5 unchanged sentences
Our cybersecurity organization continually evaluates and addresses cybersecurity risk in alignment with our business objectives to address the evolving regulatory landscape and emerging risks, including those resulting from geopolitical shifts and technological innovations such as the growth of cloud technologies and artificial intelligence.
−Removed: We maintain a formal cybersecurity training program, including annual trainings for all Kenvuers, covering, among other topics, phishing, email security, and data privacy.
+Added: We maintain a formal cybersecurity training program, including annual training for all Kenvuers, covering, among other topics, phishing, email security, and data privacy.
We employ automation, and we also engage our internal audit function and a range of external consultants and other expert third parties in connection with the evaluation and management of cybersecurity risk and the maturation of our cybersecurity program.
Our cybersecurity organization assesses, monitors, and manages cybersecurity risk through technical, physical, and administrative controls, including implementing cybersecurity policies , procedures, and strategies, with the ultimate goal of preventing cybersecurity incidents to the extent feasible, while increasing our system resilience in an effort to minimize business impact should an incident occur.
−Removed: The underlying controls of the cybersecurity risk management program are based on
−Removed: recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology Cybersecurity Framework.
+Added: The underlying controls of the cybersecurity risk management program are based on recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology Cybersecurity Framework.
In addition, we maintain a Data Incident Response Program, which is designed to identify, assess, manage, and report significant data incidents, including those reasonably likely to affect our business strategy, results of operations, or financial condition.
3 unchanged sentences
Our organization tests and monitors these processes, including through table-top exercise testing with senior leaders.
−Removed: We rely heavily on our supply chain to deliver our products to our customers and consumers, and a cybersecurity incident at a supplier or partner could materially adversely impact us.
+Added: Finally, in 2025 we matured our cybersecurity risk governance through the addition of an artificial intelligence governance program to pay particular attention to the evolving risks associated with these emerging technologies.
+Added: This governance program enables oversight by our cybersecurity, privacy, legal, and data organizations to facilitate compliant and safe leverage of the competitive benefits of artificial intelligence.
+Added: We rely heavily on our supply chain to deliver our products to our customers and consumers, and a cybersecurity incident at a supplier or partner could materially impact us.
As such, we have processes in place to oversee and identify risks from cybersecurity threats associated with suppliers and our use of third-party service providers, including through our Supplier Cyber Risk Assessment process, which assesses third-party cybersecurity controls through a combination of risk assessment questionnaires, commercially available risk data, and proprietary algorithms.
21 unchanged sentences
He holds a Juris Doctor from Luiss Guido Carli University (Rome, Italy) and a Master of Laws in European Law and Economic Analysis from the College of Europe (Bruges, Belgium).
−Removed: The other members of the cybersecurity organization have decades of experience
−Removed: selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and rely on threat intelligence as well as other information obtained from governmental, public, or private sources, including external consultants.
+Added: The other members of the cybersecurity organization have decades of experience selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and rely on threat intelligence as well as other information obtained from governmental, public, or private sources, including external consultants.
Notwithstanding our cybersecurity measures, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.