7 unchanged sentences
Each quarter, the Board receives a report from the Audit Committee chair on items covered during that quarter’s meeting.
−Removed: In 2023, the topics included our focus on cybersecurity resilience, our approach to responsible use of Artificial Intelligence and the new cybersecurity disclosure rules.
+Added: In 2024, the topics included, among other items, our focus on cybersecurity resilience, new cybersecurity initiatives and our approach to responsible use of artificial intelligence.
Our Board's and Audit Committee’s inputs are key components in the development of our long-term cybersecurity strategy, aligning the program’s goals within our risk tolerance.
−Removed: In addition, a biennial cybersecurity risk assessment is completed with an external third party to provide us with a more complete view of our cybersecurity risk.
+Added: In addition, a periodic cybersecurity risk assessment is completed with an external third party to provide us with a more complete view of our cybersecurity risk.
We retain a prominent cybersecurity consulting firm to assist with, and advise on, our cybersecurity and incident response program.
−Removed: We engage on a quarterly basis with our auditors on matters regarding cybersecurity and maintain a robust control environment, in compliance with the Sarbanes-Oxley Act of 2002, as amended, that includes controls to protect the confidentiality, integrity and availability our data.
+Added: We engage on a quarterly basis with our internal auditors on matters regarding cybersecurity and maintain a robust control environment, in compliance with the Sarbanes-Oxley Act of 2002, as amended, that includes controls to protect the confidentiality, integrity and availability our data.
We, along with CoreSite, our data centers operations subsidiary, each maintain a management information security steering committee.
3 unchanged sentences
These committees provide direction and support for our and CoreSite’s security initiatives and review operational metrics.
−Removed: Our steering committee includes our CISO, our Chief Information Officer, our Chief Risk Officer, our Chief Technology Officer, our Senior Counsel—Corporate Legal, CoreSite’s Senior Vice President of IT & Digitization and CoreSite’s Vice President of Information Security and IT Infrastructure, each of whom has experience, both at American Tower and in prior roles, related to cybersecurity.
−Removed: Our CISO has 25 years of experience in cybersecurity, previously holding positions in the cybersecurity service provider space and at a software security firm.
+Added: Our steering committee includes our CISO, our Chief Information Officer, our Senior Vice President and Chief Security Officer, our Senior Vice President, Internal Audit, our Chief Technology Officer, our Vice President, Corporate Legal, CoreSite’s Senior Vice President of IT & Digitization and CoreSite’s Vice President of Information Security and IT Infrastructure.
+Added: Our CISO has held information security and IT leadership positions across large organizations for eight years, which included overseeing governance and compliance programs.
Our Chief Information Officer has held IT leadership positions across large, multi-national companies for nearly three decades, where he has overseen cybersecurity programs.
−Removed: Our Chief Risk Officer has nearly 40 years of risk and audit experience, including oversight of IT audit, with experience at a leading public accounting firm as well as one of the world’s largest computer storage and software companies.
−Removed: Our Chief Technology Officer has over 30 years of experience in the technology space, including leadership roles with wireless carriers and chip manufacturers, where cybersecurity was critical to the delivery of secure solutions.
−Removed: Our Senior Counsel—Corporate Legal also serves as our lead Privacy Officer and is a lawyer who has led our privacy program since its inception.
+Added: Our Chief Security Officer heads our converged physical and information security team and has over 26 years of experience in the corporate security, crisis management, and security consulting industries, including as head of global security for a major mining company and through leadership positions in several international risk consultancies.
+Added: Our Senior Vice President, Internal Audit, has over 30 years of international finance leadership experience and heads our Internal Audit function, including the evaluation of risk and vulnerabilities for both physical and system assets and the testing of related controls.
+Added: Our Chief Technology Officer has over 30 years of experience in the technology space, including leadership roles with wireless carriers
+Added: and chip manufacturers, where cybersecurity was critical to the delivery of secure solutions.
+Added: Our Vice President, Corporate Legal also serves as our lead Privacy Officer and is a lawyer who has led our privacy program since its inception.
CoreSite’s Senior Vice President of IT & Digitization has led CoreSite’s IT function for over 5 years, including having responsibility for securing the business’s cybersecurity environment.
20 unchanged sentences
We conduct an incident response exercise at least annually to ensure a timely, consistent and compliant response.
−Removed: In 2023, we performed two separate exercises:
−Removed: (1) a crisis management tabletop exercise that simulated a ransomware incident and included participation from our management, including our CEO and CFO, and (2) an IT-focused tabletop which simulated multiple types of cybersecurity incidents, including (a) compromised credentials, (b) brute force attack, (c) uncleaned malware and (d) ransomware.
−Removed: Both of these tabletop exercises were facilitated by a third-party.
+Added: In 2024, we performed an IT-focused tabletop exercise which simulated multiple types of cybersecurity incidents, including (a) compromised credentials, (b) brute force attack, (c) uncleaned malware and (d) ransomware.
+Added: This tabletop exercise was facilitated by a third-party.
Our cybersecurity risk management processes extend to the oversight and identification of threats associated with our use of third-party vendors and service providers.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.