrated Enterprise Risk Management program.
+Added: A cybersecurity governance council, comprised of executive leaders, including the two members of the Audit Committee with cybersecurity experience, meets at least quarterly to review the Company’s cybersecurity program and its effectiveness.
This cybersecurity governance council receives updates and reports from the Company’s global cybersecurity team (discussed below) on the cybersecurity program and its effectiveness relating to the prevention, detection, mitigation and remediation of cybersecurity incidents.
8 unchanged sentences
Third-party service providers are also monitored through a combination of security information and event management technology and managed detection response services.
−Removed: The CIO provides key results and findings from these assessments to the cybersecurity governance council and Audit Committee.
+Added: The CIO provides key results and findings from these assessments to the cybersecurity governance council and Audit
The Company has a robust incident response plan intended to help provide timely remediation to cybersecurity incidents and also to help provide notice of any material incidents to the appropriate internal and external entities.
5 unchanged sentences
As we have previously described in Item 1A, Risk Factors, there have been significant and increasing instances of data and security breaches, malicious interference with technology systems and industrial espionage involving companies in numerous industries, including cloud providers, and cybersecurity threats are becoming more complex.
−Removed: In addition, at times a large percentage of our workforce may be working remotely in response to outbreaks of infectious disease, which may heighten these risks.
+Added: In addition, at times a large percentage of our workforce may be working remotely, which may heighten these risks.
While we have taken steps to maintain and enhance our cybersecurity by implementing additional security technologies, internal controls, network and data center resiliency, redundancy and disaster recovery processes and backup systems, upgrading our remote work environment and by obtaining insurance coverage, these measures may be inadequate and our technology systems could be vulnerable to disability, failures, or unauthorized access.
−Removed: As a result, any inability by us to successfully manage our information systems, or respond effectively to any attack on or interference with our systems, including matters related to system and data security, privacy, reliability, compliance, performance and access, problems related to our systems caused by natural disasters, security breaches or malicious attacks, and any inability of these systems to fulfill
−Removed: their intended business purpose, could impede our ability to record or process orders, manufacture and ship in a timely manner, account for and collect receivables, protect sensitive data of the Company, our customers, our employees, our suppliers and other business partners, comply with our third party obligations of confidentiality and care, or otherwise carry on business in the normal course.
+Added: As a result, any inability by us to successfully manage our information systems, or respond effectively to any attack on or interference with our systems, including matters related to system and data security, privacy, reliability, compliance, performance and access, problems related to our systems caused by natural disasters, security breaches or malicious attacks, misuse of artificial intelligence tools, and any inability of these systems to fulfill their intended business purpose, could impede our ability to record or process orders, manufacture and ship in a timely manner, account for and collect receivables, protect sensitive data of the Company, our customers, our employees, our suppliers and other business partners, comply with our third party obligations of confidentiality and care, or otherwise carry on business in the normal course.
Any such events could require costly remediation beyond levels covered by insurance and could cause us to lose customers and/or revenue, including as a result of legal or regulatory claims or proceedings, or damage our reputation, any of which could have a material adverse effect on our business and operating results.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.