8 unchanged sentences
We leverage qualified third-party security assessors to identify vulnerabilities through both internal and external penetration tests and perform internal cybersecurity maturity assessments.
−Removed: In addition, our internal audit team conducts an information security and information technology audit on an annual basis.
+Added: In addition, our internal audit team conducts information security and information technology audits on an annual basis.
We are also subject to examinations by applicable regulators.
We conduct cybersecurity awareness training for personnel upon hire and on a periodic basis thereafter, which includes phishing training campaigns.
+Added: SoFi Technologies, Inc.
As part of our cybersecurity risk management program, SoFi maintains a formal Third-Party Security Risk Management program that provides oversight of cybersecurity risks related to supplier relationships.
2 unchanged sentences
We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: For more information on risks to us from cybersecurity threats, see “ Cyberattacks and other security breaches could have an adverse effect on our business, harm our reputation and expose us to liability and adversely affect our ability to collect payments and maintain accurate accounts.
−Removed: Efforts to prevent and respond to these attacks and breaches are costly ” in Part I, Item 1A.
+Added: For more information on risks to us from cybersecurity threats, see “ Cyberattacks and other security incidents and compromises could have an adverse effect on our business, harm our reputation and expose us to liability and adversely affect our ability to collect payments and maintain accurate accounts.
+Added: Efforts to prevent and respond to these attacks and incidents are costly ” in Part I, Item 1A.
“ Risk Factors — Information Technology and Data Risks ”.
2 unchanged sentences
The Risk Committee is responsible for the information technology and cybersecurity function at the Company.
−Removed: Relevant duties include, but are not limited to, annually reviewing the cybersecurity program roadmap and materials related to significant planned projects and budgeted costs and approving the cybersecurity program.
+Added: Relevant duties include, but are not limited to, annually reviewing Cybersecurity’s prior year performance and the upcoming program roadmap, and approving the cybersecurity program.
The Risk Committee meets at least four times each year and discusses cybersecurity risk management as relevant and applicable.
Our CISO has primary responsibility for assessing and managing our cybersecurity program.
−Removed: The CISO has served in this role at SoFi for three years and has over twenty years of experience working in senior leadership positions in the
−Removed: SoFi Technologies, Inc.
−Removed: TABLE OF CONTENT S
−Removed: cybersecurity industry.
+Added: The CISO has served in this role at SoFi for four years and has over twenty years of experience working in senior leadership positions in the cybersecurity industry.
He previously served as the CISO at leading software and data analytics companies and co-founded a cybersecurity company.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.