3 unchanged sentences
We have developed a comprehensive cybersecurity program designed to protect our systems and the confidentiality, integrity and availability of our data.
−Removed: We have implemented processes that are intended to assess, identify, manage and reduce cybersecurity risks.
−Removed: We maintain a global incident response plan and disaster recovery management plan, each designed to protect against, identify, evaluate, respond to and recover from an incident.
+Added: We have implemented processes that are intended to govern, manage and reduce cybersecurity risks.
+Added: We maintain a global incident response plan and disaster recovery management plan, each designed to protect against, identify, detect, respond to and recover from an incident.
These plans anticipate an array of potential scenarios and provide for the assembly of a cybersecurity incident response team in the event of a cyber incident.
1 unchanged sentence
We regularly conduct exercises to help ensure the plans’ effectiveness and our overall preparedness.
−Removed: We also have invested in tools and technologies to protect our and our patients', customers' and business partners' data and information technology, and we regularly monitor our information technology systems and infrastructure to identify and assess cybersecurity risks.
−Removed: We have designed a Threat Intelligence function that actively looks for risks that target the pharmaceutical industry generally or AbbVie specifically.
+Added: We also have invested in tools and technologies to protect our and our patients' and customers' data and information technology, and we regularly monitor our information technology systems and infrastructure to identify and assess cybersecurity risks.
+Added: We have designed a Threat Intelligence function that actively looks for emerging threats and risks that target the pharmaceutical industry generally or AbbVie specifically.
We rely in part on third parties (including assessors, consultants, advisors and others) in connection with our processes for assessing, identifying, managing and reducing cyber risks.
In addition, we have implemented a cybersecurity awareness program designed to educate and train our entire employee network on how to identify and report cybersecurity threats.
−Removed: Training programs are conducted on a periodic basis and are focused on giving employees tools to manage and defend against the most relevant and prevalent cybersecurity risks to AbbVie.
−Removed: We also provide specialized training for employees in specialized information technology roles.
+Added: Training programs are conducted on a periodic basis and are focused on giving employees information to manage and defend against the most relevant and prevalent cybersecurity risks to AbbVie.
+Added: We also provide specialized training for employees in specialized information technology roles and for business functions who may be impacted by a cyber incident.
We conduct regular drills, such as tabletop exercises, to help with our overall preparedness.
3 unchanged sentences
With respect to third-party service providers, our information security program includes conducting due diligence of relevant service providers’ information security programs prior to onboarding.
−Removed: We also contractually require third-party service providers with access to our information technology systems, sensitive business data or personally identifiable
+Added: We also contractually require third-party
| 2024 Form 10-K
−Removed: information to implement and maintain appropriate security controls and contractually restrict their ability to use our data, including personally identifiable information, for purposes other than to provide services to us, except as required by law.
+Added: service providers with access to our information technology systems, sensitive business data or personally identifiable information to implement and maintain appropriate security controls and contractually restrict their ability to use our data, including personally identifiable information, for purposes other than to provide services to us, except as required by law.
To oversee the risks associated with these service providers, we work with them to help ensure that their cybersecurity protocols are appropriate to the risk presented by their access to or use of our systems and/or data, including notification and coordination concerning incidents occurring on third-party systems that may affect us.
17 unchanged sentences
The Audit Committee receives regular updates from the Chief Information Security Officer and other members of management on our cybersecurity program, including on information security and technology risks, program assessments, and risk management practices.
−Removed: Our Chief Information Security Officer also provides similar topical updates to the full board of directors at least annually.
+Added: Our Chief Information Security Officer and other senior information technology executives also provides similar topical updates to the full board of directors at least annually.
2024 Form 10-K |
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.