6 unchanged sentences
Our global cybersecurity processes form the comprehensive framework we utilize for planning, performing, managing, assessing, and improving our security controls as they relate to cybersecurity, and form part of our overall risk management system.
−Removed: We aim to conduct our cybersecurity program in accordance with current recognized global policies and standards for cybersecurity and information technology.
+Added: We aim to conduct our cybersecurity program in accordance with currently recognized global policies and standards for cybersecurity and information technology.
These processes are managed by our cybersecurity team headed by our CISO and CIO and supported by our business continuity teams.
We conduct periodic internal and external vulnerability audits and assessments and penetration testing and provide periodic cybersecurity training to employees.
−Removed: These measures include regular phishing simulations, annual general cybersecurity awareness training and data protection training.
−Removed: We also participate in industry-specific cybersecurity roundtables and professional groups to ensure we remain abreast of industry-wide cybersecurity developments and best practices and thereby enhance our threat identification processes and responses as necessary.
−Removed: Additionally, when engaging with and utilizing third-party vendors and partners for our business, we conduct various oversight assessments, including due diligence and periodic monitoring to identify potential cybersecurity threats associated with our conducting business with such vendors and partners and to ensure any corresponding risk exposure aligns with our business requirements and risk tolerances.
+Added: These measures include regular phishing simulations, annual general cybersecurity awareness training and annual data protection training.
+Added: We also participate in industry-specific cybersecurity roundtables and professional groups to remain abreast of industry-wide cybersecurity developments and best practices and thereby enhance our threat identification processes and responses as necessary.
+Added: Additionally, when engaging with and utilizing third-party vendors and partners for our business, we conduct various oversight assessments, including due diligence and periodic monitoring to identify potential cybersecurity threats associated with our conducting business with such vendors and partners and to deliver any corresponding risk exposure aligns with our business requirements and risk tolerances.
We maintain an incident reporting and escalation process in the event of any observed, detected, or suspected events that we believe may qualify as a cybersecurity incident.
10 unchanged sentences
Board Governance and Management
−Removed: Our global cybersecurity processes are managed primarily by our CISO, whose experience includes approximately 20 years of service in roles relating to assessing, managing and providing oversight for cybersecurity risks at public and private entities, our CIO, whose experience includes managing the technology professionals and processes at public and private financial services companies, beginning in December 2024, our global CIO, whose experience includes approximately 40 years of service in financial services and technology, and our CFO, whose experience includes risk management and specialized financial knowledge.
+Added: Our global cybersecurity processes are managed primarily by our CISO, whose experience includes approximately 20 years of service in roles relating to assessing, managing and providing oversight for cybersecurity risks at public and private entities, our CIO, whose experience includes managing the technology professionals and processes at public and private financial services companies, our global CIO, whose experience includes approximately 40 years of service in financial services and technology management, and our CFO, whose experience includes risk management and specialized financial knowledge.
Pursuant to the Audit Committee charter, the Audit Committee oversees the management of the Company’s risk management process, including the identification, prioritization, assessment and management of risks related to cybersecurity.
While our Board and Audit Committee members have broad experience in risk management and in some cases technological expertise relating to cybersecurity, our CISO and CIO and management teams handle cybersecurity threat management.
−Removed: The CISO and CIO provide the Board and Audit Committee periodic reports regarding the Company’s cybersecurity risks and threats, the status of projects to strengthen our information security systems, assessments of our information security program, and any issues associated with the emerging threat landscape.
+Added: The CISO and CIO provide the Board and Audit Committee with periodic reports regarding the Company’s cybersecurity risks and threats, the status of projects to strengthen our information security systems, assessments of our information security program, and any issues associated with the emerging threat landscape.
In addition, the CISO provides periodic reports to our executive officers, members of the boards of certain of our regulated entities internationally and other members of our senior management as appropriate.
2 unchanged sentences
Although we believe risks from cybersecurity threats have not materially affected our business strategy, results of operations, or financial condition to date, they may in the future, and we continue to closely monitor risks from cybersecurity threats.
−Removed: For additional information on the impact of cybersecurity matters on us, see “Item 1A — Risk Factors — Risks Related to Our IT Systems and Cybersecurity.”
+Added: For additional information on the impact of cybersecurity matters on us, see Part I, “Item 1A — Risk Factors — Risks Related to Our IT Systems and Cybersecurity.”
Disaster Recovery
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.