6 unchanged sentences
We also maintain processes and procedures for identifying and investigating cybersecurity threats and remediation should an incident occur.
−Removed: Despite our efforts to protect our systems and data, there can be no assurance that we are able to maintain effective preventive measures against all cybersecurity risks, especially because attacks can originate from a wide variety of sources, and the techniques used change frequently and may not be immediately recognizable.
+Added: Despite our efforts to protect our systems and data, there can be no assurance that we are able to maintain effective preventive measures against all cybersecurity risks, especially because attacks can originate from a wide variety of sources, and the techniques used change frequently and may not be immediately
+Added: THE CHARLES SCHWAB CORPORATION
+Added: recognizable.
Though the impact of prior cybersecurity events experienced by the Company has not been material to the Company’s strategy, results of operations, or financial condition, we continue to face increasing cybersecurity risks.
7 unchanged sentences
Schwab also engages with external firms specializing in discrete areas of cybersecurity to assess the Company’s practices, vulnerabilities, and overall cyber risk posture.
−Removed: Schwab’s corporate cybersecurity program is led by our Chief Information Security Officer (CISO) , who reports to our Chief Information Officer (CIO).
−Removed: The current CISO has been in his role for several years, and is responsible for our overall cybersecurity strategy, security engineering, security operations, cyber threat detection and incident response, and technology risk and compliance.
+Added: Schwab’s corporate cybersecurity program is led by our Chief Information Security Officer (CISO) , who reports up to our Chief Technology, Operations and Data Officer.
+Added: The current CISO was recently appointed after serving in another senior leadership role in technology risk management for more than seven years at the Company.
+Added: The CISO is responsible for our overall cybersecurity strategy, security engineering, security operations, cyber threat detection and incident response, and technology risk and compliance.
Our CISO has extensive experience assessing and managing cybersecurity risk, and is supported by a cybersecurity organization comprised of hundreds of professionals, many of whom hold various certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, and Certified in Risk and Information System Control.
−Removed: Our CISO and CIO regularly review our cybersecurity program and our prevention, detection, mitigation, and remediation efforts with management level risk committees and the Board Risk Committee, and we maintain a process for timely escalation of significant risk events to senior management and the Board .
+Added: Our CISO and Chief Technology, Operations and Data Officer regularly review our cybersecurity program and our prevention, detection, mitigation, and remediation efforts with management-level risk committees and the Board Risk Committee, and we maintain a process for timely escalation of significant risk events to senior management and the Board .
Risk Factors for additional discussion on information security risks.
See also Part II – Item 7 – Risk Management for additional information on the Company’s Enterprise Risk Management Framework, including further discussion of the Company’s risk governance and the management of related risks.
−Removed: THE CHARLES SCHWAB CORPORATION
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.