1 unchanged sentence
Cybersecurity
−Removed: We face rapidly evolving and sophisticated threats of breaches of our systems and networks as well as those of our suppliers and third-party service providers.
+Added: We face rapidly evolving and sophisticated threats, which are further amplified by the maturation of AI capabilities, of breaches of our systems and networks as well as those of our suppliers and third-party service providers.
To mitigate this threat to our business, we take a comprehensive approach to cybersecurity and expend corresponding resources on cybersecurity risk management, strategy, and governance.
Risk Management and Strategy
−Removed: We integrate our policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats into our enterprise risk management program based on recognized frameworks and applicable standards.
+Added: We integrate our policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats into our enterprise risk management program, which references aspects of recognized frameworks such as the National Institute of Standards and Technology Cybersecurity Framework and entails assessments against applicable standards such as ISO 27001, SOC 2, PCI, and FedRAMP.
Our cybersecurity program encompasses the key elements described below:
1 unchanged sentence
We employ a cross-functional, risk-based approach to identify and address anticipated and real-time threats to our cybersecurity.
−Removed: Our internal security, risk, and compliance personnel meet regularly to develop strategies for preserving the confidentiality, integrity and availability of corporate, customer, and other third-party information, identifying, preventing and mitigating cybersecurity threats, and effectively responding to cybersecurity incidents.
+Added: Our internal security, risk, and compliance personnel meet regularly to develop strategies for preserving the confidentiality, integrity and availability of corporate, customer, and other third-party information, identifying, preventing and mitigating cybersecurity threats, and effectively responding to cybersecurity events and incidents.
We maintain controls and procedures that are designed to ensure prompt escalation of certain cybersecurity incidents so that decisions regarding public disclosure and reporting of such incidents, if applicable, can be made in a timely manner.
+Added: Our in-house global threat research team, Elastic Security Labs, a team of security engineers, practitioners, and researchers, works to identify and prevent emerging threats, using malware reverse engineering, behavior analytics, data science and AI.
+Added: We use the research generated by Elastic Security Labs and other sources to implement security checks and reviews throughout our product development lifecycle.
Risk Assessment .
3 unchanged sentences
Our cybersecurity program includes a dedicated cybersecurity function led by our Chief Information Security Officer (“CISO”).
−Removed: As part of our cybersecurity function, our Distributed Security Incident Response Team (“DSRT”) administers a program to monitor, detect, investigate, respond to, and escalate management of internal and external cybersecurity threats and incidents.
+Added: As part of our cybersecurity function, our Distributed Security Response Team (“DSRT”) administers a program to monitor, detect, investigate, respond to, and escalate management of internal and external cybersecurity threats and incidents.
The DSRT provides threat intelligence information from internal and external resources to our CISO, broader security and resiliency organization, and relevant business units and functional areas as one source within our risk assessment process.
1 unchanged sentence
We have incident response and recovery plans that we test and evaluate for effectiveness in accordance with industry standards.
−Removed: Third-Party Risk Managemen t.
+Added: Third-Party Risk Management.
We have implemented controls designed to identify and mitigate cybersecurity threats associated with our use of certain third-party service providers.
−Removed: These providers are subject to security risk assessments at the time of onboarding, contract renewal, and upon detection of an increase in risk profile.
+Added: These providers are subject to security risk assessments, including open-source security review procedures, at the time of onboarding, contract renewal, and upon detection of a significant increase in risk profile.
We use a variety of inputs in the risk assessments, including information supplied by providers and third parties.
−Removed: In addition, we require these providers to meet appropriate security requirements, controls and responsibilities and investigate security incidents that have impacted our third-party providers.
+Added: In addition, we require these providers to meet appropriate security requirements, controls and responsibilities, and we investigate security incidents that have impacted our third-party providers.
+Added: Education and Awareness .
+Added: Our policies require each of our employees to contribute to our data security efforts.
+Added: We regularly reinforce with our employees the importance of handling and protecting customer and employee data, including through mandatory annual privacy, security and responsible AI use training to enhance employee awareness of how to detect and respond to cybersecurity threats.
+Added: We also perform periodic phishing tests for groups with critical access.
External Assessments .
1 unchanged sentence
These assessments include information security maturity evaluations, audits, and independent reviews of our information security control environment and operating effectiveness.
−Removed: The results of significant assessments are reported to management, our board of directors, and our Audit Committee.
+Added: The results of significant assessments are reported to management and then summarized for presentation to our Audit Committee and board of directors.
We adjust our cybersecurity processes based on these results.
7 unchanged sentences
The Audit Committee reports quarterly to our board of directors regarding the Audit Committee’s activities in overseeing cybersecurity risk management.
+Added: The Audit Committee generally receives materials, including a cybersecurity scorecard and other materials indicating current and emerging cybersecurity threat risks and describing our ability to mitigate those risks, and discusses such matters with our CISO.
Management’s Role .
Our cybersecurity program efforts are directed by our CISO who, with the support of the Chief Financial Officer, the Chief Product Officer, and the Chief Legal Officer, has the primary responsibility for assessing and managing material cybersecurity risks.
−Removed: The CISO along with these members of our management, acting as a group, drive alignment on security decisions across the Company.
−Removed: The CISO and various members of this group meet quarterly with the Audit Committee to review security performance metrics, identify security risks and review mitigation strategies, and assess the status of approved security enhancements.
−Removed: Our CISO has served in various roles in information technology, information security and risk management for over 28 years, including serving as the Information Security Officer and Chief Security Officer of multiple companies.
+Added: The CISO along with these members of our management, who also have received training and have experience with cybersecurity, acting as a group, drive alignment on security decisions across the Company.
+Added: The CISO and various members of this group generally meet quarterly with the Audit Committee to review security performance metrics, identify security risks and review mitigation strategies, and assess the status of approved security enhancements.
+Added: Our CISO has served in various roles in IT, information security and risk management for over 28 years, including serving as the Information Security Officer and Chief Security Officer of multiple companies.
Although our “Risk Factors” section in this report presents information about the material cybersecurity risks we face, we believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date.
1 unchanged sentence
Although we maintain cybersecurity insurance, the costs related to cybersecurity incidents may not be fully insured.
−Removed: For a discussion of cybersecurity risks affecting our business, see “Item 1A—Risk Factors—Risks Related to our Business and Industry—If we experience a security incident, or unauthorized access to or other unauthorized processing of confidential information, including personal data, otherwise occurs, our software may be perceived as not being secure, customers may reduce the use of or stop using our products, and we may incur significant liabilities.”
+Added: For a discussion of cybersecurity risks affecting our business, see “Item 1A—Risk Factors—Risks Related to our Business and Industry—If we experience a security incident, or if unauthorized access to or other unauthorized processing of confidential information, including personal data, otherwise occurs, our software may be perceived as not being secure, customers may reduce the use of or stop using our products, and we may incur significant liabilities.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.