11 unchanged sentences
or otherwise cause harm to the Company, our customers, employees, vendors, or other key stakeholders.
−Removed: Process — We use a multi-layered defensive cybersecurity strategy based on best practices to identify risks, protect technology assets, detect anomalies, respond to, and recover from cybersecurity incidents.
+Added: Process — We use a multi-layered defensive cybersecurity strategy to identify risks, protect technology assets, detect anomalies, respond to, and recover from cybersecurity incidents.
Our processes to identify, assess, and manage material risks from cybersecurity threats includes the following:
8 unchanged sentences
We also carry cybersecurity insurance that provides protection against potential losses arising from certain cybersecurity incidents as part of our cybersecurity risk mitigation strategy.
−Removed: Integration into our Risk Management Program — Our processes to assess, identify, and manage cybersecurity risks are expressly incorporated into our risk management program, which includes technology as one of the five primary risk categories addressed by our risk program, with cybersecurity risks being one of the three subcategories within the technology risk category.
−Removed: As a result, our risk management leadership team works with the Chief Information Officer ("CIO") and Vice President of Information Technology Security ("VPIT"), which we refer to collectively as "Cybersecurity Leadership," to define the top areas of risk in both the technology and cybersecurity areas, with such risks incorporated into our risk management program.
−Removed: Our risk management leadership team also meets on a quarterly basis with our cross-functional technology risk working group, comprised of leaders across the information technology, operations, internal audit, information security and legal departments, to monitor developments on an ongoing basis in the threat landscape in order to identify and prioritize key cybersecurity threats that may impact the Company.
+Added: Integration into our Risk Management Program — Our processes to assess, identify, and manage cybersecurity risks are expressly incorporated into our risk management program, which includes technology and cybersecurity as risks addressed by our risk program.
+Added: As a result, the Chief Information Officer ("CIO") reviews and updates technology and cybersecurity risks as appropriate, and these risks are included in the Company’s risk management program and reviewed by the risk management leadership team as part of its overall enterprise risk oversight.
Incident Response
−Removed: The Company has a dedicated cybersecurity incident response team, overseen by Cybersecurity Leadership, which is responsible for managing and coordinating the Company’s cybersecurity incident response plans and efforts.
+Added: The Company has cybersecurity incident response teams, overseen by each brand’s IT Leadership , which is responsible for managing and coordinating incident response plans and efforts.
This team also collaborates closely with other teams in identifying, protecting from, detecting, responding to, and recovering from cybersecurity incidents.
−Removed: Cybersecurity incidents that meet certain thresholds are escalated to Cybersecurity Leadership and cross-functional teams on an as-needed basis for support and guidance.
+Added: Cybersecurity incidents that meet certain thresholds are escalated to the CIO, Vice President of Information Technology Security ("VPIT"), and Knight-Swift subsidiaries' IT leaders (collectively, "Cybersecurity Leadership") along with cross-functional teams on an as-needed basis for support and guidance.
Additionally, this team tracks potentially material cybersecurity incidents to help identify and analyze them.
−Removed: The Company’s
−Removed: Table of Contents Glossary of Terms
−Removed: KNIGHT-SWIFT TRANSPORTATION HOLDINGS INC.
−Removed: cybersecurity incident response team partners with the Company’s internal cybersecurity teams as well as with external legal advisors, communication specialists, government agencies, regulators, law enforcement, vendors, and other key stakeholders as appropriate to respond to cybersecurity incidents.
+Added: The Company’s cybersecurity incident response teams partner with the Company’s internal teams as well as with external legal advisors, communication specialists, government agencies, regulators, law enforcement, vendors, and other key stakeholders as appropriate to respond to cybersecurity incidents.
The Company maintains a cybersecurity incident response plan to prepare for and respond to cybersecurity incidents.
The incident response plan includes standard processes for reporting and escalating cybersecurity incidents to senior management and the Board as appropriate.
−Removed: Additionally, the Company conducts at least one cybersecurity tabletop exercise on an annual basis, where members of a cross-functional team engage in a simulated cybersecurity incident scenario.
−Removed: This preparedness exercise is intended to provide training for the participants and to help the Company assess its processes and capabilities in addressing major cybersecurity incidents.
+Added: Table of Contents Glossary of Terms
+Added: KNIGHT-SWIFT TRANSPORTATION HOLDINGS INC.
+Added: Additionally, the Company conducts tabletop exercises, where members of a cross-functional team engage in a simulated incident scenario.
+Added: This preparedness exercise is intended to provide training for the participants and to help the Company assess its processes and capabilities in addressing major incidents.
Use of Third Parties
2 unchanged sentences
Additionally, the Company leverages a number of third-party tools and technologies as part of its efforts to enhance cybersecurity functions.
−Removed: This includes a managed security service provider to augment the Company’s dedicated security operations team, an endpoint detection and response system for continuous monitoring, detection, and response capabilities, and a security information and event management solution to automate real-time threat detection, investigation, and prioritization.
+Added: This includes managed security service providers to augment the Company’s dedicated security operations team, an endpoint detection and response system for continuous monitoring, detection, and response capabilities, and a security information and event management solution to automate real-time threat detection, investigation, and prioritization.
We also rely on third-party service providers to support our business and operations, which may include processing of confidential and other sensitive data.
13 unchanged sentences
The Board is responsible for overseeing management’s assessments of major risks facing the Company and for reviewing options to mitigate such risks.
−Removed: The Board’s oversight of major risks, including cybersecurity risks, occurs at both the full Board level and at the Board committee level through the Nominating and Corporate Governance Committee .
+Added: The Board’s oversight of cybersecurity risks occurs at both the full Board level and at the Board committee level through the Nominating and Corporate Governance Committee .
The Board — The Chief Executive Officer, the Chief Financial Officer, the CIO, members of senior management, and other personnel and advisors, as requested by the Board, report on the risks to the Company, including cybersecurity risks, at regularly scheduled meetings of the Board and its committees.
3 unchanged sentences
KNIGHT-SWIFT TRANSPORTATION HOLDINGS INC.
−Removed: Nominating and Corporate Governance Committee — The Nominating and Corporate Governance Committee, which is comprised entirely of independent directors, reviews with management the Company's technology and cybersecurity frameworks, policies, programs, opportunities, and risk profile both at its regularly scheduled meetings and, if appropriate, in real time.
−Removed: Cybersecurity Leadership, members of the cybersecurity team, or other advisors, as requested by the Nominating and Corporate Governance Committee , report at least quarterly on the Company's technology, data privacy, and cybersecurity strategies and risks.
−Removed: Cybersecurity topics are presented to the Nominating and Corporate Governance Committee on a quarterly basis and generally highlight any significant cybersecurity incidents, the cyber threat landscape, cybersecurity program enhancements, cybersecurity risks and related mitigation activities, and any other relevant cybersecurity topics.
+Added: Nominating and Corporate Governance Committee — The Nominating and Corporate Governance Committee, which is comprised entirely of independent directors, reviews with management the Company's technology and cybersecurity frameworks, policies, programs, opportunities, and risk profile.
+Added: Cybersecurity Leadership, members of the cybersecurity team, or other advisors, as requested by the Nominating and Corporate Governance Committee , report at least annually on the Company's technology, data privacy, and cybersecurity strategies and risks.
+Added: Cybersecurity topics are presented to the Nominating and Corporate Governance Committee on an annual basis with additional frequency as requested and generally highlight any significant cybersecurity incidents, the cyber threat landscape, cybersecurity program enhancements, cybersecurity risks and related mitigation activities, and any other relevant cybersecurity topics.
Reporting to the Nominating and Corporate Governance Committee is multi-format and includes both live presentations and memoranda.
−Removed: The Board believes that this regular cadence of reporting helps to provide the Nominating and Corporate Governance Committee with an informed understanding of the Company's dynamic cybersecurity program and threat landscape.
+Added: The Board believes that this cadence of reporting helps to provide the Nominating and Corporate Governance Committee with an informed understanding of the Company's dynamic cybersecurity program and threat landscape.
The Nominating and Corporate Governance Committee further reviews with management the Company's business continuity and disaster recovery plans and capabilities, including our cybersecurity and business interruption insurance coverages, and the effectiveness of the Company's escalation procedures.
3 unchanged sentences
Management's Role
−Removed: The Company has a dedicated cybersecurity organization within its technology department that focuses on current and emerging cybersecurity matters.
−Removed: The Company’s cybersecurity function is led by Cybersecurity Leadership who are actively involved in assessing and managing cybersecurity risks.
−Removed: They are responsible for implementing cybersecurity policies, programs, procedures, and strategies.
+Added: The Company has dedicated cybersecurity resources within its decentralized technology departments that focus on current and emerging cybersecurity matters.
+Added: The Company’s cybersecurity function is led by Cybersecurity Leadership who manage cybersecurity risks.
+Added: Subsidiaries' IT leaders are responsible for implementing cybersecurity policies, programs, procedures, and strategies.
The responsibilities and relevant experience of each of the Cybersecurity Leaders are listed below:
−Removed: • The CIO provides leadership for the Company’s technology department, including responsibility for leading organization-wide cybersecurity strategy, policy, and processes .
+Added: • The CIO provides leadership for the Company’s technology department, including responsibility for leading organization-wide cybersecurity strategy and policy .
Our CIO has served in this role since June 2024 and has over 25 years of cybersecurity experience, including technology positions at the US Army, Accenture, Advance Auto Parts, Finishline Shoes, and PF Chang's.
−Removed: • The VPIT, reporting to the CIO, is responsible for the assessment, oversight, and management of our enterprise-wide cybersecurity strategy and governance.
+Added: • The VPIT, reporting to the CIO, is responsible for the oversight and management of cybersecurity strategy and governance.
Our VPIT has served in this role since 2020 and has significant relevant experience and professional certifications, including nearly 20 years of cybersecurity and infrastructure experience.
−Removed: The VPIT, along with our cybersecurity team, has guided the organization through building a multi-layer cybersecurity program.
−Removed: The Company's cybersecurity department is comprised of teams that engage in a range of cybersecurity activities such as threat intelligence, security architecture, and incident response.
+Added: The VPIT, along with our cybersecurity team, has guided technology departments through building a multi-layer cybersecurity program.
+Added: The Company's cybersecurity departments are comprised of teams that engage in a range of cybersecurity activities such as threat intelligence, security architecture, and incident response.
These teams, in coordination with third parties, conduct vulnerability management and penetration testing to identify, classify, prioritize, remediate, and mitigate vulnerabilities.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.