2 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: FactSet recognizes the importance of identifying, assessing, and managing material risks associated with cybersecurity threats.
−Removed: These risks include, among other things, operational risks, intellectual property theft, fraud, extortion, violation of data privacy or cybersecurity laws, legal and regulatory risks, and reputational risks.
We maintain an information security program with a dedicated internal team that is tasked with leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
1 unchanged sentence
The information security team also oversees the detection, prevention, mitigation and remediation of all cybersecurity incidents.
+Added: Our information security team proactively monitors emerging cyber threat activity to proactively tune and upgrade our cyber capabilities to maintain a robust security posture.
Our information security program is managed by a dedicated Chief Information Security Officer ("CISO") who reports to our Chief Technology Officer, a member of our Executive Leadership Team ("ELT").
−Removed: Our current acting CISO has a graduate degree in computer engineering and has worked in cybersecurity for over a decade.
+Added: Our CISO has a graduate degree in computer engineering and has worked in cybersecurity for over two decades, including at a major financial institution.
The information security team is comprised of approximately 60 employees, with dedicated teams assigned to governance, risk and compliance, identity and access management, strategy and architecture, and analytics and automation.
The team operates from FactSet locations around the world, including offices in the U.S., India, the Philippines and Europe.
−Removed: FactSet's information security and governance framework is guided by International Organization for Standardization ("ISO") 27002 and System and Organization Control ("SOC") 2 Trust Service Criteria.
−Removed: We also have implemented the National Institute of Standards and Technology ("NIST") Cybersecurity Framework.
+Added: FactSet's information security and governance framework is guided by International Organization for Standardization ("ISO") 27001 and System and Organization Control ("SOC") 2 Trust Service Criteria and the National Institute of Standards and Technology ("NIST") Cybersecurity Framework.
Cybersecurity risk management is integrated into our broader Enterprise Risk Management ("ERM") framework.
FactSet's ERM program is designed to identify, prioritize and assess the most significant risks that could impact our ability to achieve our strategic business objectives.
−Removed: ERM activities include conducting enterprise risk assessments to better understand risk exposures, emerging risks, and steps that management has taken to monitor and control such exposures.
−Removed: Our information security leadership team, in concert with our ERM team, reviews our oversight of cybersecurity risks at least annually through our enterprise risk assessment process.
+Added: Our information security leadership team, in concert with our ERM team, reviews our cybersecurity risks each quarter through our enterprise risk assessment process.
FactSet's information security program is grounded in a risk-based approach.
−Removed: Our information security team undertakes various activities to assess, identify, and manage risks from cybersecurity threats, including managing security controls, conducting penetration testing, leading training and tabletop exercises, and conducting internal and external vulnerability assessments.
−Removed: Findings from our internal and external vulnerability assessments are classified using a combination of scores and internal business metrics.
−Removed: Findings are remediated commensurate with the respective risk rating.
−Removed: FactSet's IT Risk Management Policy includes severity-based escalation requirements designed to ensure proper management-level visibility and evaluation of risk issues, regardless of the source of that risk.
+Added: Our information security team undertakes various activities to assess, identify and manage risks from cybersecurity threats, including managing security controls, conducting penetration testing, leading training and tabletop exercises (including an annual tabletop exercise with the ELT), and conducting internal and external vulnerability assessments.
+Added: All FactSet's employees receive mandatory annual cybersecurity training;
+Added: software engineers receive training on secure software development best practices;
+Added: and other ad hoc training is provided to employees on the latest cyber threat landscape.
+Added: In addition, we also perform quarterly "phishing simulations" to test the effectiveness of our security training program.
+Added: FactSet's information security team performs annual penetration testing with leading service providers, to mimic motivated threat actors, to assess the internal and external security posture of the Company.
+Added: Findings from the penetration test and our internal and external vulnerability assessments are classified using a combination of scores and internal business metrics.
We have processes to identify and mitigate cybersecurity risks stemming from our relationships with third parties, including protocols to assess vendors' cybersecurity programs before we engage them and to monitor vendors, once engaged, for ongoing compliance with our cybersecurity standards.
We also have an incident response plan that provides procedures for how we can detect, respond to, and recover from potential cybersecurity incidents, which include processes designed to triage, assess severity, escalate, contain, investigate, and remediate any incident, as well as to comply with any applicable legal obligations and mitigate potential brand and reputational damage.
−Removed: Our information security program is regularly evaluated by internal and external experts with the results of those reviews reported to senior management, including the ELT and the FactSet Board of Directors (the "Board").
+Added: Our information security program is regularly evaluated by internal and external experts with the results of those reviews reported to senior management, including the ELT and the FactSet Audit Committee, and, where appropriate, the Board of Directors (the "Board").
We also actively engage with key vendors, industry participants, and intelligence and law enforcement communities as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures.
The cybersecurity threat landscape is dynamic and volatile and requires significant investment.
−Removed: To date, risks from cybersecurity threats have not materially affected our business strategy, results of operations, or financial condition.
+Added: To date, risks from cybersecurity threats have not materially affected, and we do not believe are reasonably likely to materially affect, our business strategy, results of operations, or financial condition.
As discussed more fully under Item 1A, Risk Factors in this Annual Report on Form 10-K, although our processes are designed to help identify, detect, prevent, respond to, and mitigate cybersecurity risks, cybersecurity threats are rapidly evolving and we may not be able to anticipate, prevent, or detect all such attacks and there is no guarantee that a future cybersecurity incident could not materially affect our business strategy, results of operations, or financial condition.
Cybersecurity Governance
−Removed: Cybersecurity is an important part of our Board's risk management focus.
−Removed: Regular reporting on the results and status of our ERM function, as well as our information security program, is provided to our senior management, including the ELT and the Board.
−Removed: The Board is responsible for overseeing our risk management governance, and our Board, together with its committees, engages with our management team in monitoring Company risks, including cybersecurity and data protection risks.
−Removed: The Audit Committee is responsible for risk oversight, including risks related to cybersecurity threats, and periodically reviews our information security programs, including our cybersecurity efforts.
−Removed: Our CISO regularly updates the Audit Committee on our information security program, providing an overview of risks and trends and addressing topics including our incident response plan, cybersecurity threat developments, and the steps we are taking to respond to these matters.
+Added: Cybersecurity is an important part of our Audit Committee, Board and ELT’s risk management focus.
+Added: The Board coordinates with the Audit Committee for active Board- and Committee-level oversight of the Company’s technology and cyber risk profile, cyber strategies and information security initiatives.
+Added: The Audit Committee monitors management’s responsibility in the area of risk oversight, including cybersecurity risks.
+Added: At each regular meeting, the Audit Committee receives updates from the CISO, regarding trends, emergent risks to our technology infrastructure, major updates on security assessments and threat landscape, and the steps we are taking to respond to these matters.
+Added: The CISO also provides an annual update to the Board , or as may otherwise be required.
+Added: Management has day-to-day responsibility for identifying risks facing FactSet, formulating risk management policies and procedures, managing our key risk exposures on a day-to-day basis and setting the right “tone at the top.” As part of this, the ERM and technology teams, including the CISO, also deliver regular updates to the ELT on cybersecurity and related matters.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.