3 unchanged sentences
We are committed to protecting the security and integrity of our systems, networks, databases and applications and, as a result, have implemented processes designed to prevent, assess, identify, and manage material risks associated with cybersecurity threats .
−Removed: Liberty’s corporate level IT and cybersecurity functions assess, identify, and manage risks from cybersecurity threats at the corporate level, while Formula 1 and QuintEvents operate their own cybersecurity functions with oversight from Liberty.
−Removed: Live Nation, an equity affiliate, as a separate publicly traded company from Liberty, operates its own cybersecurity function.
−Removed: Oversight for Live Nation’s cybersecurity functions rests with its board of directors, of which an employee of Liberty is a member, in collaboration with Live Nation’s Global Data Governance Board and Audit Committee.
+Added: Liberty’s corporate level IT and cybersecurity functions assess, identify, and manage risks from cybersecurity threats at the corporate level, while Formula 1 and MotoGP operate their own cybersecurity functions with oversight from Liberty.
Cybersecurity risks are assessed as part of our enterprise risk assessment and risk management program and our cybersecurity risk management program is designed and assessed based on recognized frameworks, including the National Institute of Standards and Technology Cybersecurity Framework.
2 unchanged sentences
To manage and mitigate material risks from cybersecurity threats to our information systems and data, we implement and maintain various technical, physical and organizational measures, processes and policies.
−Removed: These measures include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, Security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity awareness and training, phishing tests, and penetration testing.
−Removed: Cybersecurity awareness training is also made available annually to our Board of Directors.
−Removed: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level, Formula 1 and QuintEvents.
+Added: These measures
+Added: include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, Security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity awareness and training, phishing tests, and penetration testing.
+Added: Cybersecurity awareness training is also made available to our Board of Directors.
+Added: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level, Formula 1 and MotoGP.
These frameworks are a set of coordinated procedures and tasks that our incident response teams execute with the goal of ensuring timely and accurate identification, resolution and reporting of cybersecurity incidents both internally and externally, as necessary.
4 unchanged sentences
As of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition.
−Removed: For additional information on our cybersecurity risks, see “ The degradation, failure or misuse of the Company’s information systems could cause a disruption of services or improper loss, use and disclosure of personal data or other
−Removed: confidential information, resulting in increased costs, liabilities or loss of revenue.
+Added: For additional information on our cybersecurity risks, see “ The degradation, failure or misuse of the Company’s information systems could cause a disruption of services or improper loss, use and disclosure of personal data or other confidential information, resulting in increased costs, liabilities or loss of revenue.
" in Part I, Item 1A of this Annual Report on Form 10-K.
7 unchanged sentences
Role of Management
−Removed: We have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Facilities departments .
+Added: We have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Technology departments .
The ISSC has management oversight responsibility for assessing and managing technology and operational risk, including information security, fraud, vendor, data protection and privacy, business continuity and resilience, and cybersecurity risks at the corporate level and our subsidiaries.
At Formula 1, the Head of Information Security, together with the Director of IT, are responsible for day-to-day management and oversight of subsidiary cybersecurity, including assessing, monitoring and mitigating cybersecurity risk as well as regular reporting to Formula 1 executive management and the ISSC .
+Added: At MotoGP, the Cybersecurity Manager, together with the Director of IT and Head of Technology, are responsible for similar cybersecurity risk oversight and program management.
Liberty and Formula 1 have also established a Risk and Compliance Committee responsible for overseeing and monitoring all corporate compliance initiatives at Formula 1, including cybersecurity.
1 unchanged sentence
The Head of Information Security provides quarterly updates to the Risk and Compliance Committee on cybersecurity risks and initiatives as well as any cybersecurity events, as applicable.
−Removed: Our management team’s experience includes a diverse background in telecom, technology, media and other industries, with decades of experience in various aspects of cybersecurity.
−Removed: Liberty’s Head of Cybersecurity has more than 25 years of cybersecurity and IT experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications.
−Removed: Formula 1’s Head of Information Security and Director of IT together have more than 30 years of experience and the Head of Information Security has multiple certifications, including Certified Information Security Manager and Certified Information Systems Security Professional.
−Removed: All have worked at a variety of companies, including large publicly traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, business applications, customer facing applications and customer payment systems.
+Added: Liberty and MotoGP are in the process of establishing a similar Risk and Compliance Committee for MotoGP.
+Added: Our management team’s experience includes a diverse background in telecom, technology, media, sports and other industries, with decades of experience in various aspects of cybersecurity.
+Added: Liberty’s Head of Cybersecurity has more than 15 years of cybersecurity, technology and risk management experience.
+Added: Formula 1’s Head of Information Security and Director of IT together have more than 30 years of cybersecurity and technology experience.
+Added: MotoGP’s Cybersecurity Manager and Director of IT together have more than 40 years of cybersecurity and technology experience.
+Added: All have worked at a variety of companies, including large publicly traded companies, where they advised on, implemented and managed IT and cybersecurity programs and teams, developed tools and processes to protect internal and cloud networks, business applications, customer facing applications and customer payment systems.
+Added: The team members who support Liberty, Formula 1 and MotoGP’s information security functions also have extensive relevant education, professional certifications and industry experience .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.