6 unchanged sentences
• risk assessments to help mitigate material cybersecurity risks to our critical systems, information, services, and our broader enterprise IT environment;
−Removed: • a team comprised of IT security, IT infrastructure, and IT compliance personnel principally responsible for directing (1) our cybersecurity risk assessment processes, (2) our security processes, and (3) our response to cybersecurity incidents;
+Added: • a team composed of IT security, IT infrastructure, and IT compliance personnel principally responsible for directing (1) our cybersecurity risk assessment processes, (2) our security processes, and (3) our response to cybersecurity incidents;
• the use of external cybersecurity service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes;
4 unchanged sentences
• cybersecurity insurance to cover certain expenses in the event of a cybersecurity incident.
−Removed: The cybersecurity team reports to the Chief Information Officer and in January 2024, we hired a Chief Information Security Officer (“CISO”) with significant experience in leading cybersecurity teams to assume the leadership of management’s responsibilities and governance discussed below.
+Added: The cybersecurity team reports to the Chief Information Officer (“CIO”) and in January 2024, we hired a Chief Information Security Officer (“CISO”) with significant experience in leading cybersecurity teams to assume the leadership of management’s responsibilities and governance discussed below.
We evaluate our cybersecurity risk management processes and continue to integrate our procedures into our overall enterprise risk management program, which shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas.
4 unchanged sentences
We rely on, and in certain cases require, our third parties to communicate such incidents timely.
−Removed: As previously disclosed, on September 14, 2023, we announced that an unauthorized actor had gained access to our information technology network as a result of a social engineering attack on an outsourced IT support vendor used by the Company, and acquired a copy of, among other data, our loyalty program database (“Data Incident”).
+Added: As previously disclosed , on September 14, 2023, we announced that an unauthorized actor had gained access to our information technology network as a result of a social engineering attack on an outsourced IT support vendor used by the Company, and acquired a copy of, among other data, our loyalty program database, which includes driver’s license numbers and/or social security numbers for a significant number of members in the database (“Data Incident”).
After detecting suspicious activity in our information technology network, we activated our IRP, which included containment measures, and commenced an investigation of the incident.
10 unchanged sentences
Our Board considers cybersecurity risk as critical to the enterprise and is responsible for reviewing our cybersecurity risk profile, including management’s design, implementation and enforcement of our cybersecurity risk management program.
−Removed: The Board of Directors receives periodic updates from our Chief Information Officer (“CIO”) on cybersecurity risks and threats.
−Removed: Board members also receive periodic presentations on cybersecurity topics from our CIO, supported by our internal security staff, or external experts as part of the Board’s continuing education on topics that impact public companies.
+Added: The Board of Directors receive periodic updates and presentations on cybersecurity topics from our CISO , supported by internal security staff and/or external experts, as part of the Board’s continuing education on topics that impact public companies.
The Board has determined that retaining responsibility for risks related to cybersecurity oversight is appropriate, given the complexity of the risks associated with cybersecurity and the attention required to appropriately review and monitor such risks.
The full Board lends its collective experience and attention to discussing and overseeing potential risks identified by management and stays up to date on management’s risk-mitigation processes related to cybersecurity.
−Removed: Our CIO supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which include briefings from internal security personnel;
+Added: Our CISO is responsible for assessing and managing our material risks from cybersecurity threats and has the primary responsibility for leading our overall cybersecurity risk management program, supervising both our internal cybersecurity personnel and external cybersecurity service providers.
+Added: Our CISO has over 20 years global large-scale cybersecurity experience in managing and leading IT and cybersecurity teams.
+Added: Members of the cybersecurity team hold various credentials and certificates with respect to information systems and they participate in continuing education.
+Added: Our CISO also supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which include briefings from internal security personnel;
threat intelligence and other information obtained from governmental, public or private sources, including external cybersecurity service providers;
and alerts and reports produced by security tools deployed in the IT environment.
−Removed: Our CIO is responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: Our CIO has the primary responsibility for leading our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our external cybersecurity service providers.
−Removed: Our CIO has significant global experience in managing and leading IT and cybersecurity teams.
−Removed: Members of the cybersecurity team hold various credentials and certificates with respect to information systems and they participate in continuing education.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.