9 unchanged sentences
The JFI Privacy Policy is also annually reviewed and updated by management to align with industry best practices and state and federal regulatory requirements.
+Added: Part I | Item 1C.
+Added: Cybersecurity
Our cybersecurity program includes a threat and vulnerability management program to identify, assess, prevent, detect, monitor and remediate internal and external threats to, and vulnerabilities of, the Company’s electronic systems, applications and data.
7 unchanged sentences
We also monitor and periodically reassess third-party service vendors to ensure controls are maintained to expectations.
−Removed: Part I | Item 1C.
−Removed: Cybersecurity
Cybersecurity Incidents
−Removed: As previously disclosed in Item 2.
−Removed: Management’s Discussion and Analysis of Financial Condition and Results of Operations — Macroeconomic, Industry and Regulatory Trends — Cybersecurity Event in our Form 10-Q for the quarter ended June 30, 2023, Jackson determined that its information at one of our third-party vendors, Pension Benefit Information, LLC (“PBI”), was impacted by a cybersecurity breach involving Progress Software Corporation’s MOVEit Transfer software.
−Removed: The PBI service helps Jackson to identify possible beneficiaries for death benefits.
−Removed: According to PBI, an unknown actor exploited a MOVEit software flaw to access PBI’s systems and download certain data.
−Removed: Our assessment indicated that personally identifiable information relating to approximately 850,000 of Jackson’s customers was obtained by that unknown actor from PBI’s systems.
−Removed: PBI informed Jackson that it rectified the MOVEit vulnerability.
−Removed: Separately, Jackson experienced unauthorized access to two servers as a result of the MOVEit flaw;
−Removed: however, the scope and nature of the data accessed on those servers was significantly less than the PBI impact.
−Removed: Our assessment was that a subset of information relating to certain partner organizations and individuals, including certain customers of Jackson, was obtained from the two affected servers.
−Removed: At this time, we do not believe the incidents or related litigation will have a material adverse effect on the business, operations, or financial results of Jackson Financial.
+Added: We are not aware of any material cybersecurity events that are likely to have a material effect on our business strategy, results of operation or financial condition.
JFI’s Board Oversight of Risks from Cybersecurity Threats:
9 unchanged sentences
As noted, the CISO meets in dedicated sessions with the Finance and Risk Committee to review and discuss in-depth cybersecurity risks facing the Company.
−Removed: Our Information Security and Privacy Team includes 70 full-time positions with at least 50% of our associates holding industry certifications, such as the Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and Certified Information Privacy Professional (CIPP).
+Added: Our Information Security and Privacy Team includes over 70 full-time positions with at least 50% of our associates holding relevant industry certifications, such as the Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and Certified Information Privacy Professional (CIPP).
All associates and contractors with access to our Company’s systems receive comprehensive initial and ongoing annual training on responsible information security, data security, and cybersecurity practices and how to protect against cyber threats.
+Added: Part I | Item 1C.
+Added: Cybersecurity
Regular independent third-party assessments, penetration testing, and internal audits are conducted to validate controls and to position our cybersecurity maturity level at or ahead of industry trends in meeting stringent security standards.
1 unchanged sentence
Certain of these control activities are also subject to an assessment by our external auditor to support its opinion on the effectiveness of our internal control over financial reporting.
−Removed: Part I | Item 2.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.