4 unchanged sentences
Dow's comprehensive cybersecurity and information security framework includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and enhanced security with ransomware defense.
−Removed: The framework leverages International Organization for Standardizations 27001/27002 standards for general information technology controls, International Society of Automation/International Electrotechnical Commission standards for industrial automation, the National Institute of Standards and Technology Cyber Security Framework ("NIST CSF") for measuring overall readiness to respond to cyber threats, and Sarbanes-Oxley for assessment of internal controls.
+Added: The framework leverages International Organization for Standardizations 27001/27002 standards for general information technology controls, International Society of Automation/International Electrotechnical Commission standards for industrial automation, the National Institute of Standards and Technology Cyber Security Framework ("NIST CSF") for measuring overall readiness to respond to cybersecurity threats, and Sarbanes-Oxley for assessment of internal controls.
In addition, the Company maintains business continuity and disaster recovery plans as well as a cybersecurity insurance policy.
−Removed: Dow has comprehensive processes to manage cybersecurity risks when engaging with third-party service providers, including reviewing questionnaires and independent quantitative scores of the vendor’s cyber hygiene, maintaining robust controls to address and mitigate significant risks that may arise, and performing ongoing assessments and reviews throughout the duration of the engagement.
+Added: Dow has comprehensive processes to manage cybersecurity risks when engaging with third-party service providers, including reviewing questionnaires and independent quantitative scores of the vendor’s cybersecurity hygiene, maintaining robust controls to address and mitigate significant risks that may arise, and performing ongoing assessments and reviews throughout the duration of the engagement.
Dow has established cybersecurity and information security awareness training programs.
1 unchanged sentence
Training is administered and tracked through online learning modules.
−Removed: Training topics include how to escalate suspicious activities including phishing, viruses, spams, insider threats, suspect human behaviors or safety issues.
+Added: Training topics include how to escalate suspicious activities including phishing, viruses, spams, deep fakes, insider threats, suspect human behaviors or safety issues.
Based on role and location, some employees receive additional in-depth training to provide more comprehensive knowledge on potential risks related to their individual job responsibilities.
Training is supplemented through regular Company communications with frequent updates to educate on the latest adversary trends and social engineering techniques.
−Removed: Additionally, Dow engages in cyber crisis response simulations to assess Dow’s ability to adapt to information and operational technology threats.
+Added: Additionally, Dow engages in cybersecurity crisis response simulations to assess Dow’s ability to adapt to information and operational technology threats.
Improper or illegitimate use of the Company’s information system resources or violation of the Company’s information security policies and procedures is subject to disciplinary action.
−Removed: Dow’s security posture is supported by a comprehensive defense-in-depth strategy that relies on layers of technology including Multi-Factor Authentication and principles of Zero Trust to ensure that access to information and communication is vetted and secure.
+Added: Dow’s security posture is supported by a comprehensive defense-in-depth strategy that relies on layers of technology including, but not limited to, Multi-Factor Authentication and Zero Trust principles to ensure that access to information and communication is vetted and secure.
Dow also utilizes internal and external audits and assessments, vulnerability testing, governance processes over outsourced service providers, active risk management and benchmarking against peers in the industry to validate Dow’s security posture.
5 unchanged sentences
Role of Management
−Removed: Dow’s Information Systems organization is led by Dow’s Chief Information and Digital Officer, who reports to Dow's Chief Operating Officer, and is responsible for administration of the cybersecurity and information security framework and risk management, with oversight by the Audit Committee of the Board.
−Removed: The Company’s Chief Information and Digital Officer has formal education in information technology and more than 30 years of experience in information systems and technology, including as the vice president of Global Information Technology.
−Removed: Prior to joining Dow, the Chief Information and Digital Officer held a variety of leadership roles including vice president of Information Technology at Cargill, Incorporated.
−Removed: The Chief Information and Digital Officer receives
−Removed: regular updates on cybersecurity matters, results of mitigation efforts and cybersecurity incident response and remediation.
+Added: Dow’s information systems organization is led by Dow’s chief information & digital officer, who reports to Dow's chief operating officer, and is responsible for administration of the cybersecurity and information security framework and risk management, with oversight by the Audit Committee of the Board.
+Added: The Company’s chief information & digital officer has formal education in information technology and more than 30 years of experience in information systems and technology, including as the vice president of Global Information Technology at Cargill, Incorporated, prior to joining Dow.
+Added: The chief information & digital officer receives regular updates on cybersecurity matters, results of mitigation efforts and cybersecurity incident response and remediation.
The Company’s management responsible for developing and executing Dow’s cybersecurity policies is comprised of individuals with either formal education and degrees in information technology or cybersecurity, or with experience working in information technology and cybersecurity, including relevant experience in security related industries.
5 unchanged sentences
The CSOC is also responsible for activating the containment and resolution efforts and third-party service providers are engaged where appropriate to support the Company through the resolution of the incident.
+Added: The CSOC reports all cybersecurity incidents to the Company’s Materiality Assessment Team, which includes senior representatives from information technology, finance, legal and other relevant business functions.
+Added: If the Materiality Assessment Team initially assesses that a cybersecurity incident may be material, the CSOC immediately notifies the Cybersecurity Executive Steering Team for final determination of materiality.
+Added: The Cybersecurity Executive Steering Team consists of the chief operating officer;
+Added: chief financial officer;
+Added: chief information & digital officer;
+Added: chief information security officer;
+Added: senior vice president, operations, manufacturing & engineering;
+Added: chief technology & sustainability officer;
+Added: vice president of government affairs;
+Added: and general counsel.
The CSOC escalates incidents with significant impact and pervasiveness to the Company’s Corporate Crisis Management Team for further action.
−Removed: After initial identification, the CSOC monitors all cybersecurity incidents for changes in degree of impact or pervasiveness.
+Added: After initial identification, the CSOC monitors all cybersecurity incidents for changes in degree of impact or pervasiveness to ensure timely escalation and response.
+Added: Decisions of the Cybersecurity Executive Steering Team are communicated through established governance channels, including reporting to the Audit Committee of the Board.
+Added: This process is integrated into the Company’s overall incident response and risk management framework, ensuring alignment between operational response and strategic oversight.
Role of the Board
1 unchanged sentence
The Board is responsible for overseeing overall risk management for the Company, including review and approval of the enterprise risk management approach and processes implemented by management to identify, assess, manage and mitigate risk, at least annually.
−Removed: While the full Board is accountable for cybersecurity and AI risk management, the Board has delegated responsibility for oversight of the Company’s cybersecurity and information security framework and risk management to the Audit Committee of the Board.
−Removed: The Audit Committee receives information and updates at least quarterly and actively engages with senior leaders, including the Chief Information and Digital Officer and Chief Information Security Officer, with respect to the effectiveness of the Company’s cybersecurity and information security framework, data privacy, and risk management.
−Removed: In addition, the Audit Committee receives reports summarizing threat detection and mitigation plans, audits of internal controls, training and certification, and other cyber priorities and initiatives, as well as timely updates from senior leaders on material incidents relating to information systems security, including cybersecurity incidents.
+Added: While the full Board is accountable for cybersecurity and AI risk management and is presented with an annual cybersecurity update, the Board has delegated responsibility for oversight of the Company’s cybersecurity and information security framework and risk management to the Audit Committee of the Board.
+Added: The Audit Committee receives information and updates at least quarterly and actively engages with senior leaders, including the chief information & digital officer and chief information security officer, with respect to the effectiveness of the Company’s cybersecurity and information security framework, data privacy, and risk management.
+Added: In addition, the Audit Committee receives reports summarizing threat detection and mitigation plans, audits of internal controls, training and certification, and other cybersecurity priorities and initiatives, as well as timely updates from senior leaders on material incidents relating to information systems security, including cybersecurity incidents.
The Audit Committee also reviews external firms’ assessments of the Company’s security posture and NIST CSF maturity level.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.