UNRESOLVED STAFF COMMENTS
−Removed: RAYMOND JAMES FINANCIAL, INC.
−Removed: AND SUBSIDIARIES
CYBERSECURITY
−Removed: Cybersecurity risk is a key operational risk facing the firm, and measures to address such risk are an important component of the firm’s overall Enterprise Risk Management (“ERM”) program.
−Removed: As part of our ERM program, we have implemented and maintain a program to identify, assess, and manage risks arising from cybersecurity threats (“Cybersecurity Program”).
−Removed: Our Cybersecurity Program seeks to mitigate cybersecurity risk and associated legal, financial, reputational, regulatory and/or operational risks by protecting our clients, associates, and services through a comprehensive, cross-functional approach.
+Added: Cybersecurity risk is a key operational risk facing the firm, and measures to address such risk are an important component of the firm’s overall Enterprise Risk Management (“ERM”) framework.
+Added: As part of our ERM framework, we have implemented and maintain a program to identify, assess, and manage risks arising from cybersecurity threats (“Cybersecurity Program”).
+Added: Our Cybersecurity Program seeks to mitigate cybersecurity risk and associated legal, financial, reputational, regulatory and/or operational risks by protecting our clients, associates, firm data, and services through a comprehensive, cross-functional approach.
Specifically, our Cybersecurity Program is focused on preserving the confidentiality, integrity, and availability of information, enabling the secure and uninterrupted delivery of financial services, and protecting the firm and the safe operation of our technology systems.
3 unchanged sentences
Refer to “Item 1A - Risk Factors” of this Form 10-K for additional information on our cybersecurity risks.
+Added: RAYMOND JAMES FINANCIAL, INC.
+Added: AND SUBSIDIARIES
Cybersecurity risk management process
13 unchanged sentences
In addition, our processes are designed to help identify, oversee, and mitigate cybersecurity risks associated with our use of third-party vendors.
−Removed: We have a supplier risk management process that includes evaluation of, and response to, cybersecurity risks at our third-party vendors, and this process covers vendor selection, onboarding, performance monitoring, and risk management.
−Removed: Our supplier risk management program includes policies and standards requiring that we perform cybersecurity due diligence reviews on our vendors based on the inherent risk profile of a particular supplier or service provider.
−Removed: We also monitor certain of our principal suppliers and service providers on an ongoing basis by conducting additional periodic reviews.
−Removed: Additionally, we execute agreements with our third-party vendors, independent contractor financial advisors, and firms
−Removed: RAYMOND JAMES FINANCIAL, INC.
−Removed: AND SUBSIDIARIES
−Removed: affiliated with us through our RCS division under which these parties contractually agree to implement certain safeguards designed to protect firm data and mitigate cybersecurity risks.
+Added: We have a third-party risk management process that includes evaluation of, and response to, cybersecurity risks at our third-party vendors, and this process covers vendor selection, onboarding, performance monitoring, and risk management.
+Added: Our third-party risk management program includes policies and standards requiring that we perform cybersecurity due diligence reviews on our vendors based on the inherent risk profile of a particular supplier or service provider.
+Added: We also monitor our principal third parties and service providers on an ongoing basis by conducting additional periodic reviews.
+Added: Additionally, we execute agreements with our third-party vendors, independent contractor financial advisors, and firms affiliated with us through our RCS division under which these parties contractually agree to implement certain safeguards designed to protect firm data and mitigate cybersecurity risks.
We also maintain business continuity plans that include identification of critical functions, third-party suppliers, and personnel.
3 unchanged sentences
While we and our third-party vendors have experienced cybersecurity incidents, as well as adverse impacts from such incidents, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected the firm, including our business strategy, results of operations, or financial condition.
−Removed: However, due to the evolving threat environment, we expect to continue to experience cybersecurity incidents resulting in adverse impacts with increased frequency and severity, and there can be no assurance that future cybersecurity incidents, including incidents experienced by our third-party vendors, will not have a material adverse impact on the firm, including its business strategy, results of operations, financial condition, and/or reputation.
+Added: However, due to the evolving threat environment, we expect to continue to experience cybersecurity incidents resulting in adverse impacts with increased frequency and severity, and there can be no assurance that future cybersecurity incidents, including incidents experienced by our third parties, will not have a material adverse impact on the firm, including its business strategy, results of operations, financial condition, and/or reputation.
See Item 1A - Risk Factors of this Form 10-K for additional information on our cybersecurity risks.
+Added: RAYMOND JAMES FINANCIAL, INC.
+Added: AND SUBSIDIARIES
The Board of Directors has designated its Risk Committee to assist it in overseeing management’s responsibility to implement an effective risk management framework designed to identify, assess, and manage key risks, including cybersecurity risk.
4 unchanged sentences
Under the Risk Committee’s oversight, management works closely with key stakeholders, including regulators, government agencies, peer institutions, and industry groups, and develops and invests in human talent and innovative technology in order to better manage cybersecurity risk.
−Removed: The firm’s cybersecurity program is led by our CISO, who, effective October 1, 2024, reports to our Chief Information Officer (“CIO”).
+Added: The firm’s Cybersecurity Program is led by our CISO , who reports to our Chief Information Officer (“CIO”).
The CISO, in coordination with our information technology, compliance (including privacy), and risk management functions, works collaboratively across the firm to implement a program designed to protect the firm’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the firm’s incident response and recovery plans.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.