2 unchanged sentences
Risk Management and Strategy
−Removed: Starbucks has implemented a cybersecurity program that leverages industry-standard cybersecurity frameworks to assess, identify, and manage cybersecurity risk.
+Added: Starbucks has implemented a cybersecurity program that leverages industry-standard cybersecurity frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework, to assess, identify, and manage cybersecurity risk.
Our cybersecurity program is integrated with the Enterprise Risk Management (“ERM”) framework and governance processes utilized by management and our Board to oversee our various top enterprise risks.
2 unchanged sentences
We periodically evaluate evolving cybersecurity risks and legal and compliance requirements, and we make ongoing strategic investments to address those evolving risks and requirements.
+Added: We also participate in multiple cybersecurity forums that share threat intelligence and best practices.
Starbucks assesses, measures, and reports on cybersecurity risk at operational, program or management, and strategic or executive oversight levels.
We maintain and periodically update written cybersecurity policies, standards, and controls, which are reviewed by a cross-functional management-level committee and designed to align with business objectives, regulatory requirements, and industry best practices.
−Removed: We train our employees through annual cybersecurity awareness training, phishing simulations, and periodic communications about timely cybersecurity topics and threats.
+Added: We train our employees through annual cybersecurity awareness training, which includes information about how to report cybersecurity concerns and incidents, as well as phishing simulations and periodic communications about timely cybersecurity topics and threats.
We also implement a variety of tools to monitor our systems and network activity, and we conduct various simulated attacks and penetration tests to assess the effectiveness of these tools.
1 unchanged sentence
The plan provides for the creation of a cross-functional, tailored incident response team, led by dedicated incident responders, that may include both Company personnel and third-party service providers, as appropriate.
−Removed: The incident response plan includes incident classification and escalation protocols, as well as processes to assess and comply with applicable legal obligations.
+Added: The incident response plan includes incident classification and escalation protocols, including a process for informing senior management and the Board, as appropriate, as well as processes to assess and comply with applicable legal obligations.
We periodically test the effectiveness of the plan, and review and update it, as appropriate.
5 unchanged sentences
However, there can be no assurance that we, or our third-party business partners or service providers, will not experience a cybersecurity threat or incident in the future that could materially adversely affect our business strategy, results of operations, or financial condition.
−Removed: For further discussion of the risks related to cybersecurity, see the risk factors discussed under “Risks Related to Cybersecurity and Data Privacy” in our Risk Factors in Item 1A of this Form 10-K.
+Added: For further discussion of the risks related to cybersecurity, see the risk factors discussed under “Risks Related to Cybersecurity, Data Privacy, and Information Technology” in our Risk Factors in Item 1A of this Form 10-K.
Our cybersecurity program is led by our senior vice president, chief information security officer (“ciso”), who is responsible for identifying, assessing, and managing our collective information security and technology risks.
−Removed: Our ciso has more than 20 years of experience in the information security and technology fields.
−Removed: The ciso reports to our executive vice president, chief technology officer, who has spent more than 25 years of service in various leadership roles in information technology across multiple Fortune 500 companies.
+Added: Our ciso has more than 20 years of experience in the information security and technology fields, including various leadership roles in several large companies across multiple industries.
+Added: Those roles have included leading various cybersecurity capabilities and managing information security, business intelligence, and data analytics teams.
The ciso is informed about the prevention, detection, mitigation, and remediation of cybersecurity incidents through management of, and participation in, the cybersecurity program described above, including through reports prepared by our internal cybersecurity team and the operation of our incident response plan.
−Removed: The ciso meets regularly with leaders of our various information technology management teams and with the Risk Management Committee (a management-level committee, which is co-managed by our cfo and chief legal officer), to review and discuss our cybersecurity and other information technology risks and opportunities.
−Removed: Our Board has ultimate cybersecurity and data privacy risk oversight responsibility for the Company and administers this responsibility both directly and with assistance from the Audit and Compliance Committee (“Audit Committee”) and the Environmental, Partner, and Community Impact Committee (the “Impact Committee”).
−Removed: The Audit Committee oversees our cybersecurity and technology risks, and the Impact Committee oversees our data privacy risks, all of which are integrated into our overall ERM program.
+Added: The ciso meets regularly with leaders of our various information technology management teams and with the Risk Management Committee (a cross-functional management-level
+Added: committee, which is co-managed by our cfo and chief legal officer and meets at least quarterly), to review and discuss our cybersecurity and other information technology risks and opportunities.
+Added: Our Board has ultimate cybersecurity and data privacy risk oversight responsibility for the Company and administers this responsibility both directly and with assistance from the Audit and Compliance Committee (“Audit Committee”).
+Added: The Audit Committee oversees our cybersecurity and technology risks, along with our data privacy risks, all of which are integrated into our overall ERM program.
The Audit Committee actively reviews and discusses our cybersecurity and technology risk management programs and regularly reports out to the full Board on our relevant strengths and opportunities.
−Removed: The Impact Committee reviews our data privacy risk management programs and reports out to the full Board on our relevant strengths and opportunities.
+Added: The Audit Committee also reviews our data privacy risk management programs and reports out to the full Board on our relevant strengths and opportunities.
The Audit Committee receives quarterly updates from the ciso or other members of the ciso’s team with responsibility for oversight of our key cybersecurity program components.
These updates include, as appropriate, ongoing changes in our external and internal cybersecurity threat landscape, new technology trends and regulatory developments, evolving internal policies and practices used to manage and mitigate cybersecurity and technology-related risks, cybersecurity incidents and our response to them, and trends in various metrics that are used to help assess our overall cybersecurity program effectiveness .
−Removed: The Impact Committee receives annual updates from our vice president, data privacy, on our data privacy practices, emerging risks, and evolving global privacy laws and regulations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.