11 unchanged sentences
designed to detect, prevent and respond to malicious and accidental disruptions to the delivery of critical technology services.
−Removed: Mellon’s cybersecurity strategy and procedures are embedded in its Three Lines of Defense model.
+Added: BNY Mellon’s
+Added: cybersecurity risk management program is embedded in its three lines of defense model.
As part of its first line of defense, BNY Mellon
1 unchanged sentence
that is responsible for the day-to-day management of risks from cybersecurity threats.
−Removed: ISD’s responsibilities include cyber threat
−Removed: intelligence, incident response and other cybersecurity operations aimed at enabling BNY Mellon to identify, assess and manage existing
−Removed: and emerging cybersecurity threats.
−Removed: ISD monitors for potential threats and communicates relevant risks to the CISO and other members
−Removed: of executive management.
−Removed: Additionally, ISD maintains a cybersecurity incident response and reporting process pursuant to which cybersecurity
−Removed: incidents are classified according to their severity based upon an assessment of multiple factors.
−Removed: Certain cybersecurity incidents may
−Removed: activate enterprise-wide resiliency processes, which include, among other things, escalation through the management and Board committee
−Removed: structures described below.
−Removed: BNY Mellon also has standing arrangements with third parties to assist BNY Mellon in identifying, assessing
−Removed: and managing cybersecurity threats, including in connection with risk assessments, penetration testing, legal advice and other aspects
−Removed: of BNY Mellon’s cybersecurity risk management and incident response processes.
+Added: ISD’s responsibilities include cybersecurity
+Added: threat intelligence, incident response and other cybersecurity operations aimed at enabling BNY Mellon to identify, assess and manage
+Added: existing and emerging cybersecurity threats.
+Added: ISD monitors for potential threats and communicates relevant risks to the CISO and other
+Added: members of executive management.
+Added: Additionally, ISD maintains a cybersecurity incident response and reporting process pursuant to
+Added: which cybersecurity incidents are classified according to their severity based upon an assessment of multiple factors.
+Added: Certain cybersecurity
+Added: incidents may activate enterprise-wide resiliency processes, which include, among other things, escalation through the management and
+Added: Board committee structures described below.
+Added: In addition, BNY Mellon maintains a preparedness program designed to reinforce cybersecurity
+Added: risk management practices and compliance with BNY Mellon’s policies and procedures.
+Added: The preparedness program includes mandatory
+Added: training for all employees, contractors and consultants, enhanced training for those in roles presenting higher risk, calibrated phishing
+Added: email simulations, distribution of information security awareness materials and cybersecurity event simulation exercises.
+Added: BNY Mellon leverages both internal and external assessments and engages with third-party assessors, consultants and auditors to evaluate
+Added: and test its cybersecurity controls and provide guidance on potential improvements, including design and operating effectiveness.
+Added: has standing arrangements with third parties to assist BNY Mellon in identifying, assessing and managing cybersecurity threats, including
+Added: in connection with risk assessments, penetration testing, legal advice and other aspects of BNY Mellon’s cybersecurity risk management
+Added: and incident response processes.
BNY Mellon has a defined third-party governance
33 unchanged sentences
BNY Mellon’s Technology Risk Committee is
−Removed: responsible for, among other things, overseeing and reviewing significant cybersecurity incidents.
−Removed: The Technology Risk Committee receives
−Removed: reports from management and has protocols for escalating certain issues and risks to the Senior Risk and Control Committee and the Risk
−Removed: Committee of the Board.
−Removed: The Technology Risk Committee is co-chaired by the Head of Technology Risk and Control and the Chief Technology
−Removed: Risk Officer, and the CISO is a member.
−Removed: BNY Mellon’s CIO, CISO and Chief Technology
−Removed: Risk Officer each have extensive experience in assessing and managing risks from cybersecurity threats.
−Removed: BNY Mellon’s CISO joined
−Removed: BNY Mellon in 2022 and previously served as head of information security at a Fortune 500 biopharmaceutical company and an information
−Removed: technology company, as well as the Global Chief Technology Officer at a large cybersecurity company.
−Removed: BNY Mellon’s CIO has served
−Removed: in that position since 2017 and previously held roles as Chief Information Officer, Chief Technology Officer, and numerous other technology
−Removed: management positions at other large financial institutions.
−Removed: BNY Mellon’s Chief Technology Risk Officer joined BNY Mellon in 2021
−Removed: and previously served as Global Head of Technology Risk Management, Chief Information Security Officer, Global Head of Cyber Risk and
−Removed: Operational Resilience and Chief Risk Officer for Technology and Operations at other large financial institutions.
+Added: the most senior governance committee primarily focused on cybersecurity and technology risk issues and is a part of the second line of
+Added: defense risk function.
+Added: It is responsible for, among other things, overseeing and reviewing emerging cybersecurity risks, significant cybersecurity
+Added: incidents and remediation plans.
+Added: The Technology Risk Committee receives reports from management and has protocols for escalating certain
+Added: issues and risks to the Senior Risk and Control Committee and the Risk Committee of the Board.
+Added: The Technology Risk Committee is chaired
+Added: by the interim Chief Technology Risk Officer.
+Added: Members include key leaders from the first line of defense, including the CISO.
+Added: BNY Mellon’s CIO, CISO and interim Chief
+Added: Technology Risk Officer each have extensive experience in assessing and managing risks from cybersecurity threats.
+Added: BNY Mellon’s
+Added: CISO joined BNY Mellon in 2022 and previously served as head of information security at a Fortune 500 biopharmaceutical company and an
+Added: information technology company, as well as the Global Chief Technology Officer at a large cybersecurity company.
+Added: BNY Mellon’s CIO
+Added: joined BNY Mellon in September 2024 from a large multinational company, where she was responsible for overseeing information technology
+Added: and cybersecurity operations.
+Added: BNY Mellon’s interim Chief Technology Risk Officer joined BNY Mellon in November 2024 and has
+Added: previous experience as Global Head of Cyber, Technology and Information Security Risk Management at a global systemically important financial
+Added: institution and over a decade of experience serving the U.S.
+Added: intelligence community in a variety of cybersecurity-related positions.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.