4 unchanged sentences
Our operations rely on the secure processing, storage and transmission of confidential and other information by our information systems and those of third parties.
+Added: AI may also increase cybersecurity and fraud risk.
+Added: Threat actors may use AI to automate attacks or create more convincing phishing or impersonation attempts.
Lazard maintains a formal, robust cybersecurity and information security program that is aligned with the National Institute of Standards and Technology Cybersecurity Framework (“CSF”) and integrated into our overall risk management process.
21 unchanged sentences
We also use an enterprise-wide third-party technology provider to assist in our identification and assessment of cybersecurity risks to the Company presented by third parties, and our contracts are vetted by our internal legal and compliance departments as part of a process designed to ensure that we are provided the right to audit and test the security and quality of each of our vendors.
−Removed: As part of our screening and evaluation processes, we conduct due diligence on our potential vendors, as well as regular assessments of current vendors, regarding compliance with law (including financial regulations, sanctions regimes and data privacy regulations) and cybersecurity standards, including background checks and system tests.
+Added: As part of our screening and evaluation processes, we conduct due diligence on our potential vendors, as well as
+Added: regular assessments of current vendors, regarding compliance with law (including financial regulations, sanctions regimes and data privacy regulations) and cybersecurity standards, including background checks and system tests.
Our Chief Information Security Officer (“CISO”) regularly engages independent third parties to assess the performance of our cybersecurity risk management systems and procedures and to help test and identify cybersecurity risks to the Company.
24 unchanged sentences
The Assessment Committee also provides a summary of all incidents that are determined to be immaterial to the Board’s Audit Committee at the next scheduled meeting.
−Removed: For additional information regarding how cybersecurity threats or incidents are reasonably likely to materially affect our business strategy, results of operations or financial condition, see “ Risk Factors—A failure in or breach of our information systems or infrastructure, or those of third parties with which we do business, including as a result of cybersecurity incidents or threats, could disrupt our businesses, lead to reputational harm and legal liability or otherwise
−Removed: impact our ability to operate our business ” and “ Risk Factors—Other operational risks may disrupt our businesses, result in regulatory action against us or limit our growth .”
+Added: For additional information regarding how cybersecurity threats or incidents are reasonably likely to materially affect our business strategy, results of operations or financial condition, see “ Risk Factors—A failure in or breach of our
+Added: information systems or infrastructure, or those of third parties with which we do business, including as a result of cybersecurity incidents or threats, could disrupt our businesses, lead to reputational harm and legal liability or otherwise impact our ability to operate our business ”, “ Risk Factors—Our use of AI and development, integration, and reliance on related third-party technologies could adversely affect our business, financial condition, results of operations and reputation, and “ Risk Factors—Other operational risks may disrupt our businesses, result in regulatory action against us or limit our growth .”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.