10 unchanged sentences
disrupt or delay our operations or systems;
−Removed: or otherwise cause harm to the Company, our customers, employees, or other key stakeholders.
+Added: or otherwise cause harm to the Company, our customers, employees, vendors, or other key stakeholders.
Process — We use a multi-layered defensive cybersecurity strategy based on best practices to identify risks, protect technology assets, detect anomalies, respond to, and recover from cybersecurity incidents.
Our processes to identify, assess, and manage material risks from cybersecurity threats includes the following:
−Removed: • Identify - We identify risks from cybersecurity threats by first developing and maintaining an understanding of assets and systems essential to our operation and reputation, as well as assets and systems that could provide value to threat actors.
+Added: • Identify - We identify risks from cybersecurity threats by first developing and maintaining an understanding of assets and systems essential to our operations and reputation, as well as assets and systems that could provide value to threat actors.
Any attempt by a threat actor is considered a potential risk if a threat actor can use it to reduce the value of an asset, reduce our ability to utilize or otherwise access the value of an asset, or surreptitiously gain or increase their access to an asset or system which would result in decreased information security or a disruption in our operations.
4 unchanged sentences
We further monitor, test, assess, and update these processes, including working with technology partners, government agencies, regulators, law enforcement, industry groups, and peers to implement practices to guard against an evolving cyber threat environment and to ensure we remain compliant with relevant regulatory requirements.
−Removed: We offer cybersecurity training for staff at key sites, focusing on reducing human risk through anti-phishing and social engineering exercises.
+Added: We offer cybersecurity training for corporate employees at headquarters and terminal locations, focusing on reducing human risk through anti-phishing and social engineering exercises.
We also carry cybersecurity insurance that provides protection against potential losses arising from certain cybersecurity incidents as part of our cybersecurity risk mitigation strategy.
7 unchanged sentences
Additionally, this team tracks potentially material cybersecurity incidents to help identify and analyze them.
−Removed: The Company’s cybersecurity incident response team partners with the Company’s internal cybersecurity teams as well as with
+Added: The Company’s
Table of Contents Glossary of Terms
KNIGHT-SWIFT TRANSPORTATION HOLDINGS INC.
−Removed: external legal advisors, communication specialists, government agencies, regulators, law enforcement, and other key stakeholders as appropriate to respond to cybersecurity incidents.
+Added: cybersecurity incident response team partners with the Company’s internal cybersecurity teams as well as with external legal advisors, communication specialists, government agencies, regulators, law enforcement, vendors, and other key stakeholders as appropriate to respond to cybersecurity incidents.
The Company maintains a cybersecurity incident response plan to prepare for and respond to cybersecurity incidents.
13 unchanged sentences
Risks from Material Cybersecurity Threats
−Removed: As of the date of this report, the Company has not identified any cybersecurity threats that have materially affected or are reasonably anticipated to have a material effect on the organization.
+Added: As of the date of this report, the Company has not identified any cybersecurity threats that have materially affected or are reasonably anticipated to have a material effect on the Company.
Although the Company has not experienced cybersecurity incidents that are individually, or in the aggregate, material, the Company has experienced cyberattacks in the past, which the Company believes have thus far been mitigated by preventative, detective, and responsive measures put in place by the Company.
Further, despite the capabilities, processes, and other security measures we employ that we believe are designed to detect, reduce, and mitigate the risk of cybersecurity incidents, we may not be aware of all vulnerabilities or might not accurately assess the risks of incidents, and such preventative measures cannot provide absolute security and may not be sufficient in all circumstances or mitigate all potential risks.
+Added: Our business and operations could be materially and adversely impacted by cybersecurity incidents.
For a detailed discussion of the Company’s cybersecurity related risks, refer to "Operational Risk" within Part I, Item 1A.
16 unchanged sentences
Based on these management reports, the Nominating and Corporate Governance Committee may request follow-up data and presentations to address any specific concerns and recommendations.
−Removed: In addition to this regular reporting, significant cybersecurity risks or threats may also be escalated by management on as needed basis to the Nominating and Corporate Governance Committee .
+Added: In addition to this regular reporting, significant cybersecurity risks or threats may also be escalated by management on an as needed basis to the Nominating and Corporate Governance Committee .
The Nominating and Corporate Governance Committee may also escalate such issues to the full Board at any time.
5 unchanged sentences
• The CIO provides leadership for the Company’s technology department, including responsibility for leading organization-wide cybersecurity strategy, policy, and processes .
−Removed: Our CIO has served in this role since the 2017 Merger, has been at Swift since 2003, and has over 25 years of cybersecurity experience, including technology positions at AlliedSignal, Sara Lee, and J-Del.
+Added: Our CIO has served in this role since June 2024 and has over 25 years of cybersecurity experience, including technology positions at the US Army, Accenture, Advance Auto Parts, Finishline Shoes, and PF Chang's.
• The VPIT, reporting to the CIO, is responsible for the assessment, oversight, and management of our enterprise-wide cybersecurity strategy and governance.
−Removed: Our VPIT has served in this role since 2020 and has significant relevant experience and professional certifications, including 18 years of cybersecurity and infrastructure experience.
+Added: Our VPIT has served in this role since 2020 and has significant relevant experience and professional certifications, including nearly 20 years of cybersecurity and infrastructure experience.
The VPIT, along with our cybersecurity team, has guided the organization through building a multi-layer cybersecurity program.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.