4 unchanged sentences
Our cybersecurity program includes an information security policy, access management policies, an open-source policy, security incident response processes, and a supply chain policy, in addition to the secure design and vendor management programs described below.
−Removed: For a description of the risks from cybersecurity threats that may materially affect us, see the section titled “Risk Factors” included elsewhere in this Annual Report on Form 10-K.
+Added: For a description of the risks from cybersecurity threats that may materially affect us, see the risk factor titled “ If we, our customers, or third-party service providers experience an actual or perceived security breach or unauthorized parties otherwise obtain access to our customers’ data, our data, or our platform, our platform may be perceived as not being secure, our reputation may be harmed, demand for our platform may be reduced, and we may incur significant liabilities.
+Added: ” in the section titled “Risk Factors” included elsewhere in this Annual Report on Form 10-K.
Our information systems generally fall into two categories:
1 unchanged sentence
Each category has dedicated teams and processes in place to address cybersecurity risk.
−Removed: Our product security team, which reports into our EVP, Engineering, works alongside our product and engineering teams to address how security is designed into our platform.
−Removed: Our corporate security team, which reports to our Chief Information Security Officer within our Chief Financial Officer’s organization, is responsible for the secure design of our corporate systems.
+Added: Our product security team, which reports into our SVP, Engineering and Support, works alongside our product and engineering teams to address how security is designed into our platform.
+Added: Our corporate security team, which reports to our Chief Information Security Officer, is responsible for the secure design of our corporate systems.
In addition, our Chief Information Security Officer manages a global security team that performs certain cybersecurity functions for both our platform and corporate systems, including certification management, incident response, threat detection, analytics, and offensive security (such as simulations and penetration tests).
4 unchanged sentences
Our assessment and management of material risks from cybersecurity threats is a key risk area within our enterprise risk management program.
−Removed: Our Chief Information and Data Officer, Chief Information Security Officer, and EVP, Engineering are responsible for management of cybersecurity risk under our enterprise risk management program, and senior management and the audit committee of our board of directors receive reports on the key risks and the effectiveness of our management of such enterprise risks.
+Added: Our Chief Information Security Officer and SVP, Engineering and Support are responsible for management of cybersecurity risk under our enterprise risk management program, and senior management and the audit committee of our board of directors receive reports on the key risks and the effectiveness of our management of such enterprise risks.
In addition, key cybersecurity risks are assessed as part of our internal audit program.
We have completed various security audits and certifications, including SOC 2 Type II, SOC 1 Type II, PCI-DSS, HITRUST, FedRAMP High, and ISO/IEC 27001.
−Removed: We also employ a shared responsibility model where our customers are responsible for using and configuring our platform in a manner that meets applicable cybersecurity standards.
−Removed: As part of this shared security model, customers have sole responsibility for creating and securing their access credentials for our platform.
−Removed: Each of our platform and corporate systems involves the use of third-party technology or service providers, or vendors, such as hosting platforms, open-source software, and application providers.
+Added: We also employ a shared responsibility cybersecurity model where our customers are responsible for using and configuring our platform in a manner that meets applicable cybersecurity standards and requirements.
+Added: As part of this shared responsibility cybersecurity model, customers have sole responsibility for creating and securing their access credentials for our platform.
+Added: Our platform and corporate systems involve the use of third-party technology or service providers, or vendors, such as hosting platforms, open-source software, and application providers.
We also use vendors to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats to our platform and corporate systems, including consulting firms, external legal counsel, incident response vendors, penetration test providers, auditors, monitoring technology, and cybersecurity data providers .
1 unchanged sentence
Depending on the nature of the technology or services provided, the sensitivity of the information systems and data at issue, and the identity of the vendor, our vendor management process may involve different levels of assessment designed to help identify cybersecurity risks.
−Removed: For higher-risk vendors, this process includes a vendor security questionnaire, an evaluation of the vendor’s security program and security documentation, and the imposition of contractual obligations related to cybersecurity on the vendor.
−Removed: All vendors are required to undergo this review, which is in addition to the applicable security reviews conducted by our product security and corporate security teams described above.
−Removed: Our board of directors has a cybersecurity committee of the board to assist it in fulfilling its oversight responsibility with respect to the management of cybersecurity risks related to our products and services as well as our information technology and network systems.
−Removed: The responsibilities of the cybersecurity committee include overseeing our implementation and maintenance of cybersecurity measures, data governance, and compliance with applicable information security laws.
+Added: For vendors that may pose higher risks, this process includes a vendor security questionnaire, an evaluation of the vendor’s security program and security documentation, and the imposition of contractual obligations related to cybersecurity on the vendor.
+Added: All vendors are required to undergo this review, which is in addition to the applicable security reviews that may be conducted by our product security and corporate security teams described above.
+Added: Our board of directors has formed a cybersecurity committee of the board to assist it in fulfilling its oversight responsibility with respect to the management of cybersecurity risks related to our products and services as well as our information technology and network systems.
+Added: The responsibilities of the cybersecurity committee include overseeing our implementation and maintenance of cybersecurity measures, data governance, compliance with applicable information security laws, and overseeing disclosure controls relating to cybersecurity.
The cybersecurity committee receives reports from management concerning our significant cybersecurity threats and risk and the processes we have implemented to address them and has access to various reports, summaries or presentations related to cybersecurity threats, risk, and mitigation.
−Removed: In addition, our audit committee has oversight responsibility over our internal financial controls and our enterprise risk management program, including disclosure controls related to cybersecurity.
+Added: In addition, our audit committee has oversight responsibility over our internal financial controls and our enterprise risk management program.
Finally, management periodically provides cybersecurity briefings to the entire board of directors .
−Removed: The members of management who are primarily responsible for assessing and managing our material risks from cybersecurity threats are Brad Jones, our Chief Information Security Officer, and Grzegorz Czajkowski, our EVP, Engineering & Support.
−Removed: Jones joined Snowflake in 2023 and previously served in various cybersecurity roles for over 12 years across multiple technology sectors, including manufacturing, software, and services.
−Removed: Jones reports to Sunny Bedi, who has served as our Chief Information and Data Officer since 2020 and, prior to joining us, served as VP of Corporate IT / Head of Global IT at NVIDIA, where his responsibilities included managing IT security.
−Removed: Czajkowski joined Snowflake as SVP, Engineering & Support in 2019 and, prior to joining us, served in various roles at Google, including as VP Engineering where he was responsible for a portfolio of Google Cloud data analytics and for internal services addressing data analytics needs of Google’s businesses.
−Removed: Each of Messrs.
−Removed: Jones and Czajkowski is responsible for hiring appropriate personnel, integrating cybersecurity risk considerations into our overall risk management strategy, communicating key priorities to relevant personnel, approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
+Added: The members of management who are primarily responsible for assessing and managing our material risks from cybersecurity threats are our Chief Information Security Officer and our SVP, Engineering and Support.
+Added: Our Chief Information Security Officer joined Snowflake in 2023 and previously served in various cybersecurity roles for over 12 years across multiple technology sectors, including manufacturing, software, and services.
+Added: Our SVP, Engineering and Support joined Snowflake as VP of AI Engineering in 2023 in connection with our acquisition of Neeva, where he served as the head of engineering and, prior to that, he served in various roles at Google, including as VP Engineering in various technical leadership roles.
+Added: Each of our Chief Information Security Officer and SVP, Engineering and Support is responsible for hiring appropriate personnel, integrating cybersecurity risk considerations into our overall risk management strategy, communicating key priorities to relevant personnel, approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
Our cybersecurity incident response processes are designed to escalate certain cybersecurity incidents to management depending on the circumstances, including the individuals named above, who work with our incident response team to help us mitigate and remediate cybersecurity incidents of which they are notified .
−Removed: In addition, our security incident response plan provides for reporting certain cybersecurity incidents to our board of directors.
+Added: In addition, our security incident response plan provides for reporting certain cybersecurity incidents to the cybersecurity committee of the board.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.