2 unchanged sentences
Risk Management and Strategy
−Removed: We have programs for assessing, identifying, and managing material risks from cybersecurity threats through the use of a suite of various security programs and tools including, but not limited to, Managed Security Service Provider and Extended Detection and Response monitoring and alerts, internal reporting mechanisms, monitoring tools, detection tools and continuous training.
−Removed: Our information security program undergoes regular evaluations, internal audits and various exercises, including tabletop, penetration, vulnerability testing and simulations.
−Removed: The findings from these activities, including identified security gaps, are integrated into our risk remediation process and subsequently updated across our suite of security tools and applications.
−Removed: Additionally, we conduct annual Payment Card Industry Data Security Standard compliance reviews and third-party penetration testing.
−Removed: Our global cybersecurity team consists of multidisciplinary Information Technology (“IT”) resources from key areas and locales led by our Global Director of Cybersecurity.
−Removed: They are primarily responsible for delivering comprehensive reporting to executive management and auditors, addressing a wide array of cybersecurity threats, assessments, findings and future direction and strategy.
−Removed: Continuous endpoint monitoring is ensured through collaboration with a third-party cybersecurity firm.
−Removed: Rapid response protocols are in place for high or critical severity incidents, involving isolation, segmentation and forensic examination by our cybersecurity team.
−Removed: In addition, we have engaged a dedicated third-party threat hunter to assist in identifying Indicators of Compromise.
−Removed: Our Global Director of Cybersecurity leads a quarterly cybersecurity governance meeting, comprising of all IT teams from our subsidiaries.
−Removed: This meeting serves as a platform to review and discuss ongoing and upcoming security projects, compliance, and regulations.
−Removed: We conduct a comprehensive annual tabletop exercise facilitated by an external cybersecurity specialist.
−Removed: This exercise involves simulating various attack vectors, utilizing our incident response plans and procedures to respond effectively, prevent, block, and remediate potential threats.
−Removed: This exercise also includes preparing for other related potential impacts to the Company, such as business interruptions, business continuity plans, backup strategies, data protection policies and compliance, incident response, third-party forensic and legal assistance, as well as consideration of regulations such as GDPR, CCPA, PCI and other cybersecurity regulations.
−Removed: This tabletop exercise is attended by members from all
−Removed: subsidiaries, including IT management teams as well as finance, legal, insurance, and operations management teams.
−Removed: We believe our holistic approach ensures we are well-prepared and coordinated to handle a range of cybersecurity scenarios.
−Removed: Our annual testing, which is conducted by an industry-leading third-party cybersecurity firm, encompasses external and internal penetration tests, Wi-Fi tests, social engineering and physical access testing for all subsidiaries.
−Removed: We also use a vulnerability management platform to provide comprehensive visibility and tracking of assets to aid us in systematically identifying, measuring and prioritizing cybersecurity and technology risks.
−Removed: We require employees with access to information systems, including all corporate employees, to undertake data protection and cybersecurity training and compliance programs annually.
−Removed: Our third-party information technology vendors are assessed by independent auditors for compliance with System and Organization Controls (“SOC”) 1 and SOC 2.
−Removed: Access to our networks for third-party vendors is limited exclusively to the application related to the services for which they are engaged to provide.
−Removed: We routinely conduct external risk analyses by employing third-party rating tools to assess our vendors, quantifying and prioritizing identified risks based on the number and severity of vulnerabilities.
−Removed: Subsequently, we communicate these risks to our vendors proactively, seeking their collaboration in remediation efforts.
−Removed: We annually purchase cybersecurity risk insurance policies that would help defray the costs associated with a covered cybersecurity incident if it occurred.
−Removed: Our board of directors maintains comprehensive oversight of company-wide risk assessment by conducting in-depth analysis of key risks related to information security, technology and cybersecurity threats.
−Removed: The audit committee of our board of directors oversees, among other things, the adequacy and effectiveness of our internal controls, including internal controls designed to assess, identify, and manage material risks from cybersecurity threats.
−Removed: The audit committee receives quarterly reports on cybersecurity matters, including material risks and threats, from our Chief Information Officer (“CIO”) and our cybersecurity team.
−Removed: In the event of a cybersecurity incident, our Global Director of Cybersecurity or senior Information Technology management will notify our Disclosure Committee in accordance with the escalation criteria set forth by our incident response plan and related processes.
−Removed: Security incidents and events are classified based on severity (Critical, High, Medium), impact, and nature, as outlined in the Incident Response Plan.
−Removed: This classification system assists the cybersecurity team in prioritizing responses, allocating resources efficiently, and effectively managing risks.
−Removed: Our Disclosure Committee is comprised of, among others, our Chief Financial Officer, Chief Growth and Operations Officer, CIO, Senior Vice President of Finance, Executive Vice President and Director of Strategic Planning, Senior Vice President of Investor Relations and Treasurer, Senior Vice President of Legal Counsel, Vice President of Legal Counsel, and the most senior members of the financial reporting, internal audit, financial planning and analysis, and tax functions.
−Removed: Our CIO has over 28 years of experience leading our technology operations and a total of over 40 years of experience in information technology experience in the banking and fashion apparel industries.
−Removed: Our Global Director of Cybersecurity has over 20 years of experience in information technology, including a dedicated focus of more than 6 years in cybersecurity, risk management and compliance and he is a Certified Information Systems Security Professional (“CISSP”) and a Certified Ethical Hacker (“CEH”).
−Removed: Additionally, our Global Director of Cybersecurity currently serves in the role of a governing body member for the New York Evanta CISO community.
−Removed: As of the date of this Form 10-K, we are not aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition and that are required to be reported in this Form 10-K.
−Removed: For further discussion of the risks associated with cybersecurity incidents, see our “Risks Related to Cybersecurity, Data Privacy and Information Technology” contained in Item 1A - Risk Factors of this Annual Report on Form 10-K.
+Added: We have robust programs in place for assessing, identifying and managing material risks from cybersecurity threats.
+Added: Our approach leverages a comprehensive suite of security tools and initiatives, including but not limited to, Managed Security Service Providers, Extended Detection and Response monitoring, internal reporting mechanisms, and advanced detection and monitoring tools.
+Added: Our information security program is continuously evaluated through internal audits and a range of security exercises, including tabletop simulations, penetration testing, vulnerability assessments and red team exercises.
+Added: Identified security gaps from these assessments are systematically integrated into our risk remediation processes and incorporated into our security tools and applications to enhance our overall cybersecurity policies and procedures.
+Added: In addition, we conduct annual Payment Card Industry Data Security Standard compliance reviews and independent third-party penetration testing to ensure our defenses remain resilient and aligned with industry best practices.
+Added: Our global cybersecurity team is composed of multidisciplinary Information Technology (“IT”) professionals from key regions, led by our Global Director of Cybersecurity.
+Added: This team is responsible for providing comprehensive reporting to executive management and auditors, covering cybersecurity threats, assessments, findings and strategic direction for future improvements.
+Added: We ensure continuous endpoint monitoring in collaboration with a third-party cybersecurity firm.
+Added: For high or critical severity incidents, rapid response protocols are in place, including isolation, segmentation and forensic analysis by our cybersecurity team.
+Added: Additionally, we have engaged a dedicated third-party threat hunter to assist in identifying Indicators of Compromise.
+Added: Our Global Director of Cybersecurity leads a quarterly cybersecurity governance meeting, bringing together IT teams from all subsidiaries.
+Added: This meeting serves as a forum to review ongoing and upcoming security initiatives, regulatory compliance and industry best practices.
+Added: We conduct an annual tabletop exercise facilitated by an external cybersecurity specialist.
+Added: This exercise simulates various attack scenarios, testing our incident response plans and procedures to ensure effective threat detection, mitigation and remediation.
+Added: It also evaluates potential business impacts, including business continuity, backup strategies, data protection, compliance, and regulatory requirements such as GDPR, CCPA and PCI.
+Added: Participants include IT leadership, finance, legal, insurance, and operations teams across all subsidiaries, ensuring a coordinated and well-prepared response to cybersecurity threats.
+Added: Our cybersecurity resilience is further strengthened through annual penetration testing performed by a leading third-party firm.
+Added: This assessment includes external and internal penetration testing, Wi-Fi security evaluations, social engineering exercises and physical access testing.
+Added: We leverage a vulnerability management platform to maintain comprehensive asset visibility, systematically identify risks and prioritize remediation efforts.
+Added: Additionally, all corporate employees with system access must complete annual data protection and cybersecurity training to reinforce security awareness and compliance.
+Added: Our third-party IT vendors undergo independent audits to validate their compliance with System and Organization Controls (“SOC”) 1 and SOC 2 standards.
+Added: Vendor access to our networks is restricted to the applications necessary for their services.
+Added: We proactively assess vendor risk using third-party rating tools, quantifying vulnerabilities and engaging vendors in remediation efforts to mitigate potential security threats.
+Added: To further enhance our risk mitigation strategy, we maintain annual cybersecurity insurance policies designed to offset costs associated with covered cybersecurity incidents.
+Added: Our board of directors provides comprehensive oversight of enterprise risk management, including information security, technology and cybersecurity threats.
+Added: The audit committee of our board of directors is responsible for evaluating the adequacy and effectiveness of internal controls, particularly those designed to assess, identify and manage material cybersecurity risks.
+Added: The audit committee receives quarterly cybersecurity reports from the Chief Information Officer (“CIO”) and cybersecurity team, detailing material risks, threats and mitigation efforts.
+Added: In the event of a cybersecurity incident, the Global Director of Cybersecurity or senior IT leadership will escalate the issue to the Disclosure Committee, following the Incident Response Plan’s predefined escalation criteria.
+Added: Security incidents are classified based on severity (Critical, High, Medium), impact, and nature, ensuring efficient risk prioritization, resource allocation and incident response management.
+Added: Our Disclosure Committee includes key executives and senior leadership, including the Executive Vice President, Chief Growth and Operations Officer, Chief Financial Officer, CIO , Senior Vice President of Finance, Senior Vice President of Investor Relations and Treasurer, Senior Vice President of Legal Counsel and Vice President of Legal Counsel .
+Added: Additionally, it comprises senior representatives from financial reporting, internal audit, financial planning and analysis, and tax functions, ensuring a comprehensive approach to risk oversight and compliance.
+Added: Our CIO has over 28 years of experience leading our technology operations and more than 40 years of expertise in information technology, spanning the banking and fashion apparel industries.
+Added: Our Global Director of Cybersecurity has over 20 years of experience in information technology, with a specialized focus of more than seven years in cybersecurity, risk management, and compliance.
+Added: He holds Certified Information Systems Security Professional (“CISSP”) and Certified Ethical Hacker (“CEH”) credentials.
+Added: Additionally, he serves as a governing body member for the New York Evanta CISO community.
+Added: For further discussion of the risks associated with cybersecurity incidents, see our “Risks Related to Cybersecurity, Data Privacy and Information Technology” under “Risk Factors.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.