1 unchanged sentence
Cybersecurity
−Removed: Information security, including cybersecurity, is the risk of unauthorized access, use, disclosure, disruption, modification, recording or destruction of the firm’s information or systems.
As a large company in the financial services industry, we do business with a large number of clients, counterparties, and third-party service providers, and the nature of Schwab’s business involves the secure processing, storage, and transmission of confidential information about our clients and us.
3 unchanged sentences
We also maintain processes and procedures for identifying and investigating cybersecurity threats and remediation should an incident occur.
+Added: Despite our efforts to protect our systems and data, there can be no assurance that we are able to maintain effective preventive measures against all cybersecurity risks, especially because attacks can originate from a wide variety of sources, and the techniques used change frequently and may not be immediately recognizable.
Though the impact of prior cybersecurity events experienced by the Company has not been material to the Company’s strategy, results of operations, or financial condition, we continue to face increasing cybersecurity risks.
−Removed: THE CHARLES SCHWAB CORPORATION
−Removed: CSC’s Board of Directors oversees management’s processes for risk management, and the Risk Committee of the Board of Directors assists the Board in fulfilling its oversight responsibilities with respect to managing risks, including cybersecurity risks.
−Removed: Integrated within the Company’s overall enterprise risk management program, Schwab has an established information security program that knits together complementary tools, controls, and technologies to protect systems, client accounts and data.
−Removed: We continuously monitor the systems and work collaboratively with government agencies, law enforcement, and other financial institutions to address potential threats.
−Removed: We deploy advanced monitoring systems to identify suspicious activity and deter unauthorized access by internal or external actors.
−Removed: We also maintain policies, standards, and procedures, which apply to employees, contractors, and third parties, regarding the standard of care expected with all data, whether the data is internal company information, employee information, or non-public client information.
+Added: CSC’s Board of Directors, supported by the Board Risk Committee, oversees Schwab’s enterprise risk management process and policies, including cybersecurity risks.
+Added: Integrated within the Company’s overall enterprise risk management program, Schwab has an established information security program that is regularly assessed against formal industry standards and knits together complementary tools, controls, and technologies to protect systems, client accounts, and data.
+Added: We deploy advanced monitoring systems to identify suspicious activity and deter unauthorized access by internal or external actors, and work collaboratively with government agencies, law enforcement, and other financial institutions to address potential threats.
+Added: We evaluate and manage risk related to third-party vendors, assessing their cybersecurity programs and practices both prior to onboarding and over the term of service.
+Added: We also maintain policies, standards, and procedures, which apply to employees, contractors, and third parties, regarding the standard of care expected with all of our data, whether the data is internal company information, employee information, or non-public client information.
This includes limiting the number of employees who have access to clients’ personal information and internal authentication measures enforced to protect against the unauthorized use of employee credentials.
−Removed: All employees who handle sensitive information are trained in privacy and security.
+Added: Employees who handle sensitive information are trained in privacy and security, including training on recognizing social engineering.
Schwab also engages with external firms specializing in discrete areas of cybersecurity to assess the Company’s practices, vulnerabilities, and overall cyber risk posture.
2 unchanged sentences
Our CISO has extensive experience assessing and managing cybersecurity risk, and is supported by a cybersecurity organization comprised of hundreds of professionals, many of whom hold various certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, and Certified in Risk and Information System Control.
−Removed: Our CISO and CIO attend meetings of and present to the Risk Committee of CSC’s Board of Directors on our prevention, detection, mitigation, and remediation efforts of our cybersecurity program.
−Removed: We also have an escalation process in place to inform senior management and the Board of Directors of material cybersecurity incidents in a timely manner.
−Removed: Risk Factors for additional information on cybersecurity risk.
+Added: Our CISO and CIO regularly review our cybersecurity program and our prevention, detection, mitigation, and remediation efforts with management level risk committees and the Board Risk Committee, and we maintain a process for timely escalation of significant risk events to senior management and the Board .
+Added: Risk Factors for additional discussion on information security risks.
See also Part II – Item 7 – Risk Management for additional information on the Company’s Enterprise Risk Management Framework, including further discussion of the Company’s risk governance and the management of related risks.
+Added: THE CHARLES SCHWAB CORPORATION
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.