10 unchanged sentences
• a cybersecurity incident response plan and Security Operations Center (SOC) to respond to cybersecurity incidents;
−Removed: • attack and response simulations at the technical level and execute tabletop response exercises at the management level;
+Added: • attack and response simulations at the technical level and executive tabletop response exercises at the management level;
• a third-party risk management process for service providers;
• cybersecurity insurance to cover certain expenses in the event of a cybersecurity incident.
−Removed: The cybersecurity team reports to the Chief Information Officer (“CIO”) and in January 2024, we hired a Chief Information Security Officer (“CISO”) with significant experience in leading cybersecurity teams to assume the leadership of management’s responsibilities and governance discussed below.
+Added: The cybersecurity team reports to the Chief Information Officer (“CIO”) and the Chief Information Security Officer (“CISO”), who has significant experience in leading cybersecurity teams to assume the leadership of management’s responsibilities and governance discussed below.
We evaluate our cybersecurity risk management processes and continue to integrate our procedures into our overall enterprise risk management program, which shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas.
4 unchanged sentences
We rely on, and in certain cases require, our third parties to communicate such incidents timely.
−Removed: As previously disclosed , on September 14, 2023, we announced that an unauthorized actor had gained access to our information technology network as a result of a social engineering attack on an outsourced IT support vendor used by the Company, and acquired a copy of, among other data, our loyalty program database, which includes driver’s license numbers and/or social security numbers for a significant number of members in the database (“Data Incident”).
+Added: As previously disclosed , on September 14, 2023, we announced that an unauthorized actor had gained access to our information technology network as a result of a social engineering attack on an outsourced IT support vendor used by the Company, and acquired a copy of, among other data, our loyalty program database, which includes driver’s license numbers and/or social security numbers for a significant number of members in the database (the “Data Incident”).
After detecting suspicious activity in our information technology network, we activated our IRP, which included containment measures, and commenced an investigation of the incident.
6 unchanged sentences
We have also received inquiries from numerous state regulators related to the Data Incident.
−Removed: We are responding to these inquiries and cooperating fully with regulators.
+Added: We have responded to all such inquiries and have cooperated fully with regulators.
See Note 8 for further discussion.
We face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
−Removed: Our Board considers cybersecurity risk as critical to the enterprise and is responsible for reviewing our cybersecurity risk profile, including management’s design, implementation and enforcement of our cybersecurity risk management program.
+Added: See I tem 1A, “Risk Factors ” for further discussion.
+Added: Our Board considers cybersecurity risk as critical to the enterprise and is responsible for overseeing cybersecurity risk, including management’s design, implementation and enforcement of our cybersecurity risk management program.
The Board of Directors receive periodic updates and presentations on cybersecurity topics from our CISO , supported by internal security staff and/or external experts, as part of the Board’s continuing education on topics that impact public companies.
2 unchanged sentences
Our CISO is responsible for assessing and managing our material risks from cybersecurity threats and has the primary responsibility for leading our overall cybersecurity risk management program, supervising both our internal cybersecurity personnel and external cybersecurity service providers.
−Removed: Our CISO has over 20 years global large-scale cybersecurity experience in managing and leading IT and cybersecurity teams.
+Added: Our CISO has over 20 years of global large-scale cybersecurity experience in managing and leading IT and cybersecurity teams.
Members of the cybersecurity team hold various credentials and certificates with respect to information systems and they participate in continuing education.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.