1 unchanged sentence
Cybersecurity
−Removed: We regularly assess risks from cybersecurity threats, monitor our information systems for potential vulnerabilities and test those systems pursuant to the our cybersecurity policies, standards, processes and practices, which are integrated into our overall risk management system.
+Added: We regularly assess risks from cybersecurity threats, monitor our information systems for potential vulnerabilities and test those systems pursuant to our cybersecurity policies, standards, processes and practices, which are integrated into our overall risk management system.
We take a risk-based approach to cybersecurity aligned with National Institute of Standards and Technology ("NIST") Cybersecurity Framework principles and have implemented controls throughout our operations that are designed to address cybersecurity threats and incidents.
6 unchanged sentences
We utilize internal and external resources, including leading third-party providers in the cybersecurity prevention, detection and monitoring space, to monitor for cybersecurity threats to our systems and networks and to understand the broader threat environment.
+Added: Vendors and third-party service providers are subject to security assessments and contractual security requirements commensurate with the nature of the services provided and the sensitivity of the data accessed.
Our cybersecurity strategy is guided by prioritized risk, identified areas for improvement based on the NIST Cybersecurity Framework, and emerging business needs.
1 unchanged sentence
We maintain a global incident response plan, coupled with a global continuous monitoring program.
−Removed: This plan and program include incident alerting, comprehensive incident criticality assessments, and escalation processes designed to support our teams, our senior leadership, and the Board.
+Added: We regularly test our incident response plan through tabletop exercises and simulations.
+Added: This plan and program include incident alerting, comprehensive incident criticality assessments, and escalation processes designed to support our teams, our senior leadership, and the GBTG Board.
This escalation process also includes cross-functional materiality determinations and applicable reporting requirements.
−Removed: Our cybersecurity operations team manages all facets of cybersecurity monitoring, coordinating with managed services security providers and internal analysts across the Company.
−Removed: All employees are provided cybersecurity awareness training, which includes topics on our policies and procedures for reporting potential incidents.
+Added: Our cybersecurity operations team manages all facets of cybersecurity monitoring including the deployment of AI-based tools for threat detection and incident triage, coordinating with managed services security providers and internal analysts across the Company.
+Added: All employees are provided cybersecurity awareness training, which includes topics on our
+Added: policies and procedures for reporting potential incidents.
Our cybersecurity team regularly evaluates emerging risks, regulations, and compliance matters and updates applicable policies and procedures accordingly.
−Removed: To date, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and we believe are not reasonably likely to materially affect the Company, including its business strategy, results
−Removed: of operations or financial condition.
+Added: To date, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and we believe are not reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
Refer to “Part I, Item 1A.
−Removed: Risk Factors” for additional description of cybersecurity risks and potential related impacts on the Company, including the risk factor captioned “Cybersecurity attacks or security breaches or incidents impacting our systems or data could adversely affect our ability to operate, could result in personal information and our proprietary information being lost, stolen, made inaccessible, improperly disclosed or misappropriated and may cause us to be held liable or subject to regulatory penalties and sanctions and to litigation (including class action litigation), which could have a material adverse effect on our reputation and business.”
−Removed: The Board , directly and through its committees, oversees our risk management process, including cybersecurity risks and regularly receive presentations and reports from management.
+Added: Risk Factors” for additional description of cybersecurity risks and potential related impacts on the Company, including the risk factor captioned “Cybersecurity attacks, security breaches or incidents impacting our systems or data could adversely affect our ability to operate, could result in personal information and our proprietary information being lost, stolen, made inaccessible, improperly disclosed or misappropriated and may cause us to be held liable or subject to regulatory penalties and sanctions and to litigation (including class action litigation), which could have a material adverse effect on our reputation and business.”
+Added: The Board , directly and through its committees, oversees our risk management process, including cybersecurity risks, and regularly receives presentations and reports from management.
Pursuant to the Risk Management and Compliance Committee Charter, the Risk Management and Compliance Committee of the Board provides compliance oversight of our risk assessment and risk management policies, which include cybersecurity, and receives regular reports and updates on the steps management has taken to monitor and mitigate such exposures and risks.
−Removed: Our Chief Information Security Officer ("CISO"), in coordination with our Chief Technology Officer, is responsible for leading the assessment and management of cybersecurity risks.
+Added: Our Chief Information Security Officer ("CISO"), in coordination with our Chief Information Technology Officer, is responsible for leading the assessment and management of cybersecurity risks.
The current CISO has over 25 years of experience managing robust security programs, including in heavily regulated environments such as financial services.
The CISO possesses extensive experience in information security, risk management, and technology governance, with a strong background in both strategic leadership and technical security operations.
−Removed: The CISO presents to the Risk Management and Compliance Committee on a bi-annual basis concerning our cybersecurity program.
−Removed: We lease our corporate headquarters in London, United Kingdom pursuant to a lease that expires in July 2034.
−Removed: We also lease office space worldwide in various cities and locations.
−Removed: We do not own any real property.
−Removed: We consider these arrangements to be adequate for our present needs.
−Removed: Legal Proceedings
−Removed: We are not currently subject to any material legal proceedings, nor, to our knowledge, is any material legal proceeding threatened against us or any of our officers or directors in their corporate capacity.
−Removed: Mine Safety Disclosures
+Added: The CISO presents twice-per-year to the Risk Management and Compliance Committee on our cybersecurity program.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.