7 unchanged sentences
When cybersecurity risks are identified through the Enterprise Risk Management program or otherwise, they are reported to relevant business and governance leaders within the Company for appropriate action.
−Removed: To support the ongoing identification and management of cybersecurity issues, the Company provides information security employee training, conducts global and targeted phishing simulation campaigns and conducts tabletop exercises.
+Added: To support the ongoing identification and management of cybersecurity issues, the Company provides information security employee training, conducts global and targeted phishing simulation campaigns, conducts tabletop exercises and performs penetration testing, vulnerability and maturity assessments.
The Company also deploys a large library of security tools and experts to help prevent, detect, contain, eradicate and recover from potential cybersecurity issues and cyber-attacks.
−Removed: Further, the Company engages third-party consultants and services for cyber intelligence, insights and assessments of its cybersecurity risk posture and governance.
+Added: Further, the Company engages third-party consultants and services for cyber intelligence, insights, incident response support and assessments of its cybersecurity risk posture and governance.
Cybersecurity reviews are embedded into the Company’s Third-Party Risk Management program.
11 unchanged sentences
Within management, the Company’s CISO has specific responsibility for cybersecurity risk management, reporting to the CIO.
−Removed: The Company’s CISO has over 15 years of experience in cybersecurity, information security and information risk management, including several years each in security engineering and in operations, as well as running incident response organizations.
+Added: The Company’s CISO has over 20 years of experience at the Company with significant experience in supply chain operations, risk management and governance and information security.
The CISO's organization includes a dedicated team of centralized information security experts and a network of security professionals embedded in each business unit and function.
−Removed: 10 The Procter & Gamble Company
The CISO also leads the design and development of the Company’s cybersecurity program, relying on functional experts within the central Information Security organization as well as on information security experts within each of the Company’s Organizational Units.
1 unchanged sentence
Experts within the Company’s central Information Security organization help develop the Company’s cybersecurity strategies, policies and standards and similarly report security risks within the central enterprise to the CISO.
−Removed: A central team within the Company leads enterprise-wide incident investigations and response, assisting and consulting on cyber security incidents impacting individual Organizational Units.
+Added: 10 The Procter & Gamble Company
+Added: A central team within the Company leads enterprise-wide incident investigations and response, assisting and consulting on cybersecurity incidents impacting individual Organizational Units.
Alerts of potential incidents can arise from security tool alerts, employee reports, threat intelligence sources, threat hunting activities or external entities, among other sources.
1 unchanged sentence
Members of the Security Operations Center and relevant response teams work to contain and eradicate potential and identified threats and support the system’s recovery efforts, advised as needed by the Legal department and other Company experts.
−Removed: Incidents are communicated to the CISO and other members of management, including the Company’s Ethics & Compliance Committee, as well as the Audit Committee of the Board, based on documented escalation criteria.
+Added: As a part of the incident response process, the severity of cybersecurity incidents are assessed based on the nature, scope, timing and potential impact of the incident on the Company's business, operations and financial condition.
+Added: Incidents are communicated to the CISO and other members of management, including the Company’s Ethics & Compliance Committee, as well as the Audit Committee of the Board, in accordance with documented escalation criteria.
The central enterprise team also regularly reviews incident reports to update the CISO.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.