3 unchanged sentences
We have in place certain infrastructure, systems, policies, and procedures that are designed to proactively and reactively address risks from cybersecurity threats.
+Added: This includes processes for assessing, identifying, and managing material risks from cybersecurity threats.
Our information security management program seeks to follow processes set forth in recognized industry standards, and we evaluate and evolve our security measures as appropriate.
−Removed: We maintain a cybersecurity incident response plan that we periodically practice and update as needed.
+Added: We maintain a cybersecurity incident response plan that we practice and update as needed.
The identification, assessment and management of cybersecurity risk is integrated into our overall enterprise risk management program that is ultimately overseen by the Board.
2 unchanged sentences
SMCI | 2025 Form 10-K | 34
−Removed: We have a vendor risk assessment process to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers.
+Added: We also have a vendor risk assessment process to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers.
These processes consist of the distribution and review of questionnaires designed to identify cybersecurity risks associated with the engagement of third parties.
−Removed: We also periodically audit cybersecurity practices of certain third-party service providers.
−Removed: We employ a number of protective measures, including firewalls, anti-virus and endpoint detection and response technologies, regular annual training of employees with respect to cybersecurity and testing employee competence with anti-phishing policies followed up by additional remedial training as needed.
+Added: We also audit cybersecurity practices of certain third-party service providers, and take steps designed to ensure that such vendors have implemented data privacy and security controls that help mitigate the cybersecurity risks associated with these vendors, depending on the nature and sensitivity of the supplier and data it processes on our behalf.
+Added: We routinely assess our high-risk suppliers’ conformance to industry standards and evaluate them for additional information, product, and physical security requirements.
+Added: We employ a number of protective measures, including firewalls, endpoint detection and response technologies, regular annual training of employees with respect to cybersecurity and testing employee competence with anti-phishing policies followed up by additional remedial training as needed.
While there have been cyber incidents in the past, none of these incidents, individually or in aggregate, had a material adverse effect on our business strategy, operations, or financial conditions.
2 unchanged sentences
The Audit Committee also reviews the adequacy and effectiveness of our information security policies and practices and the internal controls regarding information security risks.
−Removed: The Audit Committee receives updates relating to cybersecurity risk from management, including from our Director of Information Security.
−Removed: The Board also periodically receives reports on risks from cybersecurity threats from our Director of Information Security.
+Added: The Audit Committee and the Board receive regular information security updates relating to cybersecurity risk from management, including from our Director of Information Security.
Cybersecurity risk is primarily managed by our Directors of Information Security and Information Technology .
These individuals have decades of experience in managing cybersecurity risk for public companies.
−Removed: Additionally, we have established a cross-functional Cybersecurity Committee, consisting of executive-level leadership, including representatives from the Finance, Marketing, IT, Legal, Internal Audit, and other teams, that meets periodically to review cybersecurity risks, incidents, and assess emerging threats.
−Removed: The Committee is also informed of our responses to such risks, incidents and threats.
+Added: Additionally, we have established a cross-functional Cybersecurity Committee, consisting of executive-level leadership, including representatives from Finance, IT, Legal, and other teams, that meets periodically to review cybersecurity risks, incidents, and assess emerging threats.
+Added: The Cybersecurity Committee is also informed of our responses to such risks, incidents and threats.
Our cybersecurity incident response plan also contains mechanisms to notify executive management of cybersecurity incidents.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.