2 unchanged sentences
Risk Management and Strategy Disclosure
−Removed: The Company’s Information Security team is responsible for executing the Company’s enterprise-wide cybersecurity strategy, which is based upon the Center for Internet Security’s best practice controls, including providing subject matter expertise, accountability, and oversight in the areas of policy and standards development, security architecture, engineering, and development practices, third-party IT and Security risk, compliance with industry, state, and federal regulations, and security education, awareness, and training.
+Added: The Company’s Information Security team is responsible for executing the Company’s enterprise-wide cybersecurity strategy, which is based upon the Center for Internet Security’s best practice controls, including
+Added: providing subject matter expertise, accountability, and oversight in the areas of policy and standards development, security architecture, engineering, and development practices, third-party IT and Security risk, compliance with industry, state, and federal regulations, and security education, awareness, and training.
The Information Security program is managed and overseen by a full-time Chief Information Security Officer (“CISO”) with over 25 years in information technology leadership, service management, operations, information security, risk management, and regulatory compliance.
13 unchanged sentences
As set forth in the Company’s charter, our Audit Committee, comprised of fully independent directors, is responsible for reviewing with management of the Company, the Company’s policies and practices with respect to risk assessment and risk management, including cybersecurity risk.
−Removed: The CRO reports information and cybersecurity risks through the CRO Risk Assessment Report, a copy of which is provided to the Audit Committee and the Board every quarter.
+Added: The CRO reports information and cybersecurity risks to the Audit Committee.
F&G has adopted a “three lines of defense” governance model for information and cybersecurity risk management.
4 unchanged sentences
The assessment results are presented at quarterly Operational Risk Sub-Committee (“ORSC”) and ERMC meetings.
−Removed: ERM, jointly with the Information Security professionals, annually conducts a Cybersecurity Risk Assessment based on critical security controls set forth by the Center for Internet Security.
+Added: ERM, jointly with the Information Security professionals, annually conducts a Cybersecurity Risk Assessment based
+Added: on critical security controls set forth by the Center for Internet Security.
The assessment is reported to the CRO, CISO and CIO.
1 unchanged sentence
As an added layer of defense, the Company has an incident response team in place to evaluate information and cybersecurity incidents on an on-going basis.
−Removed: Based on materiality, a security incident may be escalated to the Corporate Crisis Management Team (“CCMT”) for risk mitigation and recovery actions.
−Removed: In 2023, the Company’s data was subject to the MoveIt security incident pertaining to a third-party vendor of the Company.
−Removed: The Company activated its crisis management protocols to adequately manage the investigation, impact, and response to this incident.
−Removed: The incident was reported to the Audit Committee of the Board and disclosed to regulatory authorities.
+Added: Based on materiality, a security incident may be escalated to the Corporate Crisis Management Team (“CCMT”) for risk mitigation and recovery action s.
+Added: Cybersecurity Incidents
+Added: F&G did not experience a cybersecurity reporting incident during the year ended December 31, 2024.
+Added: On June 30, 2023, F&G filed a Current Report on Form 8-K regarding a cybersecurity incident associated with the MOVEit file transfer system.
+Added: As a result of this incident, F&G is a defendant in two putative class action lawsuits that allege certain of F&G’s customers’ personal information was disclosed due to a vulnerability in the MOVEit file transfer software.
+Added: F&G’s vendor, Pension Benefit Information, LLC (“PBI”), used the MOVEit software in the course of providing audit and address research services to F&G and many other corporate customers.
+Added: At this time, F&G does not believe the incident will have a material impact on its business, operations, or financial results.
+Added: For more details on these lawsuits, refer to Note N - Commitment and Contingencies to the Consolidated Financial Statements included in Item 8 of Part II of this Annual Report on Form 10-K.
Our headquarters are in leased facilities at 801 Grand Avenue, in Des Moines, Iowa.
−Removed: We also have leased space in Hamilton, Bermuda;
+Added: We also have leased space for our primary operations in Hamilton, Bermuda;
George Town, Cayman Islands;
and New York, New York.
−Removed: We believe our existing facilities are suitable and adequate for our present purposes and will be sufficient for us to conduct our operations.
+Added: We believe our existing facilities are suitable and adequate for our present purposes and operations.
Legal Proceedings
−Removed: See discussion of legal proceedings in Note N - Commitment and Contingencies to the Consolidated Financial Statements included in Item 8 of Part II of this Annual Report on Form 10-K, which is incorporated by reference into this Item 3 of Part I.
+Added: See discussion of legal proceedings in Note N - Commitments and Contingencies to the Consolidated Financial Statements included in Item 8 of Part II of this Annual Report on Form 10-K, which is incorporated by reference into this Item 3 of Part I.
Mine Safety Disclosures
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.