3 unchanged sentences
Risk Management and Strategy
−Removed: We depend on IT and OT for various operations, including refinery processes, petroleum movement monitoring in pipelines and terminals, point-of-sale processing at our retail sites, and other critical processes and transactions.
+Added: We depend on IT and OT for various operations, including refinery processes, petroleum movement monitoring in pipelines and terminals, and other critical processes and transactions.
We utilize IT and OT systems across our operations to capture accounting, technical and regulatory data for archiving, analysis, and reporting.
1 unchanged sentence
Additionally, our technology encompasses a company-wide network through which employees have access to key business applications.
−Removed: We established a thorough, risk-based cybersecurity program aimed at safeguarding our data, along with the data of our customers and partners.
+Added: We maintain and continually enhance a comprehensive, risk-based cybersecurity program aimed at safeguarding our data, along with the data of our customers and partners.
The identification, assessment, and management of cyber risks fall under our Enterprise Risk Management (“ERM”) program, overseen by the Board of Directors.
−Removed: Our Chief Technology Officer & Digital Officer/Chief Information Officer holds overall responsibility for IT, OT, and cybersecurity.
−Removed: Delek follows well-organized cybersecurity frameworks with a Chief Information Security Officer dedicated to overseeing cybersecurity initiatives throughout the entire enterprise.
+Added: Our Chief Technology & Data Officer holds overall responsibility for IT, OT, and cybersecurity.
+Added: Delek follows recognized cybersecurity frameworks with a Chief Information Security Officer dedicated to overseeing cybersecurity initiatives throughout the entire enterprise.
Our risk assessment process related to cybersecurity includes identifying threats and conducting vulnerability assessments, likelihood and impact assessments related to our own information and OT systems as well as our third-party service providers.
5 unchanged sentences
Our security approach also includes multiple layers of defense and testing of controls.
−Removed: We have implemented security measures, including segmentation, firewalls, intrusion detection systems, encryption, multi-factor authentication and data loss prevention to safeguard our systems and data.
+Added: We have implemented security measures, including segmentation, firewalls, intrusion detection systems, encryption, multi-factor authentication and data loss prevention designed to safeguard our systems and data.
Furthermore, we have reinforced our data protection capabilities by investing in both hardware and software.
−Removed: Recognizing that humans are often the most vulnerable element of even the most secure computer architectures, Delek has increased the frequency and sophistication of the mandatory training and phishing campaign program for our employees.
+Added: Recognizing that humans are often the most vulnerable element of even the most secure computer architectures, Delek conducts mandatory security awareness programs, including required training and phishing campaigns for our employees.
Delek also conducts monthly reviews of global cybersecurity incidents to ensure that appropriate mitigation measures are in place to guard against similar threats.
Delek is committed to enhancing its organizational resilience through a multiyear, comprehensive incident response tabletop drill program.
−Removed: Building upon the success of the two drills conducted in 2023, we are dedicated to continuous improvement and proactive readiness in addressing potential challenges and ensuring the effective management of incidents.
−Removed: Delek has not experienced a significant cybersecurity breach or associated expenses, penalties, or settlements for years ended December 31, 2023, 2022 and 2021.
−Removed: Delek continuously assesses and enhances the confidentiality, integrity, and availability of our IT and OT assets.
+Added: Building upon the success of the drill conducted in 2024 and previous years, we remain committed to continuous improvement and proactive preparedness in addressing potential challenges and effectively managing incidents.
+Added: Delek has not experienced a significant cybersecurity breach or associated expenses, penalties, or settlements for the years ended December 31, 2024, 2023 and 2022.
+Added: Delek continuously assesses and enhances the confidentiality, integrity, and availability of its IT and OT assets.
Board of Directors Oversight
2 unchanged sentences
In overseeing cybersecurity risks, the Board of Directors follows the principles identified by the National Association of Corporate Directors in the oversight of cybersecurity risks.
−Removed: Cybersecurity risks and Company programs are discussed with the Board of Directors by the Chief Technology & Digital Officer Chief Information Officer and others.
+Added: Cybersecurity risks and Company programs are discussed with the Board of Directors by the Chief Technology & Data Officer and others.
Third parties are periodically engaged in the assessment of cybersecurity, including evaluating maturity under the National Institute for Security and Technology’s and the International Society of Automation/ International Electrotechnical Commission’s cybersecurity frameworks, testing informational and operational cyber defenses, controls, and reviews of policies and procedures.
5 unchanged sentences
Management Oversight
−Removed: Our senior leadership team is actively involved in cybersecurity governance, ensuring the highest level of oversight of cybersecurity risks.
+Added: Our senior leadership team is actively involved in cybersecurity governance, providing oversight of cybersecurity risks at the highest levels of our organization.
Establishing clear lines of ownership and accountability, along with regular and transparent communication among our standing Board committees, the Board of Directors and executives, is crucial for effectively handling cybersecurity risks and opportunities.
−Removed: Our Chief Technology & Digital Officer/Chief Information Officer reports to the Chief Executive Officer, dedicating a substantial amount of their efforts to ensure the safety and security of our networks and systems.
−Removed: Our Chief Technology & Digital Officer/Chief Information Officer has nearly 20 years of IT experience including areas of technology, cybersecurity, data, analytics, and digital transformation as well as being an Adjunct Lecturer at Tel-Aviv University and the Technion for Big Data Technologies, Data Science and Data Visualization.
−Removed: Representing the state of Israel at MIT’s CDOIQ forum.
−Removed: Our Chief Technology & Digital Officer oversees a team of security professionals and regularly updates the Board of Directors on any potential risks and threats to the Company.
−Removed: Senior leadership including our Chief Technology & Digital Officer/Chief Information Officer and the Chief Information Security Officer brief the Board on information security matters multiple times throughout the year.
+Added: Our Chief Technology & Data Officer reports to the Chief Executive Officer, dedicating a substantial amount of their efforts to ensure the safety and security of our networks and systems.
+Added: Our Chief Technology & Data Officer has nearly 20 years of IT experience including areas of technology, cybersecurity, data, analytics, and digital transformation as well as being an Adjunct Lecturer at Tel-Aviv University and the Technion for Big Data Technologies, Data Science and Data Visualization.
+Added: Our Chief Technology & Data Officer oversees a team of security professionals and regularly updates the Board of Directors on any potential risks and threats to the Company.
+Added: Senior leadership including our Chief Technology & Data Officer and the Chief Information Security Officer brief the Board on information security matters multiple times throughout the year.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.