1 unchanged sentence
Not applicable.
−Removed: Fiscal 2024 Form 10-K
Cybersecurity.
6 unchanged sentences
The cybersecurity risk management process and related governance processes are integrated into our broader enterprise risk management framework, which is designed to appropriately identify, prioritize, manage, and oversee risks.
+Added: Cybersecurity risks are reviewed as part of our enterprise risk management processes, with findings integrated into our overall risk management strategy.
Overseeing our cybersecurity efforts on a day-to-day basis is our cybersecurity team, led by our Chief Information Security Officer (“CISO”).
Our cybersecurity team, in partnership with third parties, designs and implements our data security and cybersecurity programs, risk assessments, monitoring procedures, and training programs for our associates.
−Removed: We continue to make investments to enhance our ability to identify, protect from and detect security risks within our environment.
+Added: We continue to make investments to enhance our ability to identify, protect against, detect and respond to security risks within our environment.
Monitoring and Mitigation.
3 unchanged sentences
We maintain a security operations center that is staffed around the clock to detect, mitigate, and respond to cyber threats.
−Removed: In the event we identify a cybersecurity incident, we have defined procedures to respond to and recover from such incident as quickly as possible.
+Added: In the event we identify a cybersecurity incident, we have defined procedures to respond to and recover from the incident as quickly as possible.
Our policies and procedures are reviewed periodically to ensure they remain aligned with current regulatory requirements and the current threat landscape.
1 unchanged sentence
We maintain cybersecurity insurance to help provide protection against losses arising from significant security incidents.
+Added: Fiscal 2025 Form 10-K
The Company has an Incident Response Team (“IRT”), a cross-functional group with the expertise, authority and resources to act quickly, efficiently and appropriately to investigate, coordinate the response to, remediate, and communicate regarding a cybersecurity incident.
−Removed: The IRT uses a detailed incident response plan that outlines and coordinates the actions we take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess the severity of, escalate, contain, investigate, and remediate an incident, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
+Added: The IRT uses a detailed incident response plan that outlines and coordinates the actions we take to prepare for, detect, respond to and recover from cybersecurity incidents.
In addition, our IRT engages in tabletop exercises at least annually to simulate a response to a cybersecurity incident and uses the findings to improve our processes, plans and technologies.
−Removed: We provide data security and privacy awareness and training to all associates upon hire and on an annual basis, with additional customized, role-based training provided to targeted internal audiences.
+Added: We provide data security and privacy awareness training to all associates upon hire and on an annual basis, with additional customized, role-based training provided to targeted internal audiences.
In addition, we conduct periodic awareness campaigns and regular phishing email simulation tests to reinforce our new-hire and annual training and promote ongoing awareness of risks.
1 unchanged sentence
We have a vendor risk management program that works to classify service provider or business partner risk based on several factors, including but not limited to data type accessed and/or retained.
−Removed: Using a risk-based approach, we perform diligence and security risk assessments for certain vendors and service providers and include appropriate obligations in our contractual arrangements.
+Added: Using a risk-based approach, we perform diligence and security risk assessments for certain vendors and service providers and include appropriate cybersecurity and data protection obligations in our contractual arrangements.
Cybersecurity Risks.
−Removed: We have not experienced any material cybersecurity incidents in the past fiscal year.
+Added: We have in the past experienced, and may in the future experience, cybersecurity incidents;
+Added: however, we have not experienced any cybersecurity incidents that we have determined to be material in the past fiscal year.
We face risks from cybersecurity threats that, if realized, may materially affect our business strategy, results of operations or financial condition .
−Removed: Despite our efforts, our cybersecurity risk management processes may not be fully implemented, complied with or effective in preventing or mitigating future cybersecurity risks.
We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or, if realized, are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, in Part I, Item 1A.
“Risk Factors.”
−Removed: Fiscal 2024 Form 10-K
Our efforts to create a secure digital environment start with the governance and oversight of our data security and privacy policies and strategy.
−Removed: At the Board of Directors (the “Board”) level, cybersecurity is overseen by the Board and by the Board’s Audit Committee, which has primary responsibility for overseeing cybersecurity and privacy risks.
−Removed: During fiscal 2024, the Board and/or the Audit Committee received quarterly reports on privacy, data protection and/or cybersecurity matters from senior information technology (“IT”) leaders, including our Chief Information Officer (“CIO”) and CISO, as well as the Chair of our Data Security and Privacy Governance Committee (discussed below).
−Removed: In addition, our Board held a meeting dedicated to cybersecurity topics.
−Removed: Periodically, our Board receives presentations on cybersecurity matters from third-party cybersecurity experts.
−Removed: Our CISO, who reports to our CIO, joined the Company in 2021 after working with the Company as a third-party consultant since 2019.
+Added: At the Board level, cybersecurity is overseen by the Board and the Audit Committee , which has primary responsibility for overseeing data protection, cybersecurity and privacy matters.
+Added: In fiscal 2025, our Board held a session dedicated to cybersecurity and business continuity.
+Added: In addition, since the beginning of fiscal 2025, the Board and/or the Audit Committee have received reports on data protection, cybersecurity and/or privacy matters from senior information technology (“IT”) leaders, including our Chief Information Officer (“CIO”), CISO, Chief Privacy Officer, and the Chair of our Data Security and Privacy Governance Committee (discussed below).
+Added: Periodically, our Board receives presentations on these matters from third-party experts.
+Added: Our CISO, who reports to our CIO, joined the Company in 2021 after working with the Company as a third-party consultant beginning in 2019.
During a nearly two-decade tenure at a leading professional services firm, he worked with clients on managing information security, developing cybersecurity strategy, and implementing effective information and cybersecurity programs and initiatives addressing emerging cybersecurity threats.
1 unchanged sentence
He holds a Bachelor of Science degree in Information Systems and has achieved several relevant certifications, including Certified Information Security Manager, Certified Information Systems Security Professional, and Certified Information Privacy Professional.
−Removed: Our CISO leads a team of over 500 associates focused on cybersecurity.
+Added: Our CISO leads a team of associates focused on cybersecurity.
We have three management-level committees that support our cybersecurity, privacy and data governance efforts.
−Removed: They are led by our Data Security and Privacy Governance Committee, which provides management-level governance over cybersecurity matters, including discussion of cybersecurity priorities, emerging risks, awareness and training programs, risk mitigation efforts, and regulatory compliance.
+Added: They are led by our Data Security and Privacy Governance Committee, which provides management-level governance over cybersecurity and privacy matters, including discussion of cybersecurity and privacy priorities, emerging risks, awareness and training programs, risk mitigation efforts, and regulatory compliance.
This committee is chaired by our Vice President – Internal Audit and Corporate Compliance and is composed of a cross-functional team of senior leaders, including our CEO.
1 unchanged sentence
The activities of the Data Security and Privacy Governance Committee are reported to the Board or the Audit Committee by the Chair of the committee, as appropriate .
+Added: Fiscal 2025 Form 10-K
The Security and Technology Risk Leadership Committee provides leadership and oversight of our cybersecurity program.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.