2 unchanged sentences
Risk Management and Strategy
−Removed: As a large, multinational transportation and logistics company, we and our subsidiaries each face a range of risks from cybersecurity threats in connection with our operations due to our inherent dependence on information systems, software, and digital technologies to operate safely, efficiently, and effectively.
−Removed: Such risks include, but are not limited to, those related to cyberattacks, network breaches, ransomware, malware or denial-of-service attacks, phishing and other scams, theft, and unauthorized disclosure, any of which, if successful, could result in the disclosure of confidential customer or commercial data, loss of valuable intellectual property, or systems disruption, and subject us to civil liability, fines, penalties, damage of our brand or reputation, or otherwise harm our business, any of which, could be material.
−Removed: We and our subsidiaries are each exposed to such risks both through direct attacks on our own information systems and, indirectly, as a result of our engagement of third-party service providers, software vendors, and independent contractors, such as cloud computing providers.
−Removed: Certain of our third-party service providers or software vendors provide us with computing services which, in certain cases, involve hosting our data or processes on third-party servers, which exposes us to the risk that our data may be compromised or our operations disrupted if such third-party servers are compromised.
−Removed: Other third-party service providers provide us with contracted labor to whom we necessarily grant access to certain of our information systems, which indirectly exposes us to additional risks of network breaches and cybersecurity threats.
−Removed: In addition, because the trucking industry has been designated by the federal government as part of the critical U.S.
−Removed: infrastructure, as a leading provider of truckload, intermodal, and logistics services, we face increased risks from cybersecurity threats, cybercriminals, and bad actors, both foreign and domestic.
−Removed: Cyber risk management has become a vital part of our broader ERM efforts.
−Removed: To manage and mitigate cyber risks, we have a dedicated information security team that has been charged with monitoring and managing cyber threats to our information systems, and the data that is stored on those systems, using our cyber risk management methodology.
−Removed: Our information security team is led by our SDIS and overseen by our CITO.
−Removed: Our cybersecurity risk management framework encompasses, among other things, ongoing systematic processes to identify, analyze, prioritize, manage, and monitor potential cyber risks to the information systems that we own or use and the cybersecurity threats to which we are exposed as a result of our reliance on third-party service providers and third-party software.
−Removed: Our cyber risk management methodology is comprised of the following core tasks:
+Added: As a large, multinational transportation and logistics company, we and our subsidiaries are subject to significant cybersecurity risks arising from our reliance on information systems, software, and digital technologies to operate safely, efficiently, and effectively.
+Added: We strategically leverage AI technology to complement our capabilities and enhance efficiencies across our business operations, customer support, and shared service areas.
+Added: The AI capabilities and solutions that we have deployed may occasionally generate inaccurate output, disclose confidential information, exhibit data-driven biases, infringe on intellectual property rights, or cause other unintended harm.
+Added: Such risks could subject us to liability, unwanted legal or regulatory repercussions, and potentially impact our reputation and public trust.
+Added: Additionally, the use of AI and machine learning technology by malicious actors may increase the likelihood and impact of cyberattacks targeting our organization, suppliers, vendors, and service providers.
+Added: We are committed to assessing risks related to the AI capabilities that we have deployed by rigorously testing systems before implementation and monitoring and updating those systems to strengthen our defenses.
+Added: We have established formal procedures for the management, oversight, and governance of AI usage.
+Added: We have also instituted contractual and technical controls for the AI platforms we use.
+Added: Although we have not experienced cyberattacks with material effects on our operations or financial status to date, there remains a possibility that our preventative measures may be insufficient in countering or mitigating future significant attacks.
+Added: These risks include, but are not limited to, cyberattacks, network intrusions, ransomware, malware, denial-of-service attacks, phishing schemes, data theft, and unauthorized disclosure.
+Added: A cyberattack or incident that defeats our security defenses could result in the unauthorized disclosure of confidential customer or commercial information, loss of intellectual property, disruption of our operations, reputational harm, civil liability, regulatory fines or penalties, and other adverse effects on our business, any of which could be material.
+Added: We are exposed to cybersecurity threats and risks both directly, through attacks on our own systems, and indirectly, through third-party system or data breaches on a system controlled by our vendors, independent contractors, suppliers, or service providers, including cloud computing providers.
+Added: Certain third-party providers host our data or processes on their servers, which exposes us to additional risk if those servers are compromised.
+Added: Other providers supply contracted labor that requires access to our systems, increasing the potential for breaches.
+Added: Furthermore, because the trucking industry is designated by the federal government as part of critical U.S.
+Added: infrastructure, our position as a leading provider of truckload, intermodal, and logistics services heightens our exposure to cybersecurity threats from malicious actors, including foreign and domestic adversaries.
+Added: Cyber risk management is integrated into our ERM framework.
+Added: We maintain a dedicated information security team responsible for monitoring and managing cybersecurity threats to our information systems and the data stored within them, in accordance with our established cyber risk management methodology.
+Added: This team is led by our SDIS and overseen by our CITO.
+Added: Our cybersecurity risk management framework includes systematic processes designed to identify, assess, prioritize, manage, and monitor potential cyber risks.
+Added: These processes apply to information systems that we own or utilize, as well as to cybersecurity threats arising from our reliance on third-party service providers and software vendors.
+Added: This framework is intended to reduce the likelihood and impact of cybersecurity incidents and to support the resilience of our operations and is comprised of the following core tasks:
• Risk identification – Our internal information security team works with an MSSP and other external security partners to identify existing and new threats to our information systems.
−Removed: Our information security team, working in partnership with our MSSP, monitors our information systems to identify malicious and anomalous activity, uncover potential cybersecurity threats, and assess risks to information systems.
+Added: Our information security team, working in partnership with our MSSP, monitors our information systems to identify malicious and abnormal activity, uncover potential cybersecurity threats, and assess risks to information systems.
• Risk analysis – Our information security team, working in partnership with relevant cybersecurity and technology experts, analyzes identified threats to determine the likelihood of the actualization of a threat and the potential business impacts, including evaluating the potential for data loss, data corruption, disruption to business operations, and financial impact.
1 unchanged sentence
If it is determined that our existing processes, strategies, or technology may be insufficient to effectively mitigate or manage an identified risk, it is escalated to our CITO and SDIS to assess and implement potential responsive or corrective actions in our processes, strategies, or technology to address the risk.
−Removed: • Risk mitigation – Our senior executive team, which includes our CITO, using input from our information security team and our broader information technology (or IT) department, develop and approve budgets, strategies, technology roadmaps and programs which are designed to effectively manage our cyber risks, safeguard our information resources, and reduce the likelihood or impact of cybersecurity incidents.
−Removed: Our cybersecurity risk management framework is integrated into our overall ERM process which is managed, administered, and governed by our senior executive team under the oversight of the Board.
−Removed: As part of our ERM program, our senior executive team collaborates with the ERC, which is comprised of executives from various operating segments and functional departments across the Company, in the initial identification and assessment of the Company’s leading risks to an ERC, inclusive of information security.
−Removed: Although both we, and the third parties who provide services to us, commit resources to the design, implementation, monitoring, and protection of the information systems we own or use, there is no guarantee that either our or those third parties’ cybersecurity measures will effectively manage the multitude of cyber risks to which we are exposed.
+Added: • Risk mitigation – Our senior executive team, which includes our CITO, using input from our information security team and our broader information technology department, develops and approves budgets, strategies, technology roadmaps, and programs which are designed to effectively manage our cyber risks, safeguard our information resources, and reduce the likelihood or impact of cybersecurity incidents.
+Added: Our cybersecurity risk management framework is managed, administered, and governed by our senior executive team under the oversight of the Board.
+Added: As part of our ERM program, our senior executive team collaborates with the Enterprise Risk Council, which is comprised of executives from various operating segments and functional departments across the Company, in the initial identification and assessment of the Company’s leading risks, inclusive of information security.
+Added: Although we, and the third parties who provide services to us, commit resources to the design, implementation, monitoring, and protection of the information systems we own or use, there is no guarantee that either our or those third parties’ cybersecurity measures will effectively manage the multitude of cyber risks to which we are exposed.
For more information regarding the risks from cybersecurity threats that may impact our business strategy, results of operations, or financial condition, see Part I, “Item 1A.
8 unchanged sentences
Cybersecurity is a key component of our technology strategy, which is architected and managed by our CITO and reviewed and monitored by our senior executive team, with oversight from our Board and the Audit Committee, as described above.
−Removed: Our CITO’s experience and expertise in cybersecurity includes 20 years of practitioner experience as an information security advisor across multiple industry verticals where he has served in security analyst, architect, and security program leadership roles, and has led information security teams to deliver large scale information security programs for multiple Fortune 500 companies.
+Added: Our CITO’s experience and expertise in cybersecurity includes over 20 years of practitioner experience as an information security advisor across multiple industry verticals where he has served in security analyst, architect, and security program leadership roles, and has led information security teams to deliver large scale information security programs for multiple Fortune 500 companies.
Our cybersecurity risk management program is managed by our SDIS, who reports directly to the CITO.
−Removed: Our SDIS’s experience and expertise in cybersecurity includes 32 years of working in the information technology field as an analyst, architect, and leader and 14 years leading information security teams at multiple enterprises.
+Added: Our SDIS’s experience and expertise in cybersecurity includes over 30 years of working in the information technology field as an analyst, architect, and leader and over 15 years leading information security teams at multiple enterprises.
The processes by which the CITO and SDIS are informed about and monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents are described above under “Risk Management and Strategy.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.