4 unchanged sentences
Our process for assessing, identifying, and managing material risks from cybersecurity threats is integrated into our broader risk management framework to promote a company-wide culture of cybersecurity risk management.
−Removed: Our cybersecurity organization continually evaluates and addresses cybersecurity risk in alignment with our business objectives.
+Added: Our cybersecurity organization continually evaluates and addresses cybersecurity risk in alignment with our business objectives to address the evolving regulatory landscape and emerging risks, including those resulting from geopolitical shifts and technological innovations such as the growth of cloud technologies and artificial intelligence.
+Added: We maintain a formal cybersecurity training program, including annual trainings for all Kenvuers, covering, among other topics, phishing, email security, and data privacy.
We employ automation, and we also engage our internal audit function and a range of external consultants and other expert third parties in connection with the evaluation and management of cybersecurity risk and the maturation of our cybersecurity program.
−Removed: Our cybersecurity organization assesses and manages cybersecurity risk through technical, physical and administrative controls, including implementing cybersecurity policies, procedures and strategies, with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while increasing our system resilience in an effort to minimize business impact should an incident occur.
−Removed: The underlying controls of the cybersecurity risk management program are based on recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology Cybersecurity Framework.
+Added: Our cybersecurity organization assesses, monitors, and manages cybersecurity risk through technical, physical, and administrative controls, including implementing cybersecurity policies , procedures, and strategies, with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while increasing our system resilience in an effort to minimize business impact should an incident occur.
+Added: The underlying controls of the cybersecurity risk management program are based on
+Added: recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology Cybersecurity Framework.
In addition, we maintain a Data Incident Response Program, which is designed to identify, assess, manage, and report significant data incidents, including those reasonably likely to affect our business strategy, results of operations, or financial condition.
+Added: In the event of a cybersecurity incident, our cybersecurity team assesses, among other factors, safety impact, supply chain and manufacturing disruption, data and personal information loss, business operations disruption, projected cost, and potential for reputational harm, with support from external technical and legal advisors and law enforcement, as appropriate.
The Data Incident Response Program outlines the steps to be followed from incident detection to mitigation, recovery, and notification, including notifying functional areas, senior management, and the Company’s Disclosure Committee or a sub-committee thereof as appropriate.
−Removed: The disclosure committee or a sub-committee thereof will consider the materiality of an incident elevated by the Data Incident Response Program, inform the Board and other key stakeholders as appropriate, and determine the Company’s reporting obligation on a timely basis.
+Added: The Disclosure Committee or a sub-committee thereof will consider the materiality of an incident elevated by the Data Incident Response Program, inform our Board and other key stakeholders as appropriate, and determine the Company’s reporting obligation on a timely basis.
+Added: Our organization tests and monitors these processes, including through table-top exercise testing with senior leaders.
We rely heavily on our supply chain to deliver our products to our customers and consumers, and a cybersecurity incident at a supplier or partner could materially adversely impact us.
2 unchanged sentences
We require that our suppliers and partners report cybersecurity incidents to us so that we can assess the impact of such an incident on us and have dedicated processes to respond to cybersecurity incidents at third parties.
−Removed: Risks from cybersecurity threats did not materially affect our results of operations or financial condition during the period covered by this filing.
+Added: Risks from cybersecurity threats did not materially affect our results of operations or financial condition during the fiscal twelve months ended December 29, 2024.
Cybersecurity-related risks are one of the key risks contemplated by our Enterprise Risk Management (“ERM”) Framework.
3 unchanged sentences
Our ERM Framework describes the roles and responsibilities of the Integrated Risk Management Council, a cross-functional group of senior enterprise risk leaders, which meets regularly to review and discuss significant risk facing our business, including cybersecurity risk.
−Removed: Our Integrated Risk Management Council, which includes our Chief Information Security Officer (“CISO”) proactively identifies, assesses and prioritizes key or emerging risks, which are then escalated to senior management as needed and, in the case of cybersecurity risk, reported to the Nominating Governance & Sustainability Committee or our full Board.
−Removed: The Nominating, Governance and Sustainability Committee of our Board (the “NG&S Committee”) is responsible for assisting the Board with respect to designated risk oversight matters, including privacy and cybersecurity.
−Removed: The NG&S Committee receives reports from, and meets at least twice a year and as needed with, the CISO and the Chief Privacy Officer.
−Removed: The CISO and the Chief Privacy Officer inform the NG&S Committee, which in turn informs our Board, of risks from cybersecurity
−Removed: threats during such meetings.
+Added: Our Integrated Risk Management Council, which includes our Chief Information Security Officer (“CISO”), proactively identifies, assesses, and prioritizes key or emerging risks, which are then escalated to senior management as needed and, in the case of cybersecurity risk, reported to our Board’s Nominating, Governance & Sustainability Committee (the “NG&S Committee”) or our full Board .
+Added: The NG&S Committee is responsible for assisting our Board with respect to designated risk oversight matters, including privacy and cybersecurity.
+Added: The NG&S Committee receives reports from, and meets at least twice a year and as needed with, the CISO and the Chief Privacy and Digital Officer (“CPDO”).
+Added: The CISO and the CPDO inform the NG&S Committee, which in turn informs our Board, of risks from cybersecurity threats during such meetings.
The NG&S Committee reports to our full Board following each of its regularly scheduled meetings at a minimum and reviews with our Board significant issues or concerns that arise at NG&S Committee meetings.
−Removed: Our cybersecurity organization is led by our CISO.
−Removed: Our CISO leads a global team to develop our strategic cybersecurity priorities and execute operational plans.
−Removed: He has over 25 years of cybersecurity experience in the healthcare, finance and telecommunications industries and in government.
−Removed: Prior to his role at Kenvue, our CISO spent over ten years at J&J in cybersecurity, and he retired from the United States Air Force Reserves in 2018 as a Lieutenant Colonel, where he had responsibility for cybersecurity.
−Removed: He is a Certified Information Systems Security Professional and holds a Masters in Telecommunications Management from the University of Maryland, University College.
−Removed: The members of the cybersecurity organization have decades of experience selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and rely on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants.
+Added: In addition, in February 2025, the CISO and the CPDO reviewed with our Board the cybersecurity and privacy programs, the Data Incident Response Program, and the role of our Board related thereto.
+Added: Our CISO leads a global cybersecurity organization, which develops our strategic cybersecurity priorities and executes operational plans.
+Added: Our CISO has over 25 years of cybersecurity experience in the healthcare, finance, and telecommunications industries and in government.
+Added: Prior to his role at Kenvue, our CISO spent over 10 years at J&J in cybersecurity, and he retired from the United States Air Force Reserves in 2018 as a Lieutenant Colonel, where he had responsibility for cybersecurity.
+Added: He is a Certified Information Systems Security Professional and holds a Masters in Telecommunications Management from the University of Maryland, University College and a Directorship Certification from the National Association of Corporate Directors.
+Added: Our CPDO has over 10 years of privacy and digital legal experience.
+Added: Prior to his role at Kenvue, our CPDO worked for over 15 years in J&J’s Law Department.
+Added: He also worked as a lawyer in private practice at the law firm Linklaters LLP, in industry associations, and in government, and he acted as Vice Chair of the Consumer Goods Privacy+ Consortium, an association developing compliance strategies and best practices to meet requirements of global privacy laws.
+Added: He holds a Juris Doctor from Luiss Guido Carli University (Rome, Italy) and a Master of Laws in European Law and Economic Analysis from the College of Europe (Bruges, Belgium).
+Added: The other members of the cybersecurity organization have decades of experience
+Added: selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and rely on threat intelligence as well as other information obtained from governmental, public, or private sources, including external consultants.
Notwithstanding our cybersecurity measures, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us.
While we maintain cybersecurity insurance, the costs related to cybersecurity threats or disruptions may not be fully insured.
−Removed: For a discussion of cybersecurity risks, see Item 1A, “Risk Factors —Risks Related to Our Operations—An information security incident, including a cybersecurity breach, or the failure, interruption, breakdown, invasion, corruption, destruction, or breach of an information technology system owned or operated by us or a third party, could adversely affect our business, results of operations or financial condition.”
+Added: For a discussion of cybersecurity risks, see Part I, Item 1A, “Risk Factors—Risks Related to Our Operations—An information security incident, including a cybersecurity breach, or the failure of an information technology or operational technology system owned or operated by us or a third party, could adversely affect us.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.