14 unchanged sentences
As part of its first line of defense, BNY Mellon
−Removed: maintains a dedicated Information Security Division (“ISD”), led by the Chief Information Security Officer (the “CISO”),
−Removed: that is responsible for the day-to-day management of risks from cybersecurity threats.
−Removed: ISD’s responsibilities include cybersecurity
−Removed: threat intelligence, incident response and other cybersecurity operations aimed at enabling BNY Mellon to identify, assess and manage
−Removed: existing and emerging cybersecurity threats.
−Removed: ISD monitors for potential threats and communicates relevant risks to the CISO and other
+Added: maintains a dedicated Cybersecurity organization, led by the Chief Information Security Officer (the “CISO”), that is responsible
+Added: for the day-to-day management of risks from cybersecurity threats.
+Added: Cybersecurity’s responsibilities include cybersecurity threat
+Added: intelligence, incident response and other cybersecurity operations aimed at enabling BNY Mellon to identify, assess and manage existing
+Added: and emerging cybersecurity threats.
+Added: Cybersecurity monitors for potential threats and communicates relevant risks to the CISO and other
members of executive management.
−Removed: Additionally, ISD maintains a cybersecurity incident response and reporting process pursuant to
−Removed: which cybersecurity incidents are classified according to their severity based upon an assessment of multiple factors.
+Added: Additionally, Cybersecurity maintains a cybersecurity incident response and reporting process pursuant
+Added: to which cybersecurity incidents are classified according to their severity based upon an assessment of multiple factors.
Certain cybersecurity
8 unchanged sentences
and test its cybersecurity controls and provide guidance on potential improvements, including design and operating effectiveness.
−Removed: has standing arrangements with third parties to assist BNY Mellon in identifying, assessing and managing cybersecurity threats, including
−Removed: in connection with risk assessments, penetration testing, legal advice and other aspects of BNY Mellon’s cybersecurity risk management
−Removed: and incident response processes.
+Added: Mellon’s information security management system is certified to the ISO 27001 standard by an independent, accredited certification
+Added: body, and BNY Mellon maintains this certification through periodic external audits and ongoing monitoring.
BNY Mellon has a defined third-party governance
5 unchanged sentences
of additional controls by BNY Mellon and/or the applicable service provider.
−Removed: ISD is subject to ongoing review and challenge
−Removed: from Technology Risk Management, which is a part of the independent second line of defense risk function.
+Added: Cybersecurity is subject to ongoing review and
+Added: challenge from Technology Risk Management, which is a part of the independent second line of defense risk function.
Technology Risk Management,
together with the broader Risk & Compliance group, is responsible for and manages BNY Mellon’s risk management framework
−Removed: and establishes guidance for ISD and management designed to help identify, assess and manage cybersecurity risk.
+Added: and establishes guidance for Cybersecurity and management designed to help identify, assess and manage cybersecurity risk.
BNY Mellon’s Internal Audit function serves
16 unchanged sentences
Oversight Committee, which is the senior management committee responsible for the governance and oversight of BNY Mellon’s significant
−Removed: technology projects and initiatives, reviews reports from management concerning ISD and is responsible for, among other things, escalating
−Removed: issues, including significant cybersecurity threats and incidents, to the Technology Committee of the Board.
−Removed: The Technology Oversight
−Removed: Committee is chaired by the Chief Information Officer (the “CIO”) and its members include the CISO.
+Added: technology projects and initiatives, reviews reports from management concerning Cybersecurity and is responsible for, among other things,
+Added: escalating issues, including significant cybersecurity threats and incidents, to the Technology Committee of the Board and the full Board
+Added: of Directors.
+Added: The Technology Oversight Committee is chaired by the Chief Information Officer and Global Head of Engineering (the “CIO”).
BNY Mellon’s Technology Risk Committee is
4 unchanged sentences
The Technology Risk Committee receives reports from management and has protocols for escalating certain
−Removed: issues and risks to the Senior Risk and Control Committee and the Risk Committee of the Board.
−Removed: The Technology Risk Committee is chaired
−Removed: by the interim Chief Technology Risk Officer.
+Added: issues and risks to the Enterprise Risk Committee and the Risk Committee of the Board.
+Added: The Technology Risk Committee is chaired by the
+Added: Chief Technology Risk Officer.
Members include key leaders from the first line of defense, including the CISO.
−Removed: BNY Mellon’s CIO, CISO and interim Chief
−Removed: Technology Risk Officer each have extensive experience in assessing and managing risks from cybersecurity threats.
−Removed: BNY Mellon’s
−Removed: CISO joined BNY Mellon in 2022 and previously served as head of information security at a Fortune 500 biopharmaceutical company and an
−Removed: information technology company, as well as the Global Chief Technology Officer at a large cybersecurity company.
−Removed: BNY Mellon’s CIO
−Removed: joined BNY Mellon in September 2024 from a large multinational company, where she was responsible for overseeing information technology
−Removed: and cybersecurity operations.
−Removed: BNY Mellon’s interim Chief Technology Risk Officer joined BNY Mellon in November 2024 and has
−Removed: previous experience as Global Head of Cyber, Technology and Information Security Risk Management at a global systemically important financial
−Removed: institution and over a decade of experience serving the U.S.
−Removed: intelligence community in a variety of cybersecurity-related positions.
+Added: BNY Mellon’s CIO, CISO and Chief Technology
+Added: Risk Officer each have extensive experience in assessing and managing risks from cybersecurity threats.
+Added: BNY Mellon’s CIO joined
+Added: BNY Mellon in 2024 from a large multinational company, where she was responsible for overseeing information technology and cybersecurity
+Added: BNY Mellon’s CISO joined BNY Mellon in 2025 and previously led the global assurance function for cybersecurity and technology
+Added: controls at a global systemically important financial institution.
+Added: BNY Mellon’s Chief Technology Risk Officer joined BNY Mellon
+Added: in 2024 and has previous experience as Global Head of Cyber, Technology and Information Security Risk Management at a global systemically
+Added: important financial institution and over a decade of experience serving the U.S.
+Added: intelligence community in a variety of cybersecurity-related
+Added: BNY Mellon believes that refreshing leadership in the CIO, CISO and Chief Technology Risk Officer roles brings new perspectives
+Added: and specialized expertise to enhance cybersecurity practices, while continuity is safeguarded through disciplined succession and transition
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.