1 unchanged sentence
CYBERSECURITY
−Removed: Our ability to attract and retain customers, efficiently operate our businesses, execute our DRIVE transformation, including Network 2.0, and compete effectively increasingly depends in part upon the sophistication, security, and reliability of our technology network, including our ability to provide features of service that are important to our customers, to protect our confidential business information and the information provided by our customers, and to maintain customer confidence in our ability to protect our systems and to provide services consistent with their expectations.
+Added: Our ability to attract and retain customers, efficiently operate our businesses, execute our transformation initiatives, and compete effectively increasingly depends in part upon the sophistication, security, and reliability of our technology network, including our ability to provide features of service that are important to our customers, to protect our confidential business information and the information provided by our customers, and to maintain customer confidence in our ability to protect our systems and to provide services consistent with their expectations.
Cybersecurity Risk Management and Strategy
3 unchanged sentences
Leveraging components from multiple industry frameworks and best practices such as the International Organization for Standardization (“ISO”) 27001 and National Institute of Standards and Technology (“NIST”) standards, including the NIST Cybersecurity Framework, our cybersecurity program prioritizes governance, identification, protection, detection, response, and remediation measures.
+Added: FedEx increasingly utilizes artificial intelligence-enabled technologies (“AI”) within its operations and also evaluates risks associated with the use of AI by third-party vendors and service providers.
+Added: AI-related security and governance risks are considered as part of FedEx’s broader cybersecurity and enterprise risk management processes.
+Added: These considerations include, among other factors, risks related to data integrity, model governance, access controls, third-party dependencies, and the potential misuse of AI-enabled systems.
+Added: We have an AI policy to support the responsible use of AI technologies in our operations, with a focus on enhancing business effectiveness while managing ethical, legal, cybersecurity, data privacy, and other technology-related risks.
+Added: We also established an AI Council comprised of a cross-functional group of employees to support the responsible evaluation, governance, and use of AI technologies across the enterprise.
We regularly assess our cybersecurity program’s capabilities and tools to help us enhance reliability and scan our environment for vulnerabilities.
5 unchanged sentences
Compliance with regulatory requirements involves regular third-party assessments.
−Removed: Our processes are also designed to address cybersecurity risks associated with third-party service providers, including risk assessment and due diligence during selection and oversight.
−Removed: Key third parties undergo regular assessments to gauge cybersecurity control effectiveness, with heightened review of those with access to non-public data.
+Added: Our processes are also designed to address cybersecurity risks associated with third-party service providers, including risk assessment and due diligence during selection and oversight of activities throughout the vendor lifecycle.
+Added: Key third parties undergo regular assessments to gauge cybersecurity control effectiveness, with heightened review of those with access to non-public data or critical systems.
We regularly conduct table-top simulation exercises to test our cybersecurity incident response processes with the aim of enhancing effectiveness against evolving threats.
Our incident response procedures guide our preparedness, detection, response, and recovery actions.
−Removed: In the last three fiscal years to date, we have not identified any risks from cybersecurity threats or become aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business, results of operations, or financial condition.
+Added: In the last four fiscal years to date, we have not identified any risks from cybersecurity threats or become aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business, results of operations, or financial condition.
While we have significant security processes and initiatives in place, we may be unable to detect or prevent a breach or disruption in the future.
For more information about cybersecurity-related risks, please see “ Item 1A.
−Removed: “Risk Factors ” of this Form 10-K.
+Added: Risk Factors ” of this Annual Report.
Cybersecurity Governance
12 unchanged sentences
Separately, through our ERM program, key enterprise risks, including with respect to cybersecurity, are communicated to the Board and its Audit and Finance Committee at least annually, and any significant changes to these risks are reported to the Board and its Audit and Finance Committee.
−Removed: Our CISO, who reports to the Chief Executive Officer, leads our information security team and has management responsibility for overseeing FedEx’s cybersecurity program, including assessing and managing material risks from cybersecurity threats.
−Removed: who has over 25 years of experience at FedEx and has received industry-recognized information security certifications, oversees an information security organization of more than 400 security, risk, and compliance professionals based in the U.S.
+Added: Our CISO, who reports to the Executive Vice President – Chief Digital and Information Officer , leads our information security team and has management responsibility for overseeing FedEx’s cybersecurity program, including assessing and managing material risks from cybersecurity threats.
+Added: The CISO, who has over 25 years of experience at FedEx and has received industry-recognized information security certifications, oversees an information security organization of more than 400 security, risk, and compliance professionals based in the U.S.
and internationally across the FedEx enterprise.
3 unchanged sentences
Both our CISO and other members of our cybersecurity leadership team participate in threat intelligence briefings provided by various government and industry entities.
−Removed: Our CISO reports to the Chief Executive Officer, and the FedEx Executive Committee oversees our business risk, with cybersecurity threat risks being a regular topic of discussion.
+Added: Our Executive Vice President – Chief Digital and Information Officer is a member of the FedEx Executive Committee, which oversees our business risk, with cybersecurity threat risks being a regular topic of discussion.
Our cybersecurity incident response plan includes processes for communicating cybersecurity incidents to relevant levels of management, including the DTRC, Executive Committee, the CyTOC, and the full Board of Directors, as appropriate, and consideration of external reporting and disclosure requirements.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.