10 unchanged sentences
Collectively, the GIS team has decades of dedicated cybersecurity experience with personnel certified in various disciplines, including data privacy, enterprise risk management, cloud security and ethical hacking.
−Removed: While the full board of directors has overall responsibility for risk oversight, for cyber security matters, it is supported by its Audit Committee, which regularly reports to the full board of directors .
−Removed: The Audit Committee assists the board of directors in monitoring cybersecurity risk by receiving quarterly reports and as needed updates from the Chief Information Officer and the CISO, that cover, among other things, our information security framework, threat assessment, response readiness and training efforts.
+Added: While the full board of directors has overall responsibility for risk oversight, for cybersecurity matters, it is supported by its Audit Committee, which regularly reports to the full board of directors .
+Added: The Audit Committee assists the board of directors in monitoring cybersecurity risk by receiving quarterly reports and as needed updates from the Chief Information Officer and the CISO, that cover, among other things, our information security framework, risk mitigation procedures, threat assessment, response readiness and cybersecurity training efforts.
Hilton has adopted a Cybersecurity Policy that requires all employees to immediately report a potential cybersecurity incident to the GIS team, and all employees are required to certify their understanding of the Cybersecurity Policy on an annual basis.
2 unchanged sentences
The GIS team leverages several mechanisms to continuously identify and assess cybersecurity risks across the Company and utilizes a GRC platform to monitor identified risks and mitigation and remediation activities.
−Removed: The GIS team uses defined industry accepted risk management and controls frameworks to determine the potential likelihood and impact of each risk.
+Added: The GIS team uses defined industry accepted risk management and controls frameworks to determine the likelihood and potential impact of each risk.
Monitoring activities are designed and executed based on the materiality of the assessed likelihood and magnitude of impact of the risks that are identified.
2 unchanged sentences
In the event of a reported potential cybersecurity incident, a first response team, which includes leaders of the GIS team, other members of management and the legal team, determines without undue delay whether it is a QCI as defined in the CIRP.
−Removed: If an incident is determined to be a QCI, the process included in the CIRP is initiated and such incident is communicated to the designated leadership team, including Hilton's general counsel.
+Added: If an incident is determined to be a QCI, the defined process included in the CIRP is initiated and such incident is communicated to the designated leadership team, including Hilton's general counsel.
Further, appointed leaders collaborate on determining if the incident is material, as well as the resulting response, including any legal and financial reporting obligations of the Company.
−Removed: Information also is provided to additional members of senior management as appropriate.
−Removed: The remediation plan for the QCI is entered within Hilton's GRC platform and monitored and reviewed at least monthly to ensure effective implementation;
+Added: Information is also provided to additional members of senior management as appropriate.
+Added: The remediation plan for the QCI is entered within Hilton's GRC platform and monitored regularly and reviewed at least monthly to ensure effective implementation;
depending upon the type of incident, additional reporting may be produced and monitored by the GIS team to ensure the effectiveness of the remediation plan.
4 unchanged sentences
However, as discussed under "Part I—Item 1A.
−Removed: Risk Factors," specifically the risks titled "Failures in, material damage to or interruptions in our information technology systems, software or websites, including as a result of cyber-attacks on our systems or systems operated by third parties that provide operational and technical services to us, costs associated with protecting the integrity and security of personal data and other sensitive information and difficulties in updating our existing software or developing or implementing new software could have a material adverse effect on our business or results of operations" and "Cyber-attacks could have a disruptive effect on our business," the sophistication of cyber threats continues to increase, and the preventative actions we take to reduce the risk of cyber incidents and protect our systems and information may be insufficient.
+Added: Risk Factors," specifically the risks titled "Failures in, material damage to or interruptions in our information technology systems, software or websites, including as a result of cyber-attacks on our systems or systems operated by third parties that provide operational and technical services to us, costs associated with protecting the integrity and security of personal data and other sensitive information and difficulties in updating our existing software or developing or implementing new software could have a material adverse effect on our business or results of operations" and "Cyber-attacks could have a disruptive effect on our business," the sophistication of cyber threats, including those perpetrated through the use of AI, continues to increase, and the preventative actions we take to reduce the risk of cyber incidents and protect our systems and information may be insufficient.
Accordingly, no matter how well designed or implemented our controls are, we will not be able to anticipate all security breaches, and we may not be able to implement effective preventive measures against such security breaches in a timely manner.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.