4 unchanged sentences
Managing Material Risk
−Removed: The Company’s approach to risk management is unique to each reporting segment, with Virbela and Other Affiliated Services each independently identifying, assessing, and managing their material risk from cybersecurity threats, and North American Realty and International Realty operating under a joint risk framework due to the similarities in cybersecurity risk they face.
+Added: The Company’s approach to risk management is tailored to its reporting segments.
+Added: FrameVR.io, which was moved to the North American Realty segment during the first quarter of 2025, independently identifies, assesses, and manages its material risk from cybersecurity threats, and North American Realty, International Realty, and, recently, Other Affiliated Services, operate under a joint risk framework due to the similarities in cybersecurity risk they face.
While educational resources about cybersecurity risks are shared amongst Information Technology (“IT”) staff across segments, segment-specific IT staff are empowered to evaluate and address cybersecurity risks within their reporting segment in alignment with the Company’s overall business objectives and operational needs.
Where required, IT staff in each reporting segment may communicate with their counterparts in different reporting segments or with executive management of the Company to ensure compliance with cybersecurity incident and data breach reporting requirements under applicable law.
+Added: Staff across all segments are required to complete company facilitated cybersecurity training at least annually.
Engage Third Parties on Risk Management
−Removed: Understanding the complexity and evolving nature of cybersecurity threats, each reporting segment engages with a range of external experts, including cybersecurity assessors and consultants, to assess, identify, and manage material risks posed by cybersecurity threats, as determined by each reporting segment’s IT personnel.
−Removed: Each reporting segment has enabled external technologies and specialists, as deemed necessary by the reporting segment, to continuously test, alert, and report on the Company’s various computing ecosystems.
−Removed: These external assets allow the reporting segment IT leaders to leverage cybersecurity tools applicable to their segment’s risks, ensuring our cybersecurity strategies and processes continue to align with business objectives and operational needs.
−Removed: Segment IT personnel collaborate with these third-parties to review and discuss vulnerabilities and threats, consult on security enhancements for better risk identification, and audit risk management systems.
+Added: Understanding the complexity and evolving nature of cybersecurity threats, each reporting segment may engage with a range of external experts, including cybersecurity assessors and consultants, to assess, identify, and manage material risks posed by cybersecurity threats, as determined by each reporting segment.
+Added: Each reporting segment may enable external technologies and specialists, as deemed necessary by the reporting segment, to test, alert, and report on the Company’s various computing ecosystems.
+Added: These external assets allow the reporting segment leaders to leverage cybersecurity tools applicable to their segment’s risks, ensuring our cybersecurity strategies and processes continue to align with business objectives and operational needs.
+Added: Segment personnel that engage such third-parties collaborate with these third-parties to review and discuss vulnerabilities and threats, consult on security enhancements for better risk identification, and audit risk management systems.
Oversee Third -Party Risk
−Removed: Due to the risks associated with third-party access to certain systems and data in each reporting segment, when a reporting segment enters into a relationship with a third-party service provider that presents a cybersecurity risk, various security assessments may be issued by the reporting segment to enable the applicable reporting segment to identify, oversee, and manage these risks.
−Removed: The security assessments are designed to establish communication channels as between the reporting segment and the third-party for purposes of cybersecurity risk management and reporting, as well as to ensure that security controls are established as necessary to comply with that reporting segment’s security and privacy policies.
−Removed: Such assessments may include an initial assessment conducted by the IT staff of the reporting segment, an annual assessment thereafter by the IT staff of the reporting segment, and ongoing monitoring of tools deployed within the third-party’s environment by the third-party’s IT staff or equivalent thereof.
−Removed: Where applicable, the reporting segment imposes security incident reporting requirements on third-party
−Removed: service providers via written contract in order to ensure the timely reporting of incidents.
−Removed: Information obtained in initial and ongoing assessments as well as incident reports are presented to applicable reporting segment staff who (i) review and engage the third party on preventative and responsive actions based on such assessments and reports, as applicable, and (ii) evaluate the continued relationship with the third party and terminate the relationship, if necessary.
+Added: The Company recognizes that third-party service providers may introduce cybersecurity risks related to access to certain systems and data.
+Added: The Company’s cybersecurity processes include documentation of certain third-party service providers’ security postures, with risk-related information recorded in TrustArc or similar internal tracking tools.
+Added: Where applicable, these processes involve requesting third-party audit reports.
+Added: Certain third-party relationships, including individual AI licenses and vendors onboarded through non-IT channels, may not be documented or reviewed as part of the Company’s cybersecurity processes.
+Added: Where applicable, the Company maintains written contractual provisions requiring third-party service providers to report security incidents.
+Added: Any information obtained through such reporting may be reviewed and recorded by security personnel.
+Added: The Company does not routinely provide feedback to third parties on identified risks but may document available security information to facilitate internal awareness.
Risk of Cybersecurity Threats
To date, the Company has not identified a cybersecurity threat in any reporting segment, including as a result of any previous cybersecurity incidents, that has or is reasonably likely to have a current or future material effect on our business strategy, financial condition, results of operations, liquidity, capital expenditures, or capital resources.
+Added: For more information regarding risks from cybersecurity threats, see “Item 1A - Risk Factors” in this Annual Report, in particular under the caption “Cybersecurity incidents could disrupt our business operations, result in the loss of critical and confidential information, adversely impact our reputation and harm our business.”
Cybersecurity Governance
−Removed: eXp World Holdings, Inc.’s Board of Directors (the “Board”) is aware of the critical nature of managing risks associated with cybersecurity threats and meets regularly to discuss managing risk from cybersecurity threats, among other risks facing the Company.
−Removed: The Board has established oversight mechanisms to ensure effective governance in managing risks associated with cybersecurity threats.
+Added: The Company’s Board of Directors (the “Board”) is aware of the critical nature of managing risks associated with cybersecurity threats and meets regularly to discuss managing risk from cybersecurity threats, among other risks facing the Company.
+Added: The Board has established oversight mechanisms to manage risks associated with cybersecurity threats.
Board of Directors Oversight
The Board’s Nominating and Corporate Governance Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for cybersecurity risk oversight.
−Removed: When required, additional information is provided from the IT management for each reporting segment for further insight and analysis.
+Added: When required, additional information is provided from the IT management from North American Realty and additional staff for each reporting segment for further insight and analysis.
The Company is continually monitoring its cybersecurity oversight, strategy and governance for improvement and refinement.
Management’s Role Managing Risk
−Removed: The Company’s Chief Information Officer (“CIO”) plays a key role in informing the Nominating and Corporate Governance Committee of cybersecurity risks across the reporting segments.
−Removed: This management member provides comprehensive briefings to the Nominating and Corporate Governance Committee on a quarterly basis.
−Removed: These briefings include a broad range of topics, including:
+Added: The Company’s Chief Technology Officer (“CTO”) oversees cybersecurity risks for North American Realty, International Realty, and, as of recently, Other Affiliated Services;
+Added: provided, however, that cybersecurity risk management for FrameVR.io, which was moved to the North American Realty segment during the first quarter of 2025, is overseen by the Vice President of FrameVR.io, in consultation with the CTO as requested.
+Added: The CTO provides comprehensive briefings to the Nominating and Corporate Governance Committee on a quarterly basis covering a broad range of topics, including, without limitation:
● Current cybersecurity landscape and emerging threats;
−Removed: ● Status of ongoing cybersecurity initiatives and strategies in various reporting segments;
+Added: ● Status of ongoing cybersecurity initiatives and strategies within his purview;
● Incident reports and learnings from any cybersecurity events;
● Compliance with regulatory requirements and industry standards.
−Removed: The CIO receives updates on any significant developments in the cybersecurity domain from each reporting segment, which the CIO then reports to the Nominating and Corporate Governance Committee, ensuring the Board’s oversight is proactive and responsive.
+Added: The CTO receives updates on any significant developments in the cybersecurity domain from North American (excluding FrameVR.io), International Realty, and, recently, Other Affiliated Services which the CTO then reports to the Nominating and Corporate Governance Committee, ensuring the Board’s oversight is proactive and responsive.
+Added: Personnel from FrameVR.io are empowered to report cybersecurity risk to their respective leaders who may then report to the Nominating and Corporate Governance Committee directly or funnel such reporting to the CEO.
Risk Management Personnel
−Removed: Primary oversight and responsibility for managing the Company’s cybersecurity risks resides with the CIO.
−Removed: With over 25 years of experience in business and information technology management, the current Company CIO is an accomplished software executive with an exceptional record of building large-scale product delivery organizations, which include product management, engineering, information technology, and information security.
−Removed: The current Company CIO is graduate of Southern Methodist University where he obtained his M.B.A.
−Removed: and University of Oklahoma where he received his B.S.
−Removed: in Computer Sciences.
−Removed: Accompanying the CIO with the development of the security ecosystem is key personnel at each reporting segment, including:
−Removed: ● North American and International Realty’s Sr.
−Removed: Director of Information Security.
−Removed: The person currently in this role has over 15 years of experience managing enterprise level cyber security programs in various industries in addition to having a Bachelor of Science in Information Technology Management and Information Security Manager Certification.
−Removed: ● Virbela’s Director of IT.
−Removed: The person currently in this role has a Master of Computer Information Systems degree and has fifteen years of professional experience in IT roles, specializing in data management and security, operational reliability and assurance, and regulatory compliance.
−Removed: They are experienced in information security practices, having been involved in SOC 2, GDPR, CCPA, and PCI DSS compliance frameworks.
−Removed: ● Virbela’s Vice President of Frame.
−Removed: The person currently in this role has a Master in Education Technology and a decade working at the intersection of collaboration and spatial computing as a developer and technical product manager.
−Removed: They also have broad experience working with information security and privacy frameworks such as SOC-2, GDPR, and COPPA.
−Removed: ● Virbela’s President.
−Removed: The person currently in this role has a Doctorate of Philosophy in Consulting Psychology and over eleven (11) years of expertise designing and managing the Virbela product, including its cyber vulnerabilities, data collection, and related processes.
−Removed: ● Other Affiliated Services Vice President, Operations.
−Removed: The person currently in this role has Master of Business Administration in Accounting and Business/Management with sophisticated professional experience in software implementation and business intelligence.
−Removed: His experience encompasses conducting security audits, implementing intrusion detection with cloud service providers, developing access controls and API encryption, and mitigating risks through vendor relations.
−Removed: Additionally, he has worked in IT policy development, single sign-on implementation, and cloud security.
−Removed: The staff in each reporting segment have extensive knowledge of cybersecurity risk applicable to their reporting segment.
+Added: Primary oversight and responsibility for managing the Company’s cybersecurity risks resides with the CEO.
+Added: With over 25 years of experience in technology leadership, entrepreneurship, and real estate innovation, his expertise lies in leveraging technology to transform traditional industries, including pioneering the first fully cloud-based real estate brokerage model.
+Added: The CEO’s career began in the technology sector, where he founded eShippers.com, an eCommerce and logistics platform that integrated online storefronts with a national fulfillment network.
+Added: This experience in developing scalable, technology-driven solutions laid the groundwork for his later success in building the Company .
+Added: His vision for integrating advanced IT systems into real estate has driven eXp Realty’s growth to over 82,000 agents across 24 countries.
+Added: He holds a degree in Economics and Computer Science from the University of Oklahoma, which supports his ability to align technology initiatives with strategic business goals.
+Added: Under the CEO’s leadership, the Company continues to innovate through immersive virtual environments, advanced data systems, and scalable global operations, ensuring its position as a leader in real estate technology.
+Added: Accompanying the CEO with the development of the security ecosystem is key personnel at each reporting segment, including:
+Added: ● North American Realty and International Realty’s Chief Innovation Officer.
+Added: The person in this role has over 20 years of experience as a technologist, startup founder, and technology executive with expertise in software development, product management, and real estate technology innovation.
+Added: He holds a Bachelor of Arts from the College of Charleston and has led transformative technology initiatives, including two successful PropTech startup exits.
+Added: ● North American Realty and International Realty’s Chief Technology Officer.
+Added: The person in this role has over 20 years of experience leading global technology teams, delivering innovative software solutions, and driving business transformation.
+Added: He is experienced in building and delivering secure, scalable technology solutions, with a focus on software reliability, data integrity, and secure system architecture.
+Added: He is also actively expanding his expertise in cybersecurity, focusing on cloud security, threat mitigation, and risk management to strengthen enterprise system protection.
+Added: He holds a Master of Science in Computer Science and a Bachelor of Engineering in Mechanical Engineering.
+Added: He also completed a postgraduate degree in AI and machine learning from the University of Texas at Austin.
+Added: ● North American Realty and International Realty’s Senior Director of Information Security.
+Added: The person currently in this role has over 25 years of experience managing enterprise level cyber security programs in various industries in addition to having a Bachelor of Science in Information Technology Management and is a Certified Information Security Manager (CISM), along with ITIL and ISO certifications.
+Added: ● North American Realty and International Realty’s Senior Director of Data Privacy & GRC.
+Added: The person in this role has over 15 years of experience in data privacy, governance, and compliance, with expertise in managing enterprise-wide privacy programs and mitigating regulatory risks.
+Added: She holds a Master of Public Administration and a Bachelor of Science in Political Science, both from Kennesaw State University, and is a Certified Information Privacy Manager (CIPM) and Certified Data Privacy Solutions Engineer.
+Added: ● Vice President, FrameVR.io.
+Added: The person currently in this role has Master in Education Technology and a decade working at the intersection of collaboration and spatial computing as a developer and technical product manager.
+Added: They also have general experience working with information security and privacy frameworks such as SOC-2, GDPR, and COPPA.
+Added: The Vice President of FrameVR.io reports to the CIO.
Monitoring Cybersecurity Incidents
−Removed: Daily security assessments, alert monitoring, and the management of cybersecurity threats are the responsibility of each reporting segment.
−Removed: When appropriate, each reporting segment escalates information to the CIO to ensure awareness of cybersecurity risks across the reporting segments and to enable required incident management procedures applicable to each reporting segment.
−Removed: The reporting segments provide analysis to aid in the remediation of cybersecurity incidents.
−Removed: Each reporting segment has developed an incident response plan to pool resources that determines actions and remediation efforts, including escalation to the CIO, when necessary.
+Added: Daily security assessments, alert monitoring, and the management of cybersecurity threats are the responsibility of each reporting segment and each reporting segment deploys an approach that is tailored to their risk environment within the Company and its overall business objectives.
+Added: Notwithstanding the foregoing, Frame.
+Added: FrameVR.io is independently responsible for its assessments, alert monitoring, and management of cybersecurity threats.
+Added: When appropriate, each reporting segment escalates information to the CEO of the Company or CTO to ensure awareness of relevant cybersecurity risks across the reporting segments and to enable required incident management procedures applicable to each reporting segment.
+Added: The reporting segments and FrameVR.io provide information and analysis to aid in the remediation of cybersecurity incidents.
Reporting to Board of Directors
−Removed: The CIO, in his capacity, informs the Chief Executive Officer of the Company and Chief Strategy Officer of eXp Realty, LLC of all aspects related to cybersecurity risks and threats.
−Removed: This ensures the highest levels of management are knowledgeable and updated about the cybersecurity posture and potential risks facing the Company.
+Added: The CTO , together with reporting segment and FrameVR.io key personnel listed above and with input from the CEO, inform the Nominating and Corporate Governance Committee of relevant material aspects related to cybersecurity risks and threats.
+Added: This ensures the highest levels of oversight are aware and updated about the cybersecurity posture and potential risks facing the
Furthermore, cybersecurity incidents, strategic risk management decisions, and materiality analysis are escalated to the Board, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.