4 unchanged sentences
“Business.” Through the services agreement, we participate in Liberty’s processes for assessing, identifying, and managing risks from cybersecurity threats at the corporate headquarters, as detailed below.
−Removed: GCI operates its own cybersecurity function with oversight from Liberty Broadband.
Charter, an equity method affiliate, as a separate publicly traded company from Liberty Broadband, operates its own cybersecurity function.
6 unchanged sentences
These measures include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, Security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity awareness and training, phishing tests, and penetration testing.
−Removed: Cybersecurity awareness training is also made available annually to our board of directors.
−Removed: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level and at GCI.
+Added: Cybersecurity awareness training is also made available to our board of directors.
+Added: In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level.
These frameworks are a set of coordinated procedures and tasks that our incident response teams execute with the goal of ensuring timely and accurate identification, resolution and reporting of cybersecurity incidents both internally and externally, as necessary.
−Removed: To operate our businesses, we utilize certain third-party service providers to perform a variety of operational functions.
+Added: To operate our business, we utilize certain third-party service providers to perform a variety of operational functions.
We have implemented a third-party risk management program to evaluate the cybersecurity practices of higher risk vendors and vendors that encounter our systems or data.
3 unchanged sentences
For additional information on our cybersecurity risks, see Part I, Item 1A.
−Removed: “Risk Factors” under the section entitled “Cyberattacks or other network disruptions could have an adverse effect on our company and GCI’s business" in this Annual Report on Form 10-K.
+Added: “Risk Factors” under the section entitled “Cyberattacks or other network disruptions could have an adverse effect on our company" in this Annual Report on Form 10-K.
Role of the Board of Directors
7 unchanged sentences
Through our services agreement with Liberty discussed in Part I, Item 1.
−Removed: “Business” of this Annual Report on Form 10-K, we have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Facilities departments.
+Added: “Business” of this Annual Report on Form 10-K, we have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Technology departments.
The ISSC has management oversight responsibility for assessing and managing technology and operational risk, including information security, fraud, vendor, data protection and privacy, business continuity and resilience, and cybersecurity risks at the corporate level and our subsidiaries.
−Removed: At GCI, there is an Enterprise Security Office (“ESO”) , led by the Chief Information Security Officer (“CISO”), which is responsible for day-to-day management and oversight of subsidiary cybersecurity, including assessing, monitoring and mitigating cybersecurity risk.
−Removed: The CISO provides regular reporting to GCI executive management and the ISSC.
−Removed: Liberty Broadband has also established a Compliance Committee responsible for overseeing and monitoring all corporate compliance initiatives at GCI, including cybersecurity.
−Removed: The Compliance Committee is composed of members of Liberty Broadband’s ISSC as well as GCI’s executive leadership team, including the President & Chief Operating Officer, General Counsel, and Chief Financial Officer.
−Removed: The CISO reports periodically to the Compliance Committee on cybersecurity risks and initiatives as well as any cybersecurity events, as applicable.
−Removed: Our management team’s experience includes a diverse background in telecom and other industries, with decades of experience in various aspects of cybersecurity.
−Removed: Liberty’s Head of Cybersecurity has more than 25 years of cybersecurity and information technology experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications.
−Removed: GCI’s CISO has more than 20 years of experience and hold multiple certifications including Certified Information Security Systems Professional and Certified in Risk and Information System Control.
−Removed: Both have worked at a variety of companies, including large publicly traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, customer payment systems and telecommunications networks used by customers to transmit data.
+Added: Our management team’s experience includes a diverse background in telecom, media and other industries, with decades of combined experience in various aspects of cybersecurity.
+Added: Liberty’s Head of Cybersecurity has more than 15 years of cybersecurity, information technology, and risk management experience and has worked at and with a variety of companies, including large publicly traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, customer payment systems and telecommunications networks used by customers to transmit data.
+Added: In addition to industry and technical experience, the personnel who support Liberty’s information security also have relevant education, professional certifications, and ongoing training to keep pace with the evolving threat landscape.
+Added: Liberty Broadband
+Added: In connection with the Broadband Spin-Off, a wholly owned subsidiary of Liberty entered into a facilities sharing agreement with Liberty Broadband, pursuant to which Liberty Broadband shares office facilities with Liberty located at 12300 Liberty Boulevard, Englewood, Colorado, 80112.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.