2 unchanged sentences
Zurn Elkay’s management and Board recognize the importance of robust oversight of cybersecurity risk, information security, and technology risk in maintaining the trust and confidence of our customers, partners, employees, and stockholders.
−Removed: The Audit Committee, on behalf of the Board, oversees the Company’s material financial and other risk exposures, including risks related to cybersecurity.
−Removed: Our Board has extensive cybersecurity experience, including two members of the Audit Committee who have received a certificate in cybersecurity oversight from the Carnegie Mellon University Software Engineering Institute.
+Added: The Audit Committee, on behalf of the Board, oversees the Company’s material financial and other risk exposures, including risks related to cybersecurity and artificial intelligence.
+Added: Our Board has extensive cybersecurity experience, including two members of the Audit Committee who have received a certificate in cybersecurity oversight from the Carnegie Mellon University Software Engineering Institute and one member of the Audit Committee who received a certificate in Effective AI Oversight from the Heinz College of Information Systems and Public Policy of Carnegie Mellon University.
Cybersecurity risk also is monitored, assessed and managed as part of the Company’s integrated Enterprise Risk Management program.
7 unchanged sentences
The program uses a combination of standards and best practices from the National Institute of Standards and Technology, Center of Internet Security, third-party vendor partners, and other industry forums.
−Removed: Annually, the program is assessed both internally and externally, including a thorough industry benchmarking, maturity assessments, best practice reviews, and risk assessments, with control validation occurring monthly internally (focused on core critical controls), quarterly (focused on vulnerabilities/cyber-incident simulations) and annually (focused on a review of best practices) via third-party vendors and partners, and annually via external third parties, including the conduct of internal/external penetration tests and tabletop exercises.
+Added: The program is assessed both internally and externally, including a thorough industry benchmarking and best practice review annually, with maturity assessments and risk assessments occurring alternating years biennially.
+Added: Control validations occur monthly internally (focused on core critical controls), quarterly (focused on vulnerabilities/cyber-incident simulations) and annually (focused on a review of best practices) via third-party vendors and partners, and annually via external third parties, including the conduct of internal/external penetration tests and tabletop exercises.
Third-party service providers are assessed initially based on security questionnaires and the access of third-party service providers is audited annually and/or with any change in circumstances.
−Removed: Third-party service providers are also monitored through a combination of security information and event management technology and managed detection response services.
−Removed: The CIO provides key results and findings from these assessments to the cybersecurity governance council and Audit
+Added: Third-party service provider access is also monitored through a combination of security information and event management technology and managed detection response services.
+Added: The CIO provides key results and findings from these assessments to the cybersecurity governance council and Audit Committee.
The Company has a robust incident response plan intended to help provide timely remediation to cybersecurity incidents and also to help provide notice of any material incidents to the appropriate internal and external entities.
13 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.