2 unchanged sentences
Cybersecurity Governance
−Removed: Cybersecurity at our company is overseen by our Board, the Audit Committee and management, as well as through our Enterprise Information Security Policy (“EISP”).
+Added: Cybersecurity at our company is overseen by our Board, the Audit Committee and management, and such oversight is also carried out through our Enterprise Information Security Policy (“EISP”).
The Audit Committee of our Board is responsible for overseeing risk management strategies that are specific to our company, including reviewing management’s assessment of the current and emerging risks and related mitigation strategies across financial and non-financial risks, including cybersecurity risks.
3 unchanged sentences
The CISO has over 20 years’ experience in cybersecurity oversight, holds a Bachelor's Degree in Computer Science and Economics from York University and holds a number of information security certifications, including:
−Removed: CISSP, CISM, CISA and CRISC.
+Added: CISSP, CISM and CISA.
Cybersecurity Risk Management and Strategy
3 unchanged sentences
We believe our cybersecurity program is reasonably designed to materially protect the integrity and availability of our information and technology.
−Removed: This program addresses security governance, security awareness, employee training, relevant access and end-point security, vulnerability management, penetration testing, security monitoring and incident response.
+Added: This program addresses information security governance, employee security and data privacy awareness and training, relevant access and end-point security, vulnerability management, penetration testing, security monitoring and incident response, and recovery from operational disruption.
We use technologies to optimize our security risk detection and response capabilities, in addition to access controls and anti-malware protections.
+Added: Data protection technology is deployed and monitored.
We believe our practices align with the NIST Cybersecurity Framework in meeting and exceeding the industry average in cybersecurity practice.
+Added: When we engage third parties, we have policies and processes to assess and govern their access and services, and manage the related risks affecting Brookfield's information and technology.
+Added: For example, all third-party access must be authorized and have a legitimate business need.
+Added: Prior to authorization and granting access, the terms and conditions of such access must be agreed to as part of a formal agreement or contract.
+Added: In addition, all authorized third-party access must be limited, monitored and controlled as appropriate.
In addition, all employees regularly undergo mandatory continuing cybersecurity training.
3 unchanged sentences
In 2025, we undertook the following initiatives:
−Removed: further enhanced our data protection and threat-intelligence capabilities;
−Removed: improved our processes for third-party risk management ;
−Removed: continued mandatory cybersecurity education for all employees;
−Removed: and incorporated social engineering to our phishing simulations.
−Removed: When we engage third parties, we have policies and processes to govern their access and reduce the risks associated with their access.
−Removed: For example, all third-party access must be authorized and have a legitimate business need.
−Removed: Prior to authorization and granting access, the terms and conditions of such access must be agreed to as part of a formal agreement or contract.
−Removed: In addition, all authorized third-party access must be limited, monitored and controlled as appropriate.
+Added: completed a complex network transition to Secure Access Service Edge (SASE) network technology with enhanced zero-trust based security implemented globally;
+Added: further enhanced our vulnerability management and attack surface reduction capabilities;
+Added: continued improving our data protection by implementing ransomware protected backup technology;
+Added: continued mandatory cybersecurity education and increasingly difficult phishing simulations for all employees.
Our systems face cybersecurity risks, and we have in the past experienced threats to our data and systems.
3 unchanged sentences
Risk Factors—Failure to maintain the security of our information and technology systems could have a material adverse effect on us”.
−Removed: Our principal executive office is located at Brookfield Place, 250 Vesey Street, 15th Floor, New York, NY.
+Added: Our principal executive office is located at Brookfield, 225 Liberty Street, 8th Floor, New York, NY.
We also lease space for our other offices in North America, South America, Europe, Middle East, and Asia-Pacific.
We consider these facilities to be suitable and adequate for the management and operations of our business.
+Added: LEGAL PROCEEDINGS
+Added: For a discussion of BAM's legal proceedings, see the section entitled “Litigation” appearing in Note 21, “Commitments and Contingencies” in BAM's consolidated financial statements included elsewhere in this report, which is incorporated herein by reference.
+Added: MINE SAFETY DISCLOSURES
+Added: Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.