2 unchanged sentences
CYBERSECURITY
−Removed: Murphy’s cybersecurity environment is led by the Company’s Information Technology (IT) group, which, in addition to cybersecurity matters, oversees the Company’s IT infrastructure.
−Removed: Within the IT group, the Murphy Cybersecurity Team (MCT) is responsible for monitoring and managing security of the corporate network and enterprise systems, including developing and deploying policies, technical controls, and safety protocols and responding to security threats.
+Added: Murphy’s cybersecurity environment and risk strategy is broadly managed by the Company’s Information Technology (IT) group, which oversees the Company’s IT and Operational Technology (OT) infrastructure.
+Added: Within the IT group, the Murphy Cybersecurity Team (MCT) is specifically responsible for monitoring and managing security of the enterprise IT and OT network and systems, including developing and deploying administrative policies, technical controls, and safety protocols necessary to prevent unauthorized access, theft, damage, or loss of Company data or systems.
All members of the MCT hold globally-recognized security certifications and have wide-ranging experience in cybersecurity matters.
−Removed: The Incident Management Team (IMT) is responsible for responding to active threats and incidents as they occur.
−Removed: The Chief Information Officer is a member of the IMT, and regularly provides briefings to the Chief Executive Officer, the executive leadership team, and the Audit Committee of the Board.
−Removed: The Audit Committee is ultimately responsible for ensuring that management has processes in place to identify and evaluate cybersecurity risks to which Murphy is exposed and to implement processes and programs to manage cybersecurity risks and mitigate any incidents.
−Removed: The Audit Committee also reports material cybersecurity risks to the Board.
+Added: The Incident Management Team (IMT) is responsible for responding to active security threats and incidents as they occur.
+Added: The Chief Information Officer oversees the IT group and is a member of the IMT, and provides briefings to the CEO, the executive leadership team, and the Audit Committee of the Board regarding cybersecurity risks, strategy, and management at least annually .
+Added: The Audit Committee is ultimately responsible for overseeing cybersecurity strategy and ensuring that management has sufficient resources, programs, and processes in place to identify, evaluate, manage, and mitigate relevant cybersecurity risks to which Murphy is exposed and to implement processes and programs to manage cybersecurity risks and mitigate any incidents.
+Added: The Audit Committee also reports material cybersecurity risks to the Board as appropriate.
We believe this visibility and oversight structure allows the Board and executive leadership team to make timely, data-driven decisions ensuring that Murphy, its employees, investors, and partners are adequately protected.
−Removed: Murphy considers its protection from cybersecurity threats to be a core component of its overall enterprise risk management system.
−Removed: Murphy’s cybersecurity risk management framework consists of cyber readiness, cybersecurity governance, and risk management strategy.
−Removed: The cybersecurity risk management framework is incorporated into the overall enterprise risk management process through policies, procedures, periodic simulations, and constant monitoring of the cybersecurity environment for new and emerging threats.
−Removed: The Company also requires employees to receive regular cybersecurity training and education to mitigate cybersecurity risks.
+Added: Murphy considers its cybersecurity risk management framework to be a core component of its overall enterprise risk management system.
+Added: The cybersecurity risk management framework directly aligns with the National Institute of Standards and Technology Cybersecurity Framework and involves regular review and update of security policies and procedures;
+Added: leverage of industry-leading technologies focused on continuously monitoring, analyzing, and defending against intrusions;
+Added: regular testing of such technologies and other controls;
+Added: periodic simulations of security incidents;
+Added: and constant monitoring of the broader cybersecurity environment for new and emerging threats.
+Added: The Company also requires employees to attend regular cybersecurity training and education to mitigate cybersecurity risks.
To remain informed of the cybersecurity landscape, the Company collaborates with peers, third-party advisors, industry groups and policymakers.
1 unchanged sentence
Murphy utilizes these consultants to perform forensic analysis of data published by threat actors, to monitor and scan Murphy’s systems for threat vectors, and to consult on emerging cybersecurity environment topics.
−Removed: Murphy utilizes industry leading technologies that focus on continuous monitoring and analytics built on machine learning and artificial intelligence to safeguard against sophisticated cyberattacks.
−Removed: Deployed technologies include next generation firewalls, advanced endpoint and email protection, multi-factor authentication and Managed Detection and Response.
−Removed: In addition to the monitoring and detection processes for its own IT systems, Murphy also has processes in place to identify cybersecurity threats associated with third party service providers and partners;
−Removed: these processes include industry information sharing groups, cybersecurity notification services, vendor risk assessments, and ongoing collaboration with federal agencies.
−Removed: Murphy has not experienced any material impacts to our business, operations, or reputation due to cyberattacks or other security-related incidents.
−Removed: However, we recognize cyber threats are constantly evolving and are committed to cultivating a culture of security, remaining vigilant and continually improving our cybersecurity environment and controls.
−Removed: Descriptions of the Company’s oil and natural gas properties are included in Item 1 of this Form 10-K report beginning on page 1.
−Removed: Information required by the Securities Exchange Act Industry Guide No.
−Removed: 2 can be found in the Supplemental Oil and Gas Information section of this Annual Report on Form 10-K on pages 103 to 118 and in Note D beginning on page 77.
+Added: In addition to monitoring its own IT systems, Murphy also has processes in place to identify cybersecurity risks and threats associated with third party service providers and partners.
+Added: These processes include conducting vendor due diligence and risk assessments, participating in industry information sharing groups, subscribing to cybersecurity notification services, and maintaining ongoing collaboration with federal agencies.
+Added: To our knowledge, Murphy has not experienced any cybersecurity incidents that have had, or are likely to have, material impacts to our business, operations, finances, or reputation .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.