−Removed: Staff Comments
−Removed: Cybersecurity Risk Management, Strategy,
−Removed: and Governance
+Added: Unresolved Staff Comments
+Added: Cybersecurity Risk Management, Strategy, and Governance
the ordinary course of our business, we receive, process, use, store and share digitally large amounts of data, including user data as
7 unchanged sentences
systems and the data residing in them.
−Removed: In 2023, we did not identify
−Removed: any cybersecurity breaches that materially affected, or are reasonably likely to materially affect, our business strategy, results of
−Removed: operations, or financial condition.
−Removed: Management’s Role
−Removed: Our management team is responsible
−Removed: for monitoring, preventing, detecting, mitigating and remediating cybersecurity incidents.
−Removed: Our chief technology officer has over 40 years
−Removed: of experience and has held various leadership roles in information technology, including serving as a chief information officer and chief
−Removed: technology officer for the last 12 years.
−Removed: He has successfully implemented and managed large enterprise resource planning systems, e-commerce
−Removed: websites, stores and enterprise infrastructure, both cloud-based and on-premise.
−Removed: His expertise extends to evaluating and hiring cybersecurity
−Removed: personnel and outsourced managed services, defining incident response plans, conducting tabletop exercises, and establishing communication
−Removed: protocols with internal executives, board members, and vendors.
−Removed: He has firsthand experience in responding to actual cybersecurity incidents,
−Removed: showcasing a deep understanding of the challenges and complexities within the cybersecurity landscape in the retail sector.
−Removed: director of cybersecurity and compliance has a 15-year track record as an information technology and information security professional,
−Removed: complemented by an Executive MBA.
−Removed: His career is distinguished by a decade of leadership as the commander of the United States Army cyber
−Removed: protection team (174 CPT), where he gained cybersecurity experience at USCYBERCOM and ARCYBER.
−Removed: He holds multiple professional certifications,
−Removed: including CISSP, PMP and multiple SANS certifications.
−Removed: Our chief technology officer and senior director of cybersecurity and compliance
−Removed: report to the Audit Committee on these matters.
−Removed: We maintain a cybersecurity
−Removed: risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
−Removed: Our cybersecurity risk management
−Removed: processes are being integrated into our overall risk management processes.
−Removed: We are making efforts to incorporate cybersecurity considerations
−Removed: as a part of our business processes.
−Removed: We engage with external cybersecurity experts, including assessors, consultants, and auditors, to
−Removed: enhance our cybersecurity measures and ensure compliance with industry best practices.
−Removed: For example, a comprehensive cyber risk assessment,
−Removed: both physical and logical, was conducted by a third party, serving as an external penetration test to validate our security posture.
−Removed: have established processes to oversee and manage cybersecurity risks associated with our use of third-party service providers, ensuring
−Removed: they adhere to our security standards.
−Removed: We review third-party service provider contracts to ensure they contain data privacy and security
−Removed: provisions, aligning with our standards and regulatory requirements.
−Removed: Additionally, we have established a Technology Review Committee (“TRC”)
−Removed: tasked with the role of evaluating new software tools and technologies before their implementation.
−Removed: The TRC consists of experts from various
−Removed: domains within our organization, including information technology security, compliance, legal, and operations.
−Removed: This TRC conducts assessments
−Removed: to ensure that any new software tools meet our standards for security, compliance and operational efficiency.
−Removed: Board of Directors Oversight
−Removed: The oversight of our cybersecurity
−Removed: is assigned to the Audit Committee of our Board of Directors.
−Removed: The Audit Committee receives regular reports and briefings from management
−Removed: on our cybersecurity threat risk management and strategy processes, including on topics such as our data security posture, results from
−Removed: third-party assessments, progress towards pre-determined risk-mitigation-related goals, incident response plans, and cybersecurity threat
−Removed: risks or incidents and developments, as well as the steps management has taken to respond to these risks.
−Removed: In addition, management updates
−Removed: the Audit Committee as necessary regarding any material cybersecurity incidents as well as any incidents with lesser impact potential.
+Added: 2024, we did not identify any cybersecurity breaches that materially affected, or are reasonably likely to materially affect, our business
+Added: strategy, results of operations, or financial condition.
+Added: management team is responsible for monitoring, preventing, detecting, mitigating and remediating cybersecurity incidents.
+Added: Our chief technology
+Added: officer has over 41 years of experience and has held various leadership roles in information technology, including serving as a chief
+Added: information officer and chief technology officer for the last 13 years.
+Added: He has successfully implemented and managed large enterprise
+Added: resource planning systems, e-commerce websites, stores and enterprise infrastructure, both cloud-based and on-premise.
+Added: His expertise
+Added: extends to evaluating and hiring cybersecurity personnel and outsourced managed services, defining incident response plans, conducting
+Added: tabletop exercises, and establishing communication protocols with internal executives, board members, and vendors.
+Added: He has firsthand experience
+Added: in responding to actual cybersecurity incidents, showcasing a deep understanding of the challenges and complexities within the cybersecurity
+Added: landscape in the retail sector.
+Added: Our senior director of cybersecurity and compliance has a 16-year track record as an information technology
+Added: and information security professional, complemented by an Executive MBA.
+Added: His career is distinguished by a decade of leadership as the
+Added: commander of the United States Army cyber protection team (174 CPT), where he gained cybersecurity experience at USCYBERCOM and ARCYBER.
+Added: He holds multiple professional certifications, including CISSP, PMP and multiple SANS certifications.
+Added: Our chief technology officer and
+Added: senior director of cybersecurity and compliance report to the Audit Committee on these matters.
+Added: maintain a cybersecurity risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
+Added: Our cybersecurity risk management processes are being integrated into our overall risk management processes.
+Added: We are making efforts to
+Added: incorporate cybersecurity considerations as a part of our business processes.
+Added: We engage with external cybersecurity experts, including
+Added: assessors, consultants, and auditors, to enhance our cybersecurity measures and ensure compliance with industry best practices.
+Added: a comprehensive cyber risk assessment, both physical and logical, was conducted by a third party, serving as an external penetration
+Added: test to validate our security posture.
+Added: We have established processes to oversee and manage cybersecurity risks associated with our use
+Added: of third-party service providers, ensuring they adhere to our security standards.
+Added: We review third-party service provider contracts to
+Added: ensure they contain data privacy and security provisions, aligning with our standards and regulatory requirements.
+Added: Additionally, we have
+Added: established a Technology Review Committee (“TRC”) tasked with the role of evaluating new software tools and technologies
+Added: before their implementation.
+Added: The TRC consists of experts from various domains within our organization, including information technology
+Added: security, compliance, legal, and operations.
+Added: This TRC conducts assessments to ensure that any new software tools meet our standards for
+Added: security, compliance and operational efficiency.
+Added: of Directors Oversight
+Added: oversight of our cybersecurity is assigned to the Audit Committee of our Board of Directors.
+Added: The Audit Committee receives regular reports
+Added: and briefings from management on our cybersecurity threat risk management and strategy processes, including on topics such as our data
+Added: security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, incident response
+Added: plans, and cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to these risks.
+Added: In addition, management updates the Audit Committee as necessary regarding any material cybersecurity incidents as well as any incidents
+Added: with lesser impact potential.
The Audit Committee received one report from our Senior Director of Cybersecurity and Compliance in 2024.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.