6 unchanged sentences
We have implemented processes and procedures for the assessment, identification, and management of material risks from cybersecurity threats.
−Removed: These processes implement both qualitative and quantitative measurements that have been agreed upon with our third-party consultants, our auditors, and integrated into our overall risk management process.
+Added: These processes implement both qualitative and quantitative measurements that have been integrated into our overall risk management process.
+Added: In evaluating cybersecurity incidents and risks, management assesses materiality by considering both quantitative and qualitative factors, including the potential impact on our operations, results of operations, customer relationships, regulatory obligations, reputation, and the sensitivity of the data involved.
Our process includes assessing, mitigating, and managing risk in three categories:
2 unchanged sentences
We verify third-party compliance, such as suppliers and business partners, by aligning with several standards.
−Removed: For example, we subject our IT suppliers to the Sarbanes-Oxley ("SOX") and payment card industry ("PCI") compliance standards where applicable.
−Removed: As a publicly traded company and given the industry in which we operate, we have established a risk-based strategy informed by numerous cybersecurity frameworks from regulatory bodies such as PCI, SOX, FAA, TSA, DOT, NIST and DoD.
+Added: As a publicly traded company and given the industry in which we operate, we have established a risk-based strategy informed by recognized cybersecurity and risk management frameworks and applicable regulatory requirements, including, where relevant, NIST CSF, PCI, and other industry standards.
We use the National Institute of Standards and Technology Cybersecurity Framework ("NIST CSF") as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
6 unchanged sentences
• Insider Threats – We maintain an insider threat program, designed to identify, assess, and address potential risks from within Allegiant.
−Removed: Our program evaluates potential risks consistent with industry best practices, customer requirements and applicable law, including privacy and other considerations.
+Added: Our program seeks to evaluate potential risks consistent with industry best practices, customer requirements and applicable law, including privacy and other considerations.
• Information Sharing and Collaboration – We work with government, customer, industry and supplier partners including government-industry partnerships and critical infrastructure threat intelligence sharing platforms.
9 unchanged sentences
• Scalability – We continue to invest directly in our cybersecurity program, as well as augmentation of those cybersecurity services through managed services and third parties, depending on the maturity and risk of the operating model of the business unit.
+Added: We maintain an incident response and escalation framework designed to enable timely identification, containment, investigation, and remediation of cybersecurity incidents.
+Added: This framework includes defined escalation protocols involving senior management, legal, finance, and our disclosure controls and procedures to assess potential reporting obligations and communications, including notification to the board.
Disclosure of Identified Risks
1 unchanged sentence
Although we have not experienced cybersecurity incidents that are individually, or in the aggregate, material, we have experienced cyberattacks in the past, which we believe have thus far been largely mitigated by preventative, detective and responsive measures implemented by us.
−Removed: For a detailed discussion of our cybersecurity related risks, see Item 1A Risk Factors – “ A breach in the security of personal information, breach in credit card data or system disruptions caused by security breaches or cyberattacks – including attacks on those parties we do business with
−Removed: – could harm our ability to conduct our operations and could have a material adverse effect on our financial position or results of operations .”
+Added: For a detailed discussion of our cybersecurity related risks, see Item 1A Risk Factors – “ A breach in the security of personal information, breach in credit card data or system disruptions caused by security breaches or cyberattacks – including attacks on those parties we do business with – could harm our ability to conduct our operations and could have a material adverse effect on our financial position or results of operations .”
Board Oversight of Cybersecurity Risks
−Removed: Our board is responsible for overseeing our enterprise risk management activities in general, the appropriate committees assist the board in the role of risk oversight.
+Added: Our board is responsible for overseeing our enterprise risk management activities in general.
+Added: The appropriate committees assist the board in the role of risk oversight.
Our chief information security officer (CISO) presents a quarterly update to the full board, including an update on our risk management process and risk trends related to cybersecurity.
2 unchanged sentences
Our CISO leads our day-to-day data security and customer privacy efforts — overseeing operations, cybersecurity, privacy risk and compliance.
−Removed: The CISO, who has more than 30 years of experience reports regularly to our chief executive officer (CEO), monthly to the risk and compliance committee (consisting of executive leadership) and quarterly to our board.
+Added: The CISO, who has more than 20 years of experience, reports regularly to our President & CFO (chief financial officer), monthly to the risk and compliance committee (consisting of executive leadership), and quarterly to our board.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.