2 unchanged sentences
Risk Management and Strategy
−Removed: As a large, multinational transportation and logistics company, we face a range of risks from cybersecurity threats in connection with our operations due to our inherent dependence on interconnected advanced information systems, software, and digital technologies to operate safely, efficiently, and effectively.
+Added: As a large, multinational transportation and logistics company, we and our subsidiaries each face a range of risks from cybersecurity threats in connection with our operations due to our inherent dependence on information systems, software, and digital technologies to operate safely, efficiently, and effectively.
Such risks include, but are not limited to, those related to cyberattacks, network breaches, ransomware, malware or denial-of-service attacks, phishing and other scams, theft, and unauthorized disclosure, any of which, if successful, could result in the disclosure of confidential customer or commercial data, loss of valuable intellectual property, or systems disruption, and subject us to civil liability, fines, penalties, damage of our brand or reputation, or otherwise harm our business, any of which, could be material.
−Removed: We are exposed to such risks both through direct attacks on our own information systems and, indirectly, as a result of our engagement of third-party service providers, software vendors, and independent contractors, such as cloud computing providers.
+Added: We and our subsidiaries are each exposed to such risks both through direct attacks on our own information systems and, indirectly, as a result of our engagement of third-party service providers, software vendors, and independent contractors, such as cloud computing providers.
Certain of our third-party service providers or software vendors provide us with computing services which, in certain cases, involve hosting our data or processes on third-party servers, which exposes us to the risk that our data may be compromised or our operations disrupted if such third-party servers are compromised.
7 unchanged sentences
Our cyber risk management methodology is comprised of the following core tasks:
−Removed: • Risk identification .
−Removed: Our internal information security team works with a MSSP and other external security partners to identify existing and new threats to our information systems.
+Added: • Risk identification – Our internal information security team works with an MSSP and other external security partners to identify existing and new threats to our information systems.
Our information security team, working in partnership with our MSSP, monitors our information systems to identify malicious and anomalous activity, uncover potential cybersecurity threats, and assess risks to information systems.
−Removed: • Risk analysis.
−Removed: Our information security team, working in partnership with relevant cybersecurity and technology experts, analyzes identified threats to determine the likelihood of the actualization of a threat and the potential business impacts, including evaluating the potential for data loss, data corruption, disruption to business operations, and financial impact.
−Removed: • Risk evaluation.
−Removed: Identified risks are evaluated to determine whether gaps in our controls or risk mitigation strategies exist that could result in material risk to the Company.
+Added: • Risk analysis – Our information security team, working in partnership with relevant cybersecurity and technology experts, analyzes identified threats to determine the likelihood of the actualization of a threat and the potential business impacts, including evaluating the potential for data loss, data corruption, disruption to business operations, and financial impact.
+Added: • Risk evaluation – Identified risks are evaluated to determine whether gaps in our controls or risk mitigation strategies exist that could result in material risk to the Company.
If it is determined that our existing processes, strategies, or technology may be insufficient to effectively mitigate or manage an identified risk, it is escalated to our CITO and SDIS to assess and implement potential responsive or corrective actions in our processes, strategies, or technology to address the risk.
−Removed: • Risk mitigation.
−Removed: Our senior executive team, which includes our CITO, using input from our information security team and our broader information technology (or IT) department, develop and approve budgets, strategies, technology roadmaps and programs which are designed to effectively manage our cyber risks, safeguard our information resources, and reduce the likelihood or impact of cybersecurity incidents.
+Added: • Risk mitigation – Our senior executive team, which includes our CITO, using input from our information security team and our broader information technology (or IT) department, develop and approve budgets, strategies, technology roadmaps and programs which are designed to effectively manage our cyber risks, safeguard our information resources, and reduce the likelihood or impact of cybersecurity incidents.
Our cybersecurity risk management framework is integrated into our overall ERM process which is managed, administered, and governed by our senior executive team under the oversight of the Board.
−Removed: As part of our ERM program, our senior executive team has delegated the initial identification and assessment of the Company’s leading risks to an ERC which is comprised of executives from various operating segments and functional departments across the Company, inclusive of information security.
+Added: As part of our ERM program, our senior executive team collaborates with the ERC, which is comprised of executives from various operating segments and functional departments across the Company, in the initial identification and assessment of the Company’s leading risks to an ERC, inclusive of information security.
Although both we, and the third parties who provide services to us, commit resources to the design, implementation, monitoring, and protection of the information systems we own or use, there is no guarantee that either our or those third parties’ cybersecurity measures will effectively manage the multitude of cyber risks to which we are exposed.
14 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.