6 unchanged sentences
Our enterprise risk management framework considers cybersecurity risk alongside other company risks as part of our overall risk assessment process.
−Removed: Our enterprise risk management team collaborates with our Information Security function, led by the Company’s Chief Strategy and Transformation Officer and the Company’s Chief Information Security Officer, to gather insights for identifying, assessing and managing cybersecurity threat risks, their severity, and potential mitigations.
−Removed: We assess PepsiCo’s Information Security program using an industry-leading cybersecurity framework from the National Institute of Standards and Technology.
+Added: Our enterprise risk management team collaborates with our Cybersecurity function, led by the Company’s Chief Strategy and Transformation Officer and the Company’s Chief Information Security Officer, to gather insights for identifying, assessing and managing cybersecurity threat risks, their severity, and potential mitigations.
+Added: We assess PepsiCo’s Cybersecurity program using an industry-leading cybersecurity framework from the National Institute of Standards and Technology.
To help assess and identify our cybersecurity risks, we maintain internal resources to perform penetration testing designed to simulate evolving tactics and techniques of real-world threat actors, engage with industry partners and law enforcement and intelligence communities and conduct tabletop exercises and periodic risk interviews across our business.
2 unchanged sentences
Our processes also address cybersecurity risks associated with our use of third-party service providers including suppliers, software and cloud-based service providers.
−Removed: We proactively evaluate the cybersecurity risk of a third party by utilizing a repository of risk assessments, external monitoring sources, threat intelligence and predictive analytics to better inform PepsiCo during contracting and vendor selection processes.
+Added: We proactively evaluate the cybersecurity risk of a third party by utilizing a repository of risk assessments, external monitoring
+Added: sources, threat intelligence and predictive analytics to better inform PepsiCo during contracting and vendor selection processes.
Additionally, we require those third parties to agree by contract to implement appropriate security controls.
4 unchanged sentences
We also maintain insurance coverage that, subject to its terms and conditions, is intended to address costs associated with certain aspects of cyber incidents and information systems failures.
−Removed: Based on the information we have as of the date of this Form 10-K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially
−Removed: affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
+Added: Based on the information we have as of the date of this Form 10-K, we do not believe any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
See “Item 1A.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.