10 unchanged sentences
Our cybersecurity program provides (among other things) a framework for handling cybersecurity threats and incidents, which includes steps for identifying the nature of a cybersecurity threat (including whether the threat is associated with a third-party provider), assessing the severity of a cybersecurity threat (including advancing to key members of management where appropriate for determination of potential materiality) and implementing cybersecurity processes and procedures.
−Removed: MASTERCARD 2023 FORM 10-K 41
−Removed: CYBERSECURITY
Program highlights
10 unchanged sentences
Our Board and Risk Committee have specific oversight responsibilities with respect to cybersecurity and privacy risk:
+Added: MASTERCARD 2024 FORM 10-K 39
+Added: CYBERSECURITY
Understanding the issues and risks that are central to the company’s success, including cybersecurity matters
• Risk Committee:
−Removed: Overseeing risks relating to our policies, procedures and strategic approach to information security (inclusive of cybersecurity), privacy and data protection
+Added: Overseeing risks relating to our policies, procedures and strategic approach to information security (inclusive of cybersecurity), privacy and data protection, among other things
In general, the Audit Committee and Risk Committee coordinate to oversee our guidelines and policies with respect to risk assessment and risk management and our Audit Committee discusses our financial and operational risk exposures and the steps management has taken to monitor and control such exposures.
1 unchanged sentence
Management responsibilities
−Removed: We have a core group of senior executives who are responsible for assessing and managing risk and implementing policies, procedures and strategies pertaining to security governance and data privacy.
+Added: We have a core group of senior executives who are responsible for assessing and managing risk and implementing policies, procedures and strategies pertaining to security governance, data protection and privacy.
These executives include:
• Chief Security Officer (CSO) , who develops and oversees the programs, policies and controls we have implemented across the organization to reduce and prevent logical and physical risks, including information security and cyber risks to our people, intellectual property, data and tangible property
−Removed: • Chief Privacy and Data Responsibility Officer , who establishes and oversees the programs, policies, processes and controls we have implemented across the organization to ensure compliance with worldwide laws and regulations regarding how we collect, use, share, store, transfer and otherwise process data and leverage AI, while also managing our relevant engagements with regulators, policymakers and key stakeholders
−Removed: • Chief Data Officer , who oversees our efforts to maintain an ethical, responsible enterprise data program that adheres to our high standards for data quality, curation and governance while minimizing data risks
−Removed: • Data Protection Officer , who reports to the Chief Privacy and Data Responsibility Officer and ensures that we continue to adhere to the GDPR and local privacy requirements, including by handling privacy requests from individuals and regulators
+Added: • Chief Privacy and Data Responsibility Officer , who establishes and oversees the programs, policies, processes and controls we have implemented across the organization to ensure compliance with worldwide laws and regulations regarding how we collect, use, share, store, transfer and otherwise process data and utilize AI, while also managing our relevant engagements with regulators, policymakers and key stakeholders
+Added: • Chief Data Officer , who establishes and oversees our efforts to maintain an ethical, responsible enterprise data program that adheres to our high standards for data quality, curation and governance while minimizing data risks
+Added: • Data Protection Officer , who reports to the Chief Privacy and Data Responsibility Officer and, with the support of the Global Data Protection Office, ensures that we continue to adhere to the GDPR and local privacy requirements, including by handling privacy requests from individuals and regulators
In order to be appointed to one of the roles described above, we require expertise with cybersecurity or data privacy (as applicable), as demonstrated by prior work or other cybersecurity or data privacy experience or possession of a cybersecurity or data privacy degree or certification.
−Removed: The individuals currently serving in these roles each meet the applicable expertise requirements.
−Removed: 42 MASTERCARD 2023 FORM 10-K
−Removed: CYBERSECURITY
+Added: Each individual currently serving in these roles meets the applicable expertise requirements.
How management is informed of and monitors incidents
Our management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risks are monitored, implementing appropriate mitigation measures and maintaining our cybersecurity programs.
−Removed: Our cybersecurity programs are under the direction of our CSO (in coordination with our Chief Privacy and Data Responsibility Officer, Chief Data Officer, among others), who receives reports from our cybersecurity teams and monitors the prevention, detection, mitigation and remediation of cybersecurity incidents.
+Added: Our cybersecurity programs are under the direction of our CSO (in coordination with our Chief Privacy and Data Responsibility Officer and Chief Data Officer, among others), who receives reports from our cybersecurity teams and monitors the prevention, detection, mitigation and remediation of cybersecurity incidents.
Our management, including the CSO and our cybersecurity teams, follow a risk-based escalation process to notify the Risk Committee outside of the regular reporting cycle as appropriate when they identify an emerging risk or material issue.
3 unchanged sentences
Our Risk Committee receives regular reports on our cyber readiness, our risk profile status, our cybersecurity programs, material cybersecurity risks and mitigation strategies, third-party assessments of our cybersecurity program and other cybersecurity developments.
−Removed: The Risk Committee chair provides reports to the Board on such topics.
−Removed: In addition, our Board and the Risk Committee also receive information about these topics as part of regular business and legal and regulatory updates.
+Added: The Risk Committee Chairperson provides reports to the Board on such topics.
+Added: Our Board and the Risk Committee also receive information about these topics as part of regular business and legal and regulatory updates.
In addition, we engage directors as part of cybersecurity and data breach incident simulations.
+Added: Further, the Audit Committee would be informed of a material cybersecurity incident that could have a potential impact on our financial statements.
Despite our efforts to identify and respond to cybersecurity threats, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident.
See “Risk Factors – Information Security and Operational Resilience” in Part I, Item 1A for more information about these and other risks related to information security.
+Added: 40 MASTERCARD 2024 FORM 10-K
+Added: CYBERSECURITY
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.