23 unchanged sentences
Our workforce is required to complete information security training annually, and we periodically communicate ways to recognize and avoid cybersecurity threats to our workforce.
−Removed: ConocoPhillips 2024 10-K
Engagement of Third Parties
1 unchanged sentence
As part of the cybersecurity incident response process described above, we engage third-party experts as needed to support incident response, such as external legal advisors, cybersecurity forensic firms and other specialists.
+Added: ConocoPhillips 2025 10-K
Third-Party Service Provider Risk Management
6 unchanged sentences
Nevertheless, we recognize cybersecurity threats are on-going and evolving, and our program is designed to identify and manage those threats.
+Added: See I tem 1A.
Risk Factors— Our technologies, systems and networks are subject to cybersecurity threats for more information on our risks relating to our technologies, systems, and networks.
5 unchanged sentences
The CISO reports to the CD&IO, who holds a master’s degree in information technology and has served as Chief Information Officer/Chief Technology Officer and various roles in information technology for over 29 years.
−Removed: The CD&IO reports to the Executive Vice President and Chief Financial Officer.
+Added: The CD&IO reports to the Executive Vice President, Global Operations and Technical Functions.
This management team assesses and manages risks associated with cybersecurity.
7 unchanged sentences
In addition to this regular reporting, significant cybersecurity risks or threats may also be escalated on an as needed basis to the AFC and Board of Directors .
−Removed: ConocoPhillips 2024 10-K
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.