3 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: We face various cyber risks, including, but not limited to, risks related to unauthorized access, misuse, data theft, computer viruses, system disruptions, ransomware, malicious software and other intrusions.
−Removed: We utilize a multilayered, proactive approach to identify, evaluate, mitigate and prevent potential cyber and information security threats through our cybersecurity risk management program.
+Added: We face various cybersecurity risks, including, but not limited to, risks related to unauthorized access, misuse, data theft, computer viruses, system disruptions, ransomware, malicious software and other intrusions.
+Added: We utilize a multilayered, proactive approach to identify, evaluate, mitigate and prevent potential cybersecurity and information security threats through our cybersecurity risk management program.
Our cybersecurity risk management program is integrated into our broader Enterprise Risk Management (“ERM”) program , which is designed to identify, assess, prioritize and mitigate risks across the organization to enhance our resilience and support the achievement of our strategic objectives.
3 unchanged sentences
Our practices are generally developed from, and benchmarked against, recognized cybersecurity frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework.
−Removed: Our newly acquired businesses and consolidated bottling operations maintain separate cybersecurity programs and processes that may differ in scope and complexity from the Company’s overall cybersecurity programs and processes.
+Added: Our acquired businesses and consolidated bottling operations maintain separate cybersecurity systems and environments that may differ in scope and complexity from our own.
However, for all consolidated entities, our cybersecurity risk management program is designed to help coordinate the Company’s identification of, response to and recovery from, cybersecurity incidents and includes processes to triage, assess the severity of, escalate, contain, investigate and remediate incidents, as well as to comply with applicable legal obligations.
2 unchanged sentences
For example, we conduct tests that help discover potential vulnerabilities, including external penetration testing and tabletop and other exercises, to evaluate our core information systems and cybersecurity practices that enable improved decision-making and prioritization, as well as to promote monitoring and reporting across compliance functions.
−Removed: As part of our overall risk mitigation strategy, the Company also maintains cyber insurance coverage;
−Removed: however, such insurance may not be sufficient in type or amount to cover us against claims related to security breaches, cyberattacks and other related breaches.
−Removed: In order to oversee and identify risks from cyb ersecurity threats associated with the Company’s independent bottling partners, distributors, wholesalers, retailers and other business partners, as well as our use of third-party service providers, we maintain a third-party risk management program designed to help protect against the misuse of information technology.
+Added: As part of our overall risk mitigation strategy, the Company also maintains cybersecurity insurance coverage;
+Added: however, such insurance may not be sufficient in type or amount to cover us against claims related to security breaches, cyberattacks and other related incidents.
+Added: In order to oversee and identify risks from cyb ersecurity threats associated with the Company’s independent bottling partners, distributors, wholesalers, retailers and other business partners, as well as our use of third-party service providers, we maintain a
+Added: third-party risk management program designed to help protect against the misuse of information technology.
We have various processes and procedures to evaluate cybersecurity threats associated with third parties, including requiring key third-party service providers to complete initial and periodic security assessments.
−Removed: In addition, our Global Chief Information Security Officer (“CISO”) and other senior leaders regularly meet with key bottling partners to discuss cybersecurity risks and
−Removed: mitigation programs in order to advance risk management capabilities and proactively share cybersecurity guidelines and best practices.
−Removed: We have not identified any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of our operations, or financial condition.
−Removed: However, we have been the target of cyber attacks and expect them to continue as cybersecurity threats have been rapidly evolving in sophistication and becoming more prevalent in the industry.
+Added: In addition, our Global Chief Information Security Officer (“CISO”) and other senior leaders regularly meet with key bottling partners to discuss cybersecurity risks and mitigation programs in order to advance risk management capabilities and proactively share cybersecurity guidelines and best practices.
+Added: We do not believe that there are currently any risks from known cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial condition.
+Added: However, we have been the target of cyberattacks and expect them to continue as cybersecurity threats have been rapidly evolving in sophistication and becoming more prevalent in the industry.
We cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced an undetected cybersecurity incident in the past or that we will not experience such an incident in the future.
8 unchanged sentences
Subject matter experts are also invited, as appropriate.
−Removed: The Cybersecurity Oversight Council meets at least quarterly and has responsibility for oversight and validation of the Company’s cybersecurity strategic direction, risks and threats, priorities, resource allocation, capabilities and planning.
+Added: The Cybersecurity Oversight Council meets at least quarterly and has responsibility for oversight and validation of the Company’s cybersecurity strategic direction, risks, threats and priorities.
The Cybersecurity Oversight Council acts in alignment with the Company’s Risk Steering Committee, another cross-functional management committee, which provides strategic direction and oversight over the Company’s ERM program.
−Removed: The CISO and his team, as well as the Cybersecurity Oversight Council, are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity incidents in accordance with the Company’s cyber incident response plan.
+Added: The CISO and his team are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity incidents in accordance with the Company’s cyber incident response plan.
The Audit Committee of the Board of Directors is charged with oversight of cybersecurity matters and receives regular reports from the CISO and the CIO on, among other things, the Company’s cyber risks and threats, the status of projects to strengthen the Company’s information security systems, assessments of the Company’s security program and the emerging threat landscape.
−Removed: In accordance with our cyber incident response plan, the Audit Committee is promptly informed by management of cybersecurity incidents with the potential to materially adversely affect the Company or its information systems and is regularly updated about incidents with lesser impact potential.
+Added: In accordance with our cybersecurity incident response plan, the Audit Committee is promptly informed by management of cybersecurity incidents with the potential to materially adversely affect the Company or its information systems and is regularly updated about incidents with lesser impact potential.
The Chair of the Audit Committee regularly briefs the full Board on these matters.
In addition, the Board also periodically receives cybersecurity updates directly from management.
−Removed: In an effort to detect and defend against cyber threats, the Company annually provides its employees with various cybersecurity and data protection training programs.
−Removed: These programs cover timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use and mobile security, and educate employees on the importance of reporting all incidents promptly to the Company’s centrally managed cyber defense and security operations.
+Added: In an effort to detect and defend against cybersecurity threats, the Company annually provides its employees with various cybersecurity and data protection training programs.
+Added: These programs cover timely and relevant topics, including social engineering, phishing, deep fakes, password protection, confidential data protection, asset use and mobile security, and educate employees on the importance of reporting all incidents promptly to the Company’s centrally managed cyber defense and security operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.