7 unchanged sentences
Each quarter, the Board receives a report from the Audit Committee chair on items covered during that quarter’s meeting.
−Removed: In 2024, the topics included, among other items, our focus on cybersecurity resilience, new cybersecurity initiatives and our approach to responsible use of artificial intelligence.
+Added: In 2025, the topics included, among other items, our focus on cybersecurity resilience, new cybersecurity initiatives, third-party risk and our approach to responsible use of artificial intelligence.
Our Board's and Audit Committee’s inputs are key components in the development of our long-term cybersecurity strategy, aligning the program’s goals within our risk tolerance.
+Added: Our Board is responsible for the oversight of our AI strategy and the Audit Committee has oversight over AI-related risk exposure and receives regular AI updates from management.
+Added: Our Board, Audit Committee and management have overseen the development and launch of our AI governance program.
In addition, a periodic cybersecurity risk assessment is completed with an external third party to provide us with a more complete view of our cybersecurity risk.
6 unchanged sentences
These committees provide direction and support for our and CoreSite’s security initiatives and review operational metrics.
−Removed: Our steering committee includes our CISO, our Chief Information Officer, our Senior Vice President and Chief Security Officer, our Senior Vice President, Internal Audit, our Chief Technology Officer, our Vice President, Corporate Legal, CoreSite’s Senior Vice President of IT & Digitization and CoreSite’s Vice President of Information Security and IT Infrastructure.
−Removed: Our CISO has held information security and IT leadership positions across large organizations for eight years, which included overseeing governance and compliance programs.
+Added: Our steering committee includes our CISO, our Chief Information Officer, our Senior Vice President and Chief Security Officer, our Senior Vice President, Internal Audit, our Vice President, Corporate Legal, CoreSite’s Senior Vice President of IT & Digitization and CoreSite’s Vice President of Information Security and IT Infrastructure.
+Added: Our CISO has held information security and IT leadership positions across large organizations for nine years, which included overseeing governance and compliance programs.
Our Chief Information Officer has held IT leadership positions across large, multi-national companies for nearly three decades, where he has overseen cybersecurity programs.
1 unchanged sentence
Our Senior Vice President, Internal Audit, has over 30 years of international finance leadership experience and heads our Internal Audit function, including the evaluation of risk and vulnerabilities for both physical and system assets and the testing of related controls.
−Removed: Our Chief Technology Officer has over 30 years of experience in the technology space, including leadership roles with wireless carriers
−Removed: and chip manufacturers, where cybersecurity was critical to the delivery of secure solutions.
Our Vice President, Corporate Legal also serves as our lead Privacy Officer and is a lawyer who has led our privacy program since its inception.
1 unchanged sentence
CoreSite’s Vice President of Information Security and IT Infrastructure has over 25 years of experience building secure IT solutions across large network and data center environments and has been responsible for the day-to-day operation of CoreSite’s business-critical IT environment since 2015.
−Removed: CoreSite’s steering committee includes CoreSite’s Chief Executive Officer, its Chief Accounting Officer, its Chief Revenue Officer, its Senior Vice President of IT & Digitization, its Vice President of Legal, its Senior Vice President of Development & Product Engineering, its Senior Vice President of Data Center Operations, its Senior Vice President of Human Resources, its Vice President of Compliance & Internal Controls, its Senior Vice President of Finance & Corporate Development, its Vice President of Information Security and IT Infrastructure, its Director of Compliance & Internal Controls, and American Tower’s CISO.
+Added: CoreSite’s steering committee includes CoreSite’s Chief Executive Officer, its Chief Accounting Officer, its Chief Revenue Officer, its Senior Vice President of IT & Digitization, its Vice President of Legal, its Senior Vice President of Development & Product Engineering, its Senior Vice President of Data Center Operations, its Senior Vice President of Human Resources, its Senior Vice President of Finance & Corporate Development, its Vice President of Information Security and IT Infrastructure, its Director of Compliance & Internal Controls, and American Tower’s CISO.
Each of CoreSite’s steering committee members has been chosen based on their understanding of, and participation in, maintaining the rigorous control environment necessary to achieve the list of certifications detailed below.
9 unchanged sentences
Our cybersecurity awareness program provides training for all global employees at onboarding and subsequently three times every year.
−Removed: In 2024, across our organization, employees completed over 8,943 training classes related to cybersecurity.
−Removed: Additionally, in 2024, to elevate cybersecurity awareness, we also conducted live training as part of our Employee Development program, sent monthly phishing tips to all employees and provided weekly communications during October, which is cybersecurity awareness month.
+Added: In 2025, across our organization, employees completed over 16,000 training classes related to cybersecurity and responsible AI use.
+Added: Additionally, in 2025, to elevate cybersecurity awareness, we also conducted live trainings as part of our Employee Development program, sent monthly phishing tips to all employees and provided weekly communications during October, which is cybersecurity awareness month.
Operationally, we, along with CoreSite, each perform periodic penetration testing to identify weaknesses in systems and networks so that they can be addressed appropriately.
−Removed: At least once per year, we also engage an outside cybersecurity firm to perform independent testing.
+Added: At least once every other year, we also engage an outside cybersecurity firm to perform independent testing or a risk assessment.
Our vulnerability management program is in place to adequately identify, classify, prioritize and remediate vulnerabilities affecting assets.
−Removed: Our security operations program monitors our systems and networks, and is responsible for investigating, responding to, and reporting any potential security incidents in a timely manner.
+Added: Our security operations program monitors our
+Added: systems and networks, and is responsible for investigating, responding to, and reporting any potential security incidents in a timely manner.
Our Incident Response Plan includes steps to determine materiality of any such incident and escalate matters to the Board and our employees are regularly trained on the plan.
We conduct an incident response exercise at least annually to ensure a timely, consistent and compliant response.
−Removed: In 2024, we performed an IT-focused tabletop exercise which simulated multiple types of cybersecurity incidents, including (a) compromised credentials, (b) brute force attack, (c) uncleaned malware and (d) ransomware.
+Added: In 2025, we performed a cybersecurity-focused tabletop exercise which simulated multiple types of cybersecurity incidents, including (a) compromised credentials, (b) brute force attack, (c) uncleaned malware and (d) ransomware to validate and update our internal processes.
This tabletop exercise was facilitated by a third-party.
1 unchanged sentence
We have in place a Third-Party Cybersecurity Risk Management program to assess the cybersecurity practices of third-party vendors and service providers with access to our and CoreSite’s systems or information.
+Added: At the core of our AI governance program is our Global Artificial Intelligence Use and Development Policy, launched in 2025, which establishes the benefits, restrictions and preconditions for AI use and empowers a permanent, cross‑functional AI steering committee to review and approve AI use cases, implement mandatory employee training and ensure that AI is used responsibly and with a balanced assessment of risks and benefits.
We have not been materially impacted by any cybersecurity threats or prior cybersecurity incidents, including with respect to our business strategy, results of operations or financial condition.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.