3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: CRH leverages its Enterprise Risk Management (ERM) framework to identify, assess, respond, monitor and report material cybersecurity risks facing the Company.
+Added: CRH leverages its Enterprise Risk Management (ERM) framework, which accords with internationally recognized standards, to identify, assess, respond, monitor and report material cybersecurity risks facing the Company.
CRH manages cybersecurity risk at multiple levels within the Company.
Given CRH’s wide geographic spread, the frequency and possible scale of acquisition activity, the diversity of the types of IT systems operated by CRH companies and the decentralized nature of its operations, CRH implements an amalgam of centralized and decentralized processes for IT management.
−Removed: Under this model, Company-level management and the management of CRH’s operating subsidiaries and business units share responsibility for cybersecurity management and collaborate on assessing, identifying, and managing material risks.
−Removed: CRH’s operating subsidiaries and business units use a variety of tools and processes to identify and manage material cybersecurity risks.
−Removed: Across the Company, CRH utilizes multiple monitoring tools and practices to identify and detect unusual activities and/or potential cybersecurity incidents, including potential system breaches, and to verify the effectiveness of protective measures.
−Removed: CRH’s operating subsidiaries and business units implement various risk mitigation strategies, including continuously strengthening security measures, improving incident response plans through post-incident evaluations and assessments, investing in security technologies, providing regular and focused employee training, and transferring risk through cybersecurity insurance.
−Removed: At the Group level, CRH conducts a semi-annual bottom-up risk assessment focused on CRH’s operating subsidiaries and business units, including cybersecurity-related risks, which evaluates the impact and likelihood of the identified cyber risks and the effectiveness of existing security measures, policies, and procedures.
−Removed: CRH also requires that each operating subsidiaries completes a self-assessment regarding its cyber controls and risk, including user awareness training, email security protection, multi-factor authentication, system patch management, identity management, network segregation, antivirus and web protections, asset inventory, privileged access management, logging, monitoring, and incident response capabilities.
+Added: Under this model, Company-level management and the management of CRH’s operating companies and business units share responsibility for cybersecurity management and collaborate on assessing, identifying, and managing material risks.
+Added: CRH’s operating companies and business units use a variety of tools and processes to identify and manage material cybersecurity risks.
+Added: CRH utilizes multiple monitoring tools and practices to identify and detect unusual activities and/or potential cybersecurity incidents, including potential system breaches, and to verify the effectiveness of protective measures.
+Added: CRH’s operating companies and business units implement various risk mitigation strategies, including continuously strengthening security measures, improving incident response plans through post-incident evaluations and assessments, investing in security technologies, providing regular and focused employee training, and transferring risk through cybersecurity insurance.
+Added: At the Group level, CRH conducts a semi-annual bottom-up risk assessment focused on CRH’s operating companies and business units, including cybersecurity-related risks, which evaluates the impact and likelihood of the identified cyber risks and the effectiveness of existing security measures, policies, and procedures.
+Added: CRH also requires that each operating company completes a self-assessment regarding its cyber controls and risk, including user awareness training, email security protection, multi-factor authentication, system patch management, identity management, network segregation, antivirus and web protections, asset inventory, privileged access management, logging, monitoring, and incident response capabilities.
As described further below under “Cybersecurity Governance”, CRH’s Board and senior management receive regular briefings on cybersecurity risks facing CRH and are closely involved in identifying cybersecurity risks, developing CRH’s plan for managing such risks, and continuously refining CRH’s cyber defenses in response to the information gathered through the above-mentioned risk assessments.
To manage the risk of a material impact on CRH’s operations or financial performance due to a cybersecurity incident, CRH has implemented a mandatory Cybersecurity Incident Escalation Standard as part of its Company-wide Information Security Policy.
−Removed: This Standard, which is supported by relevant guidelines and procedural documentation, provides a structured approach adapted to the systems of each CRH operating subsidiary and business unit to manage the incident response process through a series of pre-defined phases, including triage, containment, eradication, recovery, and post-incident analysis.
+Added: This Standard, which is supported by relevant guidelines and procedural documentation, provides a structured approach adapted to the systems of each CRH operating company and business unit to manage the incident response process through a series of pre-defined phases, including triage, containment, eradication, recovery, and post-incident analysis.
CRH also provides regular and focused training to aid employees in understanding and complying with relevant Company policies and applicable regulations, including those related to cybersecurity.
14 unchanged sentences
Recent updates from the CISO have focused on the Company’s information security strategy, ongoing security assessments and ongoing projects.
−Removed: The Audit Committee is responsible for updating the full Board on identified risks related to cybersecurity.
−Removed: Our executive leadership team is responsible for CRH’s strategy and governance, including implementation and review of our ERM framework, which has identified cybersecurity as a core risk for CRH.
+Added: The Audit Committee is responsible for updating the Board on identified risks related to cybersecurity.
+Added: Our Global Leadership Team is responsible for the execution of CRH’s strategy and governance, including implementation and review of our ERM framework, which has identified cybersecurity as a core risk for CRH.
CRH has established the role of CISO to provide technical leadership on a day-to-day basis in assessing and managing the Company’s material cybersecurity risks and liaising with the chief information officers of CRH’s Divisions.
4 unchanged sentences
In line with CRH’s Cybersecurity Incident Escalation Standard and supporting guidelines and procedural documentation, incidents that are deemed potentially material to the Company and/or which may lead to the exposure of confidential or sensitive data are immediately escalated to GIS for review and, as necessary, mitigation and remediation actions are taken.
−Removed: GIS and the CISO also review regular attestation reports that are required to be prepared by CRH’s operating subsidiaries and business units regarding cybersecurity incidents that did not meet the threshold for immediate escalation.
−Removed: Following cybersecurity incidents, GIS, in conjunction with members of management of CRH’s operating subsidiaries and business units as necessary, conduct post-incident analysis and exercises designed to strengthen CRH’s cybersecurity practices.
−Removed: The management Risk Committee and broader executive leadership team are briefed on the occurrence, mitigation and remediation of cybersecurity incidents on a regular basis, including ad-hoc briefings covering significant or potentially material incidents.
+Added: GIS and the CISO also review regular attestation reports that are required to be prepared by CRH’s operating companies and business units regarding cybersecurity incidents that did not meet the threshold for immediate escalation.
+Added: Following cybersecurity incidents, GIS, in conjunction with members of management of CRH’s operating companies and business units as necessary, conduct post-incident analysis and exercises designed to strengthen CRH’s cybersecurity practices.
+Added: The Risk Committee and Global Leadership Team are briefed on the occurrence, mitigation and remediation of cybersecurity incidents on a regular basis, including ad-hoc briefings covering significant or potentially material incidents.
CRH Form 10-K 20
−Removed: CRH’s leadership team has also identified the Risk Committee, which is made up of our Chief Financial Officer, Group General Counsel, Chief Operating Officer and the Presidents of CRH Americas and CRH Europe, as the executive oversight body for risk management, including cybersecurity risks and the work of the CISO, GIS and related teams.
+Added: The Risk Committee, which is made up of our Chief Financial Officer, Group General Counsel, Chief Operating Officer and the Divisional Presidents of CRH Americas and CRH International, is the executive oversight body for risk management, including cybersecurity risks and the work of the CISO, GIS and related teams.
The Risk Committee meets quarterly with the Head of ERM to assess risks facing CRH, and, on an as-needed basis, meets with other members of CRH management regarding cybersecurity risks and developments.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.