2 unchanged sentences
Risk Management and Strategy
−Removed: Atlanta Braves Holdings’ corporate level information technology (“IT”) and cybersecurity functions are provided by Liberty as part of the services agreement described in Item 1.
−Removed: Through the services agreement, we participate in Liberty’s processes for assessing, identifying, and managing risks from cybersecurity threats at the corporate level, as detailed below.
−Removed: Braves Holdings operates its own cybersecurity function with oversight from Atlanta Braves Holdings.
−Removed: We are committed to protecting the security and integrity of our systems, networks, databases and applications and, as a result, have implemented processes designed to prevent, assess, identify, and manage material risks associated with cybersecurity threats .
+Added: Due to the utilization of technology, Atlanta Braves Holdings is subject to material risks from cybersecurity threats.
+Added: Accordingly, we have committed to protecting the security and integrity of our systems, networks, databases and applications and, as a result, have implemented processes designed to prevent, assess, identify, and manage material risks associated with cybersecurity threats .
Cybersecurity risks are assessed as part of our enterprise risk assessment and risk management program and our cybersecurity risk management program is designed and assessed based on recognized frameworks, including the National Institute of Standards and Technology Cybersecurity Framework.
2 unchanged sentences
To manage and mitigate material risks from cybersecurity threats to our information systems and data, we implement and maintain various technical, physical and organizational measures, processes and policies.
−Removed: These measures include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity
−Removed: awareness and training, phishing tests, and penetration testing.
−Removed: Cybersecurity awareness training is also made available annually to our board of directors.
−Removed: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level and at Braves Holdings.
+Added: These measures include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity awareness and training, phishing tests, and penetration testing.
+Added: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place to respond in a timely and appropriate manner.
These frameworks are a set of coordinated procedures and tasks that our incident response teams execute with the goal of ensuring timely and accurate identification, resolution and reporting of cybersecurity incidents both internally and externally, as necessary.
4 unchanged sentences
As of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition.
−Removed: For additional information on our cybersecurity risks, see “ Data loss or other breaches or disruptions of our information systems and information system security could materially harm our business and results of operations." in Part I, Item 1A of this Annual Report on Form 10-K.
+Added: For additional information on our cybersecurity risks, see “ Data loss or other breaches or disruptions of our information systems and information system security could materially harm our business and results of operations." in Part I, Item 1A – “Risk Factors” of this Annual Report on Form 10-K.
Role of the Board of Directors
Our board of directors has overall responsibility for risk oversight and has delegated to the Audit Committee primary enterprise risk oversight responsibility, including privacy and cybersecurity risk exposures, policies and practices, the steps management takes to detect, monitor and mitigate such risks and the potential impact of those exposures on our business, financial results, operations and reputation.
−Removed: The Audit Committee receives quarterly updates on the enterprise risk management program, including cybersecurity risks and the initiatives undertaken to identify, assess and mitigate such risks.
+Added: The Audit Committee receives quarterly updates on the enterprise risk management program the CESC (as defined below) including cybersecurity risks and the initiatives undertaken to identify, assess and mitigate such risks.
This cybersecurity reporting may include threat and incident reporting, vulnerability detection reporting, risk mitigation metrics, systems and security operations updates, employee education initiatives, and internal audit observations, if applicable.
3 unchanged sentences
Role of Management
−Removed: Through our services agreement with Liberty discussed in Item 1 of this Annual Report on Form 10-K, we have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Facilities departments.
−Removed: The ISSC has management oversight responsibility for assessing and managing technology and operational risk, including information security, fraud, vendor, data protection and privacy, business continuity and resilience, and cybersecurity risks at the corporate level and at Braves Holdings.
−Removed: At Braves Holdings, the Senior Vice President (“SVP”) and Head of Technology, together with the Director Cybersecurity and IT Infrastructure, is responsible for day-to-day management and oversight of subsidiary cybersecurity, including assessing, monitoring and mitigating cybersecurity risk.
−Removed: The SVP and Head of Technology provides regular reporting to Braves Holdings executive management and the ISSC.
−Removed: Braves Holdings has also established a Security Executive
−Removed: Steering Committee, which is composed of a cross functional group of executive management and technical team members, including the Chief Financial Officer, Chief Legal Officer, Baseball Assistant General Manager, Vice President Security, SVP and Head of Technology, and Director Cybersecurity and IT Infrastructure.
−Removed: The Security Executive Steering Committee meets at least quarterly and has primary management oversight responsibility for assessing and managing information security, data protection and privacy, and cybersecurity risks.
−Removed: Atlanta Braves Holdings and Braves Holdings have also established a Compliance Committee responsible for overseeing and monitoring all corporate compliance initiatives at Braves Holdings, including cybersecurity.
−Removed: The Compliance Committee is composed of members of Liberty’s ISSC as well as the Braves Holdings executive leadership team, including the President and Chief Executive Officers of the Baseball and Development divisions, Chief Financial Officer and Chief Legal Officer.
−Removed: The Head of Information Security provides periodic updates to the Compliance Committee on cybersecurity risks and initiatives as well as any cybersecurity events, as applicable.
+Added: We have established a cross functional Cybersecurity Executive Steering Committee (“CESC”) led by our Senior Vice President (“SVP”) and Head of Technology Services, Chief Legal Officer, Chief Financial Officer and other executives from our Legal, Accounting, Cybersecurity and Facilities departments.
+Added: The CESC meets at least quarterly and has primary management oversight responsibility for assessing and managing information security , data protection and privacy, and cybersecurity risks.
+Added: Our SVP and Head of Technology Services, together with the Director Cybersecurity and IT Infrastructure, is responsible for day-to-day management and oversight of our cybersecurity, including assessing, monitoring and mitigating cybersecurity risk.
+Added: The SVP and Head of Technology Services provides regular reporting to Braves Holdings executive management, the CESC and the Audit Committee.
+Added: A Compliance Committee has also been established and is responsible for overseeing and monitoring all corporate compliance initiatives at Braves Holdings, including cybersecurity.
+Added: The Compliance Committee is composed of members of the CESC as well as the Braves Holdings executive leadership team, including the President and Chief Executive Officers of the Baseball and Development divisions, Chief Financial Officer and Chief Legal Officer.
+Added: The SVP and Head of Technology Services provides periodic updates to the Compliance Committee on cybersecurity risks and initiatives as well as any cybersecurity events, as applicable.
Our management team’s experience includes a diverse background in telecom, financial services and other industries, with decades of experience in various aspects of technology and cybersecurity.
−Removed: Liberty’s Head of Cybersecurity has more than 25 years of cybersecurity and information technology experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications.
−Removed: Braves Holdings’ SVP and Head of Technology has more than 20 years of leadership experience, including delivering technology solutions and designing and building new business strategies and Braves Holdings’ Director Cybersecurity and IT Infrastructure has more than 20 years of cybersecurity and information technology experience and is a Certified Information System Security Professional.
+Added: Our SVP and Head of Technology Services has more than 30 years of leadership experience, including delivering technology solutions and designing and building new business strategies in regulated businesses and our Director Cybersecurity and IT Infrastructure has more than 20 years of cybersecurity and information technology experience and is a Certified Information System Security Professional.
Together this management team has worked at a variety of companies, including large publicly traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, business applications, customer facing applications and customer payment systems.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.