3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: CRH leverages its Enterprise Risk Management (ERM) framework, which accords with internationally recognized standards, to identify, assess, respond, monitor and report material cybersecurity risks facing the Company.
+Added: CRH leverages its Enterprise Risk Management (ERM) framework, which accords with internationally recognized standards, to identify, assess, respond, monitor, manage, and report material cybersecurity risks facing the Company.
CRH manages cybersecurity risk at multiple levels within the Company.
4 unchanged sentences
CRH’s operating companies and business units implement various risk mitigation strategies, including continuously strengthening security measures, improving incident response plans through post-incident evaluations and assessments, investing in security technologies, providing regular and focused employee training, and transferring risk through cybersecurity insurance.
−Removed: At the Group level, CRH conducts a semi-annual bottom-up risk assessment focused on CRH’s operating companies and business units, including cybersecurity-related risks, which evaluates the impact and likelihood of the identified cyber risks and the effectiveness of existing security measures, policies, and procedures.
+Added: At the Enterprise-level, CRH conducts a semi-annual bottom-up risk assessment focused on CRH’s operating companies and business units, including cybersecurity-related risks, which evaluates the impact and likelihood of the identified cyber risks and the effectiveness of existing security measures, policies, and procedures.
CRH also requires that each operating company completes a self-assessment regarding its cyber controls and risk, including user awareness training, email security protection, multi-factor authentication, system patch management, identity management, network segregation, antivirus and web protections, asset inventory, privileged access management, logging, monitoring, and incident response capabilities.
9 unchanged sentences
These systems would include the use of vendor security questionnaires, vulnerability assessments, and annual audits.
+Added: The Company’s Internal Audit function conducts regular audits of our IT infrastructure and implementation of our Global Information Security Policy and related significant internal cyber initiatives as part of our governance, risk, and compliance framework.
+Added: These internal audits include a structured assessment of the design and implementation of IT and security controls and assess the operation of our Information Security Management Systems (ISMS).
+Added: The internal audit program evaluates the effectiveness of technical, operational, and administrative security controls, and identifies opportunities for continual improvement.
CRH has not been subject to a cyber-attack that has had a material impact on our operations or financial results .
5 unchanged sentences
The Audit Committee is currently made up of six independent directors with a range of relevant cybersecurity, information technology, and operational technology experience.
−Removed: The Audit Committee receives updates at least annually from the Chief Information Security Officer (CISO) on the design and progress of key information security initiatives in addition to regular briefings on cybersecurity and management of cybersecurity-related risks from relevant members of management, including the Head of ERM and our CISO.
−Removed: Recent updates from the CISO have focused on the Company’s information security strategy, ongoing security assessments and ongoing projects.
+Added: Board-level responsibility for overseeing information security is further supported by our Cyber Security Council, which provides strategic direction, governance, and oversight of all information security matters.
+Added: The Council operates with senior management representation and regularly reviews cyber‑risk, compliance obligations, and our security performance.
+Added: This governance structure aims to ensure that information security priorities, risks, and improvements are consistently aligned with organizational objectives and regulatory expectations.
+Added: The Audit Committee receives updates at least annually from the Chief Information Security Officer (CISO) on the design and progress of key information security initiatives in addition to regular briefings on cybersecurity and management of cybersecurity-related risks from relevant members of management, including the Head of ERM and the CISO.
+Added: Recent updates from the CISO have focused on cyber transformation, threats and trends, security assessments, cyber resilience initiatives, and awareness and training.
The Audit Committee is responsible for updating the Board on identified risks related to cybersecurity.
1 unchanged sentence
CRH has established the role of CISO to provide technical leadership on a day-to-day basis in assessing and managing the Company’s material cybersecurity risks and liaising with the chief information officers of CRH’s Divisions.
−Removed: Our CISO has 25 years of experience working in IT, including more than a decade spent in prior technical and senior management roles related to cybersecurity.
+Added: The CISO has 25 years of experience working in IT, including more than a decade spent in prior technical and senior management roles related to cybersecurity.
+Added: CRH FORM 10-K
The Divisional chief information officers have in excess of 20 years of experience, on average, in IT-related and cybersecurity-related roles and, together with the CISO, hold a variety of recognized and specialized credentials related to cybersecurity and IT.
5 unchanged sentences
The Risk Committee and Global Leadership Team are briefed on the occurrence, mitigation, and remediation of cybersecurity incidents on a regular basis, including ad-hoc briefings covering significant or potentially material incidents.
−Removed: CRH Form 10-K 20
−Removed: The Risk Committee, which is made up of our Chief Financial Officer, Group General Counsel, Chief Operating Officer and the Divisional Presidents of CRH Americas and CRH International, is the executive oversight body for risk management, including cybersecurity risks and the work of the CISO, GIS and related teams.
+Added: The Risk Committee, which is made up of our Chief Financial Officer, Chief Legal and Corporate Affairs Officer, Chief Operating Officer, and the Divisional Presidents of CRH Americas and CRH International, is the executive oversight body for risk management, including cybersecurity risks and the work of the CISO, GIS and related teams.
The Risk Committee meets quarterly with the Head of ERM to assess risks facing CRH, and, on an as-needed basis, meets with other members of CRH management regarding cybersecurity risks and developments.
−Removed: The Risk Committee also reviews the half-yearly risk updates that are provided to the Audit Committee prior to dissemination.
+Added: The Risk Committee also reviews the semi-annual risk updates that are provided to the Audit Committee prior to dissemination.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.