2 unchanged sentences
Risk Management Strategy
−Removed: The Company has implemented a cybersecurity program intended to assess, identify, manage and reduce cybersecurity risk.
+Added: We have implemented a cybersecurity program intended to assess, identify, manage and reduce cybersecurity risks.
Through our partnership with Harley-Davidson, we maintain an IT incident response plan that is designed to protect against, identify, evaluate, respond to, and recover from an incident.
1 unchanged sentence
The incident response team is a cross-functional group that is composed of both Company and Harley-Davidson personnel and external service providers, and which is tailored to a particular incident so that individuals with appropriate experience and expertise are available.
−Removed: Currently the Company contracts for such cybersecurity services through the Master Services Agreement with Harley-Davidson, in addition to leveraging its own information technology and security tools and teams.
+Added: Currently, we contract for such cybersecurity services through the Master Services Agreement with Harley-Davidson, in addition to leveraging our own information technology and security tools and teams.
We have invested in tools and technologies intended to protect our data and business systems, and we monitor our computing environment on an ongoing basis to help identify and assess risk.
1 unchanged sentence
It is focused on helping our workforce recognize, avoid falling victim to and raise the visibility of potential cyber threats and scams.
−Removed: In addition, periodic cybersecurity awareness messages are posted to employees on the Company portal as new threats and scams develop throughout the year.
+Added: In addition, periodic cybersecurity awareness messages are communicated to employees as new threats and scams develop throughout the year.
+Added: To reinforce these practices, routine phishing simulations are conducted across the organization to test employees awareness and provide targeted follow-up training, as needed.
Through the Master Services Agreement with Harley-Davidson, we take measures to regularly update and improve our cybersecurity program, including conducting assessments, performing penetration testing and scanning of our systems for vulnerabilities using external third-party tools and techniques to test security controls, auditing applicable data policies, and monitoring emerging laws and regulations related to information security.
−Removed: We design our program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
+Added: The program is designed based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
However, this does not imply that we meet any particular technical standards, specifications or requirements, only that we use the NIST Cybersecurity Framework as a guide to help us identify, assess and manage cybersecurity risks relevant to our business.
3 unchanged sentences
In general, we also contractually require material third-party service providers with access to our information technology systems, sensitive business data or personal information to implement and maintain reasonably appropriate security controls and to use our personal information only to provide services to us, except as required by law.
−Removed: While the Company has experienced, and may in the future experience, cybersecurity incidents, prior incidents have not materially affected the Company’s business, results of operations or financial condition.
−Removed: Although the Company has invested in the protection of its data and information technology and monitors its systems on an ongoing basis, there can be no assurance that such efforts will in the future prevent material compromises to Company information technology systems that could have a material adverse effect on the Company’s business.
+Added: While we have experienced, and may in the future experience, cybersecurity incidents, prior incidents have not materially affected the Company’s business, results of operations or financial condition.
+Added: Although we have invested in the protection of our data and information technology and monitor our systems on an ongoing basis, there can be no assurance that such efforts will in the future prevent material compromises to our information technology systems that could have a material adverse effect on our business.
Risk Factors, which are incorporated by reference into this Item 1C.
−Removed: Our Board of Directors has risk oversight responsibility for the Company and administers this responsibility both directly and with assistance from the Audit and Finance Committee, which periodically reports to the Board of Directors on its risk oversight activities.
+Added: Our Board of Directors has risk oversight responsibility for us and administers this responsibility both directly and with assistance from the Audit and Finance Committee, which periodically reports to the Board of Directors on its risk oversight
Cybersecurity is a critical component of our overall risk management program.
Our Board of Directors is actively involved in reviewing our information security and technology risks and opportunities (including cybersecurity) and discusses these topics on a regular basis.
−Removed: The Audit and Finance Committee, comprised solely of independent directors, oversees our enterprise risk management program and assists the Board of Directors in fulfilling its oversight responsibility with respect to our information security and technology risks (including cybersecurity), which are fully integrated into our enterprise risk management systems.
+Added: The Audit and Finance Committee, comprised solely of independent directors, oversees our enterprise risk management program and assists the Board of Directors in fulfilling its oversight responsibility with respect to our information security and technology risks (including cybersecurity), which are included as part of our enterprise risk management systems.
The Audit and Finance Committee reviews and discusses our information security and technology risks (such as cybersecurity), including our information security and risk management programs.
−Removed: Our cybersecurity program is contracted through and led by Harley-Davidson’s Chief Information Security and Privacy Officer (CISO) who is responsible for assessing and managing the Company’s data privacy function and information security and technology risks (including cybersecurity).
−Removed: The CISO has over 20 years of cyber industry and compliance experience, serving in a CISO capacity for over ten of those years.
−Removed: The CISO reports to Harley Davidson’s Chief Digital and Operations Officer, who has extensive experience in leading information systems management, strategy and operational execution, including information security and incident management, prevention and response.
+Added: Our cybersecurity program is contracted through and led by Harley-Davidson’s Chief Information Security (CISO) , who is responsible for assessing and managing our data privacy function and information security and technology risks (including cybersecurity).
+Added: In October 2025, the CISO left Harley-Davidson and the Chief Digital and Operations Officer assumed the responsibilities of acting CISO from October until his departure on December 31, 2025.
+Added: Harley-Davidson’s IT Security Manager is serving as acting CISO, executing all the responsibilities of the CISO, while Harley-Davidson conducts a search to fill the position.
+Added: The Company's IT Security Manager has over 20 years of experience in Information Technology, including 13 years focused on cybersecurity and regulatory compliance, with leadership roles spanning Enterprise Security Architecture, Security Operations and Incident Response, Cybersecurity Engineering, and Application Security.
+Added: This background includes developing and executing security strategies, managing incident prevention and response, and leading operational risk programs.
+Added: The CISO reports to Harley-Davidson’s Chief Legal, Compliance and Corporate Affairs Officer, who has been providing legal support to the Harley-Davidson’s Corporate Information Security Office for over nine years.
The Harley-Davidson CISO meets regularly with the appropriate management to review and discuss our cybersecurity and other information technology risks and opportunities.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.