3 unchanged sentences
As noted above under “Risk Management”, we maintain an information and cybersecurity risk management program, which is led by our CISO and is designed to protect the confidentiality, integrity and availability of critical information and information systems.
−Removed: The program is designed based on the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) ;
+Added: The program is designed based on the NIST CSF ;
provided that t his does not imply that we meet any particular technical standards, specifications or requirements, only that we use the NIST CSF as a guide to help us identify, assess and manage cybersecurity risks relevant to our business.
−Removed: Tabl e of Contents
−Removed: Our cybersecurity risk management program is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas.
+Added: Our cybersecurity risk management program is integrated into our overall ERM program, and shares common methodologies, reporting channels and governance processes that apply across the ERM program to other legal, compliance, strategic, operational, and financial risk areas.
Our cybersecurity risk management program includes:
7 unchanged sentences
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations or financial condition.
−Removed: We face certain ongoing risks from cybersecurity threats such as loss or theft of data, ransomware or other disruptive attacks from financially motivated bad actors, and third party supply chain issues that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: We face certain ongoing risks from cybersecurity threats such as loss or theft of data, ransomware or other disruptive attacks from financially motivated bad actors, and third-party supply chain issues that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, and financial condition.
For further discussion, see “Item 1A.
−Removed: Risk Factors – Risk Management”.
+Added: Risk Factors – Risk Management” and “Item 1A.
+Added: Risk Factors – Cybersecurity, Technology and Vendor Risks”.
Cybersecurity Governance
Our Board of Directors considers cybersecurity risk to be a critical part of its risk oversight function and has delegated to the Risk & Technology Committee primary oversight of cybersecurity and other information technology risks.
−Removed: The Audit Committee also reviews cybersecurity matters are part of its oversight of major financial risk exposures .
−Removed: The Risk & Technology Committee oversees management’s implementation of our cybersecurity risk management program.
−Removed: The Risk & Technology Committee receives regular reports from management on our cybersecurity risks.
+Added: The Audit Committee also reviews cybersecurity matters as part of its oversight of major financial risk exposures .
+Added: The Risk & Technology Committee oversees management’s implementation of our cybersecurity risk management program, and receives regular reports from management on our cybersecurity risks.
In addition, management updates the Risk & Technology Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.
The Risk & Technology Committee periodically reports to the Board of Directors regarding its activities, including those related to cybersecurity.
−Removed: As part of its oversight of major financial risk exposures , the Audit Committee also reviews with management and the Company’s internal and independent auditors the Company’s risk assessments and risk management program, including with respect to cybersecurity.
+Added: As part of its oversight of major financial risk exposures , the Audit Committee also reviews with management and our internal and independent auditors our risk assessments and risk management program, including with respect to cybersecurity.
Board members receive presentations on cybersecurity topics from our CISO or external experts as part of the Board’s continuing education on topics that impact public companies.
−Removed: Our management team, including our CISO, Chief Risk Officer (CRO) and Chief Operational Risk Officer (CORO), is responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: Our management team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Our management team, including our CISO, CRO and CORO, is responsible for assessing and managing our material risks from cybersecurity threats.
+Added: Our management team has primary responsibility for our overall cybersecurity risk
+Added: Tabl e of Contents
+Added: management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
Our CISO works closely with our CRO and CORO, who are responsible for providing effective oversight and challenge to the activities of our CISO.
−Removed: Our CISO, who reports to our Executive Vice President and Chief Technology Officer, has 30 years of cybersecurity, risk and technology experience across the financial services, banking and insurance industries.
−Removed: She maintains both Certified Enterprise Risk Professional (CERP) and Certified Information Systems Auditor (CISA) certifications.
−Removed: She serves on CyberOhio as an advisor to the State of Ohio and is active as a Board member at Ohio University Grid Computing and Emerging Technologies program.
−Removed: She is an active member in several CISO forums.
+Added: Our CISO, who reports to our Executive Vice President and Chief Technology Officer, has 25 years of cybersecurity and information security experience across a number of regulated industries, including financial services, healthcare and defense and national security.
+Added: Our CISO has been a Certified Information System Security Professional (CISSP) for over 20 years and serves on the governing body of various organizations focused on technology and cybersecurity, including as an Advisory Council Member to the Harvard Business Review and a Governing Board Member of Evanta, an organization of peer-CISOs .
Each of our CRO (who reports to our Chief Executive Officer) and CORO (who reports to our CRO) has over 20 years of financial services experience in operations and risk management.
−Removed: Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, and, as appropriate, provides briefings from internal security personnel;
−Removed: threat intelligence and
−Removed: Tabl e of Contents
−Removed: other information obtained from governmental, public or private sources, including external consultants engaged by us;
−Removed: and alerts and reports produced by security tools deployed in the IT environment.
+Added: Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, and, as appropriate, provides briefings from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us, and alerts and reports produced by security tools deployed in the IT environment.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.