2 unchanged sentences
Risk Management and Strategy
−Removed: As a technology and communications company that globally transmits large amounts of information over our networks, we recognize the critical importance of maintaining the security and integrity of information and systems under our control.
−Removed: We view cybersecurity risk as one of our principal enterprise-wide risks, subject to control and monitoring at various levels of management throughout the Company.
+Added: As a technology and communications company that globally transmits large amounts of information over our networks, we recognize the critical importance of maintaining the confidentiality, integrity and availability of information and systems under our control.
+Added: Our cybersecurity risk management program is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise program to other key risk areas.
We dedicate significant resources towards programs designed to identify, assess, manage, mitigate and respond to cybersecurity threats.
−Removed: As described in Item 1A “Risk Factors,” several features of our operations heighten our susceptibility to cyber-attacks, including (i) our material reliance on systems owned, operated or controlled by unaffiliated third-party operators and (ii) our processing and storage of large amounts of sensitive customer data.
−Removed: Cyber-attacks on our systems may be initiated by a wide variety of intruders, including employees, cyber-criminals, nation state actors and other advanced persistent threat actors, and may include attempts by outside parties to gain access to sensitive data that is stored in or transmitted across our network.
−Removed: Cyber-attacks can take many forms, including computer hackings, computer viruses, ransomware, worms or other destructive or disruptive software, denial of service attacks, or other malicious activities.
To identify, assess and mitigate cybersecurity risk, we have implemented a global information security management program that includes administrative, technical, and physical safeguards.
−Removed: This program seeks to identify, detect, protect and respond to threats to our information systems.
+Added: This program seeks to identify, detect, protect against, and respond to threats to our information systems.
Our security operations center provides advanced threat detection and response capabilities.
1 unchanged sentence
Our cybersecurity and privacy policies encompass information security, incident response procedures, and vendor management.
−Removed: Our risk management team works closely with our information technology, privacy, product, and operations departments to continuously evaluate emerging cyber risk.
+Added: Our risk management team works closely with our information technology, privacy, product, and operations departments to continuously evaluate emerging cyber risk as part of our overall risk management program.
We monitor existing or proposed cybersecurity and privacy laws, regulations and guidance that are or may be applicable to us in the regions where we operate, including in the European Union and the United Kingdom where we are subject to the GDPR, as well as various other laws governing privacy rights, data protection and cybersecurity in other regions.
government contractor, we are required to comply with extensive governmental regulations and standards regarding cyber security.
−Removed: We periodically engage both internal and external auditors and consultants to assess and enhance our program.
−Removed: These independent external auditors and consultants are accredited under various information security standards, including those administered by the International Organization for Standardization and the PCI Security Standards Council.
−Removed: These engagements typically include penetration testing, third-party certifications, compliance assessments, audits, and assessments of vulnerabilities and emerging threats.
+Added: We periodically engage both internal and external auditors and consultants to assess and enhance our program and to assist in responding to cybersecurity incidents.
+Added: Many of these independent external auditors and consultants are accredited under various information security standards, including those administered by the International Organization for Standardization and the PCI Security Standards Council.
+Added: These engagements typically include penetration testing, third-party certifications, compliance assessments, audits, and assessments of vulnerabilities and emerging threats, as well as digital forensics and related work.
We also periodically deploy our Internal Audit processes to conduct additional reviews and assessments.
2 unchanged sentences
We have a vendor risk management program that assesses, manages and oversees risks associated with third-party service providers who have access to our data and systems.
−Removed: We maintain ongoing monitoring to ensure their compliance with our cybersecurity standards.
−Removed: Despite our efforts to prevent security incidents, (i) some of these attacks have resulted in security incidents (although thus far we do not believe that any of these incidents has resulted in a material adverse effect on our operating results or financial condition) and (ii) future security incidents are likely (some of which could have a material adverse effect on our operating results or financial condition).
−Removed: See Item 1A “Risk Factors” for a further discussion of cybersecurity risks.
+Added: We engage in diligence, contracting or maintain ongoing monitoring for compliance with our cybersecurity standards, depending on our assessment of each provider's operational criticality and risk profile.
+Added: Despite our efforts to manage cybersecurity risks and prevent security incidents, (i) some of these attacks have resulted in security incidents (although thus far we do not believe that any of these incidents has resulted in or is reasonably likely to result in a material adverse effect on our business strategy, operating results, or financial condition) and (ii) future security incidents are likely (some of which could have a material adverse effect on our operating results or financial condition).
+Added: See “Risk Factors” in Item 1A for a further discussion of cybersecurity risks and how they have affected or may affect us.
+Added: Table o f Contents
We maintain an Incident Response Playbook that provides a set of guidelines for our stakeholders to follow when handling any data incident.
This playbook describes how we assess incidents and how our security team shares information about such incidents with others at Lumen, including senior leadership and, if warranted, with some or all members of our Board of Directors.
−Removed: These escalation provisions, together with our disclosure controls and procedures, are designed to ensure that appropriate representatives throughout the Company are available to assess how to respond to such incidents and make any necessary public notifications.
−Removed: Our Cybersecurity Incident Response Team (“CIRT”) is responsible for detecting and coordinating responses to all security incidents.
−Removed: This team regularly assesses its communication plan to confirm that its members can be alerted quickly in the event of an actual crisis and meet as a team to discuss response options.
+Added: These escalation provisions, together with our disclosure controls and procedures, are designed to facilitate appropriate representatives throughout the Company in their assessment of relevant incidents and any necessary public notifications.
+Added: Our Cybersecurity Incident Response Team (“CIRT”) is responsible for detecting and coordinating responses to appropriate security incidents.
+Added: This team regularly assesses its internal communication plan and meet as a team to discuss response options.
The CIRT also addresses each incident, unless it determines that an incident is sufficiently serious.
−Removed: In those instances, it will notify our Cyber Security Watch Team (“CSWAT”), which is responsible for addressing cybersecurity incidents that raise more significant risks.
−Removed: Our CSWAT is comprised of senior IT, operations, risk, legal and compliance leaders across business segments.
+Added: In those instances, it notifies our Cyber Security Watch Team (“CSWAT”), which is responsible for addressing cybersecurity incidents that raise more significant risks.
+Added: Our CSWAT comprises senior IT, operations, risk, legal and compliance leaders across business segments.
In addition to addressing our more significant cyber incidents, the CSWAT manages risks from matters related to business continuity, including risks posed by cybersecurity threats, and implements controls to mitigate such operational risks.
1 unchanged sentence
As part of our overall risk management approach, we prioritize the identification and management of cybersecurity risk at several levels, including oversight by our Board of Directors, executive commitment, and employee training.
−Removed: Our Risk and Security Committee , comprised of independent directors from our Board, assists the Board in overseeing our cybersecurity and data privacy risk.
+Added: Our Risk and Security Committee , comprising independent directors from our Board, assists the Board in overseeing our cybersecurity and data privacy risk.
Specifically, our Risk and Security Committee, which meets quarterly, (i) receives periodic reports from our Chief Security Officer (“CSO”) on security programs, including incident reports, (ii) reviews cybersecurity risk assessments from information security, privacy, and internal audit management teams, including the adequacy and effectiveness of the Company’s internal controls regarding cybersecurity;
4 unchanged sentences
The full Board also reviews our cybersecurity risks in connection with its annual review of our enterprise risk mitigation programs.
−Removed: Our CSO has extensive experience working in the public and private sectors leading security organizations, risk management functions, and driving large information technology deployments.
+Added: Our CSO has extensive experience working in the public and private sectors leading security organizations, managing risk functions, and driving large information technology deployments.
He has an Engineering degree, a Master of Business Administration, a Chief Information Security Officer Certification, and a Global Information Assurance Certification Security Leadership Certification.
−Removed: He oversees the implementation and compliance of our information security standards and mitigation of information security related risks.
+Added: He oversees the implementation and compliance of our information security standards and is primarily responsible for managing our processes to assess and mitigate information security related risks.
Our cybersecurity organization includes a response team and management-level committees who support our processes to assess and manage cybersecurity risk as follows:
2 unchanged sentences
We generally seek to promote a company-wide awareness of cybersecurity risk through broad-based communications and educational initiatives, including regularly conducting phishing tests and holding employee trainings on our privacy, cybersecurity and information management policies, at least annually and more frequently when legal or other developments warrant.
+Added: Table o f Contents
• The Technology, Security, and Privacy Council, co-chaired by the CSO, the Chief Information Officer (CIO), and the Chief Privacy Officer (CPO), leverages the combined expertise of various security, IT, legal, internal audit, and operational leaders across the company.
7 unchanged sentences
Some of the more significant risks discussed by the ROC are also reported to our Risk and Security Committee at least quarterly.
+Added: Table o f Contents
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.