8 unchanged sentences
and ADM’s use of third-party products, services and components.
−Removed: During the year ended December 31, 2024, the Company has not identified risks from cybersecurity threats, including as a result of prior cybersecurity incidents, that have materially affected or are reasonably anticipated to materially affect the Company, including its business strategy, results of operations, or financial condition.
−Removed: Nevertheless, the Company recognizes cybersecurity threats are ongoing and evolving.
−Removed: For more information on the Company's cybersecurity risks, refer to Item 1A.
−Removed: Risk Factors.
ADM is committed to supporting the governance and oversight of cybersecurity risks and to implementing mechanisms, controls, technologies, and processes designed to help the Company assess, identify, and manage these risks.
+Added: To date, the Company has not identified risks from cybersecurity threats, including as a result of previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: However, the Company is subject to ongoing risks from cybersecurity threats that could materially affect the Company, including its business strategy, results of operations, or financial condition, as further described in Item 1A.
+Added: Risk Factors.
Cybersecurity risks are included in the risk universe that the Company’s Enterprise Risk Management (ERM) function evaluates, with input from information security subject matter experts at the Company, to assess top risks to the enterprise.
1 unchanged sentence
Integrating cybersecurity risk into the overall ERM process in this manner assists the Company in identifying, assessing, and managing material cybersecurity risks.
−Removed: ARCHER-DANIELS-MIDLAND COMPANY
The Company has a dedicated cybersecurity team that collaborates with compliance, privacy, legal, and other teams across the global organization to assess the risk landscape.
3 unchanged sentences
Additionally, the Company has ongoing partnerships with government and commercial cybersecurity experts to understand emerging cybersecurity threats.
+Added: ARCHER-DANIELS-MIDLAND COMPANY
The Company has seen an increase in cyberattack volume, frequency, and sophistication.
4 unchanged sentences
The Board of Directors has oversight of cybersecurity risk as part of the ERM program.
−Removed: The Board of Directors is assisted by the Sustainability and Technology Committee, which regularly reviews the cybersecurity program with management and reports to the Board of Directors and the Audit Committee, which assists the Board in its oversight of the Company's ERM program.
+Added: The Board of Directors is assisted by the Sustainability and Technology Committee, which regularly reviews the cybersecurity program with management and reports to the Board of Directors.
+Added: The Board is also assisted by the Audit Committee in its oversight of the Company's ERM program.
Cybersecurity reviews by the Sustainability and Technology Committee or the Board of Directors generally occur quarterly, or more frequently as determined to be necessary or advisable.
−Removed: In recent years, the Board added a director who had served as Chief Information Officer for a large public company with sensitive information to assist the Board and Sustainability and Technology Committee in overseeing cybersecurity risks.
−Removed: The Company’s cybersecurity program is led by the Chief Information Security Officer (CISO) , who reports to the Senior Vice President and Chief Technology Officer (CTO).
−Removed: The CISO is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from professionals in the information security team, many of whom hold cybersecurity certifications in Information Systems Security or Information Security Management, and through the use of technological tools and software and results from third party audits.
−Removed: Additionally, the CISO directs the Global Information and Cyber Security Council (the “Council”), which includes a diverse range of relevant experts.
−Removed: The Council includes management from global technology, compliance, privacy, controlling, operations, security, automation, ERM, and internal audit.
+Added: In recent years, the Board added a director who had previously served as the Chief Information Officer for a large public company with complex information security requirements to enhance the Board's and Sustainability and Technology Committee's oversight of cybersecurity risks.
+Added: The Company’s cybersecurity program is led by the Chief Information Security Officer (CISO) , who reports to the Senior Vice President and Chief Information and Digital Officer (CIDO).
+Added: The CISO monitors the Company's prevention, detection, mitigation, and remediation efforts through regular communication and reporting from professionals in the information security team, many of whom hold cybersecurity certifications in Information Systems Security or Information Security Management, and through the use of technological tools and software and results from third party audits.
+Added: Additionally, the CISO directs the Company's Global Information and Cyber Security Council (the “Council”), which includes representatives from key functions such as global technology, compliance, privacy, controlling, operations, security, automation, ERM, and internal audit.
The Council promotes alignment and communication of new and ongoing cybersecurity prevention techniques and provides a forum for staying current on the latest cybersecurity threats.
−Removed: The CTO and CISO report information about such risks to the Board of Directors, the Sustainability and Technology Committee, or the Audit Committee during the regular cybersecurity reviews.
−Removed: The CISO and CTO have extensive experience assessing and managing cybersecurity programs and cybersecurity risk.
−Removed: The CISO has served in that position since 2018 and, was previously the Vice President, Head of Enterprise Security, Americas at Worldpay and a Security Principal/Strategist for Hewlett Packard Enterprises for a combined cybersecurity experience of 20 years.
−Removed: The CTO joined ADM in 2016 and was previously Senior Vice President and Chief Information Officer at Dow Corning Corporation for approximately 6 years.
+Added: The CISO and CIDO report information about such risks to the Board of Directors, the Sustainability and Technology Committee, or the Audit Committee during the regular cybersecurity reviews.
+Added: The CISO and CIDO have extensive experience assessing and managing cybersecurity programs and cybersecurity risk.
+Added: The CISO has served in that position since 2018 and was previously the Vice President, Head of Enterprise Security, Americas at Worldpay and a Security Principal/Strategist for Hewlett Packard Enterprises for a combined 20 years of cybersecurity experience.
+Added: The CIDO joined the Company effective January 14, 2026, replacing the Company's former Chief Technology Officer.
+Added: Prior to joining ADM, the CIDO served as the Chief Information Technology and Data Officer for the Americas & Global Sales Technology at Danone for approximately six years, and, prior to Danone, held senior IT and data leadership roles at Gillette, Procter & Gamble and Nike since 2007.
+Added: Through these roles, the CIDO has extensive experience overseeing, managing, and working on cybersecurity programs.
ARCHER-DANIELS-MIDLAND COMPANY
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.