5 unchanged sentences
We have implemented cybersecurity policies, procedures, technologies, and controls to aid in our efforts to access, identify, and manage such risks.
−Removed: Material risks from cybersecurity threats are managed across GM, GM Financial, Cruise, service providers such as data processors, third-party suppliers, dealers and vendors, and monitoring such risks and threats are integrated into the Company's overall risk management program .
+Added: Material risks from cybersecurity threats are managed across GM, GM Financial, service providers such as data processors, third-party suppliers, dealers, and vendors, and monitoring such risks and threats are integrated into the Company's overall risk management program .
GM has a Cybersecurity Management Board that brings together representatives from senior management across the Company's Software & Services, Product Development, Information Technology, Manufacturing, Finance, Communications, Human Resources, Legal, and Public Policy organizations to provide guidance and monitor overall company cybersecurity risk.
7 unchanged sentences
From time to time, the Company's processes are audited and validated by internal and external experts.
−Removed: The Company leverages a third-party cybersecurity program with the goal of minimizing disruption to the Company's business and production operations, strengthening supply chain resilience in response to cyber-related events and supporting the integrity of components and systems used in its products and services.
−Removed: GENERAL MOTORS COMPANY AND SUBSIDIARIES
+Added: The Company leverages a third-party risk management process with the goal of minimizing disruption to the Company's business and production operations, strengthening supply chain resilience in response to cyber-related events, and supporting the integrity of components and systems used in its products and services.
When cybersecurity incidents occur, the GM Cybersecurity team's focus is on responding to and containing the threat and minimizing impact.
2 unchanged sentences
Our policies and procedures are reviewed periodically for alignment with regulatory requirements and the threat landscape.
−Removed: In the last three fiscal years, the Company has not experienced any material cybersecurity incidents and expenses incurred from cybersecurity incidents were immaterial (including penalties and settlements, of which there were none).
+Added: The Company has not experienced any material cybersecurity incidents and expenses incurred from cybersecurity incidents were immaterial (including penalties and settlements, of which there were none).
For a discussion of whether and how any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or, if realized, are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition, see Item 1A.
Risk Factors – "Risks related to our intellectual property, cybersecurity, information technology, and data management practices", which are incorporated by reference into this Item 1C.
+Added: GENERAL MOTORS COMPANY AND SUBSIDIARIES
The GM Board of Directors is responsible for overseeing the Company's enterprise risk, and has established its Risk and Cybersecurity Committee with specific responsibility for overseeing our cybersecurity program, among other things.
4 unchanged sentences
The CISO holds a master's degree in information security policy and management, has taught information security courses at the graduate level, is an inventor on cybersecurity-related patents, and has been a speaker at leading cybersecurity conferences.
−Removed: The CISO and the Cybersecurity Management Board monitor the prevention, mitigation, detection and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above, including through the operation of the Company's incident response plans, which include escalation to the Risk and Cybersecurity Committee, as appropriate, and simulated exercises.
+Added: The CISO and the Cybersecurity Management Board monitor the prevention, mitigation, detection, and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above, including through the operation of the Company's incident response plans, which include periodic reports and escalation to the Risk and Cybersecurity Committee, as appropriate, and simulated exercises.
* * * * * * *
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.