7 unchanged sentences
We aim to conduct our cybersecurity program in accordance with current recognized global policies and standards for cybersecurity and information technology.
−Removed: These processes are managed by our cybersecurity team headed by our CISO and supported by our business continuity teams.
+Added: These processes are managed by our cybersecurity team headed by our CISO and CIO and supported by our business continuity teams.
We conduct periodic internal and external vulnerability audits and assessments and penetration testing and provide periodic cybersecurity training to employees.
4 unchanged sentences
Risks are identified based on a four-tier system, and tiers are assigned based on the service impact, user impact, financial impact, and security impact that a threat may pose.
−Removed: Our processes include
−Removed: steps to recover our systems and information through established and tested system recovery plans and business continuity plans, each based on the appropriate response associated with the corresponding tier of the identified threat.
+Added: Our processes include steps to recover our systems and information through established and tested system recovery plans and business continuity plans, each based on the appropriate response associated with the corresponding tier of the identified threat.
Our incident response process includes steps to notify key incident management team members who are responsible for communicating with regulatory and other governmental authorities about cybersecurity events as applicable and as required by law.
7 unchanged sentences
Board Governance and Management
−Removed: Our global cybersecurity processes are managed primarily by our CISO, whose experience includes approximately 25 years of service in roles relating to assessing, managing and providing oversight for cybersecurity risks at public and private entities;
−Removed: our CIO, whose experience includes managing the technology professionals and processes at public and private financial services companies;
−Removed: and our CFO, whose experience includes risk management and specialized financial knowledge.
+Added: Our global cybersecurity processes are managed primarily by our CISO, whose experience includes approximately 20 years of service in roles relating to assessing, managing and providing oversight for cybersecurity risks at public and private entities, our CIO, whose experience includes managing the technology professionals and processes at public and private financial services companies, beginning in December 2024, our global CIO, whose experience includes approximately 40 years of service in financial services and technology, and our CFO, whose experience includes risk management and specialized financial knowledge.
Pursuant to the Audit Committee charter, the Audit Committee oversees the management of the Company’s risk management process, including the identification, prioritization, assessment and management of risks related to cybersecurity.
15 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.