14 unchanged sentences
Enterprise-wide training is a vital component to reducing risk and protecting customers, employees and company information.
−Removed: We expect all Delta employees to adhere to information security and privacy policies as they handle corporate and customer information in their daily jobs.
+Added: We expect all Delta employees and third-party contractors to adhere to information security and privacy policies as they handle corporate and customer information in their daily jobs.
As a result, we require all employees and contractors with access to Delta’s information to complete annual training, which is updated as new technology, security and privacy issues emerge.
All new employees are required to complete training within 30 days of hire.
−Removed: We also regularly conduct other training and employee education activities, including through awareness programs and campaigns.
−Removed: We engage with assessors, consultants, auditors and other third parties, including by regularly having a third party review our overall cybersecurity program to help identify areas for continued focus, improvement and/or compliance.
+Added: We also conduct, at least annually, other training and employee education activities, including through awareness programs and campaigns.
+Added: We engage assessors, consultants, auditors and other third parties to perform assessments of our cybersecurity program with the intent to identify areas for continued improvement, as well as to ensure ongoing compliance with regulatory requirements to which we are subject.
In connection with certain regulatory requirements, we are required to engage third parties to assess our cybersecurity controls.
4 unchanged sentences
We perform diligence on third parties, particularly those that have access to our systems, data or facilities that house such systems or data, and continually monitor cybersecurity threat risks identified through such diligence.
−Removed: Additionally, we generally require those third parties that could introduce significant cybersecurity risk to us to agree by contract to manage their cybersecurity risks in specified ways, and to agree to be subject to cybersecurity audits, which we conduct as appropriate.
+Added: Additionally, we generally require those third parties that could introduce significant cybersecurity risk to us to agree by contract to manage their cybersecurity risks in specified ways, and to agree to be subject to cybersecurity audits.
We regularly test our incident response processes through table-top exercises to ensure they continue to be effective as our business and the cybersecurity threat landscape evolve.
7 unchanged sentences
As reflected in the Audit Committee’s charter, the Board has specifically delegated responsibility for oversight of cybersecurity matters to the Audit Committee as part of its review of our ERM framework.
−Removed: The Audit Committee regularly receives updates on cybersecurity risks and the security and operations of our information technology systems from our Chief Information Officer and our Chief Information Security Officer.
−Removed: In 2023, the Audit Committee received briefings on information security matters at all of its regular meetings.
−Removed: In addition, our Chief Information Officer, our Chief Information Security Officer, other members of our information technology leadership team and an outside legal expert on cybersecurity matters held a special session with all members of our Board of Directors to provide an overview of the information security environment.
+Added: The Audit Committee receives updates on cybersecurity risks and the security and operations of our information technology systems from our Chief Information Officer and our Chief Information Security Officer at least twice per year with additional updates as requested by the Chair of the Audit Committee.
+Added: In 2024, the Audit Committee received updates on information security matters at two of its regular meetings.
+Added: In addition, our Chief Information Officer, our Chief Information Security Officer, other members of our information technology leadership team provided a general overview of information technology matters, including cybersecurity, in a special session with all members of our Board of Directors.
In addition to information provided in these meetings, members of our Board also have access to internal and external education on cybersecurity risks.
25 unchanged sentences
A350-900 24 — 11 35 4.9 9 10
+Added: A350-1000 — — — — — 20 —
B-717-200 48 32 — 80 23.3 — —
9 unchanged sentences
The following table summarizes the aircraft operated by regional carriers on our behalf at December 31, 2024.
−Removed: In 2023, we retired all remaining CRJ-200 aircraft from service.
Regional aircraft information by fleet type and carrier
7 unchanged sentences
Total 16 158 11 132 317
−Removed: (1) We own 190 and have operating leases for three of these regional aircraft.
+Added: (1) We own 195 and have operating leases for two of these regional aircraft.
The remainder are owned or leased by SkyWest Airlines, Inc.
or Republic Airways, Inc.
−Removed: (2) Excluded from the total operating count above are nine CRJ-700 and five CRJ-900 which are owned and temporarily parked as of December 31, 2023.
+Added: (2) Excluded from the total operating count above are nine CRJ-700 and one CRJ-900 which are owned and temporarily parked as of December 31, 2024.
(3) Endeavor Air, Inc.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.