3 unchanged sentences
As a result, our systems and operations as well as those of the third parties on which we rely to conduct certain key functions are vulnerable to cybersecurity incidents, which we have experienced in the past.
−Removed: We have a cybersecurity program that includes physical, technological, and administrative controls to detect, contain, respond to and remediate cybersecurity threats and incidents and defined processes to assess, identify and manage material risks from cybersecurity threats.
+Added: Although no organization can eliminate cybersecurity and information technology risk completely, w e have a cybersecurity program that includes physical, technological, and administrative controls designed to detect, contain, respond to and remediate cybersecurity threats and incidents and defined processes to assess, identify and manage material risks from cybersecurity threats.
These controls and processes include, among others:
1 unchanged sentence
• establishing an offensive security team that actively tests our security controls, imitating methods persons trying to achieve unauthorized access might use to identify any weaknesses;
−Removed: • our global privacy program supported by our privacy engineering and privacy legal teams and the Privacy Advisory Council, a cross functional team of senior leaders from legal, engineering, product, and compliance;
−Removed: • maintaining an incident response plan which includes required responses in the event of a cybersecurity incident;
−Removed: • conducting mandatory annual security and privacy training for all employees and contractors and, where appropriate, giving employees and contractors role-based training focused on content specific to their role at the Company;
+Added: • our global privacy program supported by our privacy engineering and privacy legal teams;
+Added: • maintaining an incident response plan which outlines the roles and responsibilities of key personnel in the event of a cybersecurity incident;
+Added: • conducting mandatory annual security and privacy training for employees and contractors and, where appropriate, giving employees and contractors role-based training focused on content specific to their role at the Company;
• undertaking an annual review of our consumer facing policies and statements related to cybersecurity;
−Removed: • requiring employees to treat customer information and data with care through policy, practice and contract (as applicable);
−Removed: • leveraging the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”) incident handling framework to help us identify, protect, detect, respond, and recover when there is an actual or potential cybersecurity incident;
−Removed: • carrying information security risk insurance that provides protection against the potential losses arising from a cybersecurity incident.
+Added: • requiring our employees to treat customer information and data with care through policy, practice and contract (as applicable);
+Added: • carrying cybersecurity insurance that provides some protection against potential losses arising from a cybersecurity incident.
Our cybersecurity program is managed by the Company’s Security and Corporate Engineering organization, which is led by our CSO , who reports directly to the CEO.
−Removed: Currently, our CSO is Erika Dean.
−Removed: Dean, who joined the Company in 2021, has over twenty years of experience in the security industry.
−Removed: Prior to joining our Company, she held a variety of leadership positions in cybersecurity at Capital One, including as Vice President, Divisional Chief Information Security Officer.
−Removed: Additionally, several of Robinhood’s subsidiaries, including RHC, RHF, and RHS, have a Chief Information Security Officer, who reports to the CSO, and a Risk Operating Committee (“ROC”) that manages risks, including cybersecurity risks, specific to each entity.
−Removed: The Chief Information Security Officers have expertise in cybersecurity, industry and regulatory standards, risk management, and security operations.
−Removed: The Security organization elevates risks to the ROCs where applicable.
+Added: Our CSO has over twenty years of experience in the security industry and has held a variety of leadership positions in cybersecurity at Capital One, including as Vice President, Divisional Chief Information Security Officer.
+Added: Additionally, several of Robinhood’s subsidiaries, including RHC, RHF, and RHS, have a Chief Information Security Officer, who reports to the CSO, and a Risk Operating Committee (“ROC”) that manages risks, including cybersecurity risks, specific to each entity’s business.
+Added: Each of our Chief Information Security Officers has expertise in cybersecurity, industry and regulatory standards, risk management, and security operations.
+Added: The Security organization elevates risks to the relevant ROCs where applicable.
Our cybersecurity program is aligned with industry standards and best practices, such as the NIST CSF, and we engage third-party consultants annually to conduct a NIST CSF maturity assessment of our cybersecurity program.
−Removed: We maintain a Third Party Security and Privacy Policy and conduct security reviews of vendors, including for potential fourth-party risks, prior to and during their contracts with Robinhood and require all third-party service providers with access to personal, confidential or proprietary information to implement and maintain comprehensive cybersecurity practices consistent with applicable legal standards and industry best practices.
+Added: We maintain a Third Party Security and Privacy Standard and conduct security reviews of vendors, including for potential fourth-party risks, prior to and during their contracts with Robinhood and require all third-party service providers with access to personal, confidential or proprietary information to implement and maintain cybersecurity practices consistent with applicable legal standards and industry standards.
Any identified security or privacy risks of doing business with a vendor, including potential fourth-party risks, are highlighted to business owners to help make informed risk-based decisions.
1 unchanged sentence
Services provided by third-party consultants include, but are not limited to:
−Removed: regular assessments to our cybersecurity program including cyber maturity assessments and penetration tests;
+Added: regular assessments of our cybersecurity program including cyber maturity assessments and penetration tests;
risk scoring of our critical business partners and vendors;
and participating in incident response processes.
−Removed: Management is responsible for day-to-day risk operations and management processes.
+Added: Our management is responsible for the Company’s day-to-day risk operations and management processes.
Management has established cybersecurity standards to improve the Company’s cybersecurity risk posture and to help define and implement appropriate measures to protect the Company’s systems and data from cyber threats.
−Removed: In addition to our Internal Audit and Compliance functions, the Company has a management ERC, which comprises senior leaders of the Company, including the CEO, CFO, CLO, CSO, Vice President of Risk and Audit, and CBO, among others, and reviews on at least a quarterly basis risks that are escalated by the Company’s ERM function, including cybersecurity risks.
−Removed: ERM maintains a risk taxonomy and a scoring methodology design to ensure risks are elevated in a clear and transparent manner, and further escalates top risks to the Safety Committee, along with planned mitigants and monitoring procedures.
−Removed: If a cybersecurity incident occurs, incident response procedures are in place to ensure that the occurrence is appropriately reported to the CSO, and business continuity plans are mobilized to minimize disruption to business operations.
−Removed: We have also implemented guidelines to outline communications responsibilities during incidents of all severity levels, including the escalation process for alerting senior management of high severity incidents.
+Added: In addition to our Internal Audit and Compliance functions, the ERM team partners with various front-line risk teams and risk owners across Robinhood, to foster consistent risk management practices across Robinhood.
+Added: In particular, the ERM team provides
+Added: governance over risk management practices and reports on a quarterly basis on top risks to the Safety Committee, along with planned mitigants and monitoring procedures.
+Added: If a cybersecurity incident occurs, incident response procedures are in place to facilitate the appropriate reporting to the CSO, and business continuity plans are mobilized to minimize disruption to business operations.
+Added: We have also implemented guidelines to outline communications responsibilities during incidents of all severity levels, including an escalation process for alerting senior management of high severity and material incidents.
If a significant cybersecurity incident occurs, we will conduct an assessment to determine if it is material to us.
−Removed: If a materiality assessment is required, the CSO will report such an incident to our Materiality Assessment Committee (“MAC”), which consists of the CFO, CLO, and CBO (in addition to the CSO).
−Removed: The MAC will then determine, without unreasonable delay, whether the incident is material to the
+Added: If a materiality assessment is required, the CSO will report such an incident to our Materiality Assessment Committee (“MAC”), which consists of the CFO, CLO, and CBO (in addition to the CSO) and notify the CEO.
+Added: The MAC will then determine, without unreasonable delay, whether the incident is material to the Company.
In making such determination, the MAC may consult with the CEO, other members of the Company’s management, and the Company’s outside professional advisors, in each case, as appropriate.
6 unchanged sentences
and competitiveness.
−Removed: The principal role of our board of directors and the Safety Committee is one of oversight, recognizing that management is responsible for the design, implementation, and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks.
+Added: The principal role of our board of directors and the Safety Committee, a board-level committee composed solely of independent directors, is one of oversight, recognizing that management is responsible for the design, implementation, and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks.
The Safety Committee reviews management’s exercise of its responsibility to identify, assess, manage, monitor and mitigate material risks not specifically allocated to the board of directors or another of its committees.
The Safety Committee has been explicitly assigned the responsibility to oversee risks from cybersecurity threats, among others, and the full board of directors will be notified when the MAC is assessing a cybersecurity incident and informed of any required disclosures.
−Removed: Our board of directors and Safety Committee receive updates on relevant industry developments, threats, and material risks identified as needed each quarter.
−Removed: The board of directors and the Safety Committee also receive updates, including material legal and legislative developments, concerning data privacy and security, the rapidly evolving cybersecurity risk landscape, and the Safety Committee facilitates the board of directors’ oversight responsibilities.
+Added: Our board of directors and Safety Committee receive updates on relevant industry developments, threats, and material risks identified as needed each quarter , including material legal and legislative developments, concerning data privacy and security, the rapidly evolving cybersecurity risk landscape, and the Safety Committee facilitates the board of directors’ oversight responsibilities.
Our systems and those of our customers and third-party service providers have been and might in the future be vulnerable to cybersecurity threats.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.