7 unchanged sentences
We maintain multiple levels of protection to mitigate data security risks, and we regularly test our systems to discover and address potential vulnerabilities, including without limitation:
+Added: 2025 Form 10-K | H&R Block, Inc.
• using a multi-layered, zero-trust principled approach to secure systems;
4 unchanged sentences
• security and business controls to appropriately limit access to and use of personal information, including adaptive and multifactor authentication;
−Removed: 2024 Form 10-K | H&R Block, Inc.
• comprehensive data protections, including encryption, to facilitate the secure storage, use, and transmission of sensitive data;
5 unchanged sentences
Risks associated with cybersecurity threats are a top priority for ongoing oversight by the ERM team and the Enterprise Risk Committee.
−Removed: Our Chief Risk Officer oversees the activities of the Enterprise Risk Committee and, together with the Chief Information Security Officer (CISO), briefs the Audit Committee and the Board of Directors on information security risk matters as a part of regular ERM reports, with a deep dive focused on information security at least annually (or more frequently if appropriate).
−Removed: In addition, the Audit Committee receives regular reports on cybersecurity matters from the Chief Information Officer (CIO) and the CISO.
−Removed: The Board of Directors is also updated by the CIO and CISO on a periodic basis.
−Removed: Our CIO, who reports directly to the President and CEO, has over 30 years of leadership experience in technology-based roles across multiple industries.
−Removed: Our CISO, who reports directly to the CIO, has extensive cybersecurity knowledge and skills gained from over 25 years of information technology experience, with more than 15 years of Information Security specialization.
+Added: Our Vice President, Legal and Corporate Secretary, oversees the activities of the Enterprise Risk Committee and, together with the Chief Information Security Officer (CISO), briefs the Audit Committee and the Board of Directors on information security risk matters as a part of regular ERM reports, with a deep dive focused on information security at least annually (or more frequently if appropriate).
+Added: In addition, the Audit Committee receives regular reports on cybersecurity matters from the Chief Legal and Administrative Officer (CLAO) and the CISO.
+Added: The Board of Directors is also updated by the CLAO and CISO on a periodic basis.
+Added: Our CLAO, who reports directly to the President and CEO, has over 30 years of leadership experience across multiple industries in roles responsible for overseeing and managing risk.
+Added: Our CISO, who reports directly to the CLAO, has extensive cybersecurity knowledge and skills gained from over 30 years of experience in consulting and technology roles, with more than 18 years of Information Security specialization.
Our CISO is responsible for understanding, managing, and communicating cybersecurity risks internally to our management (including the Enterprise Risk Committee on which he serves), and works closely with our Legal department to oversee compliance with legal, regulatory, and contractual security requirements.
3 unchanged sentences
In addition to our internal capabilities, we also periodically engage external consultants, legal counsel, or other third-party advisors to assist with assessing, identifying, and managing cybersecurity risks.
+Added: H&R Block, Inc.
+Added: | 2025 Form 10-K
Material Cybersecurity Risks, Threats, and Incidents
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.