11 unchanged sentences
We conduct cybersecurity awareness training for personnel upon hire and on a periodic basis thereafter, which includes phishing training campaigns.
−Removed: SoFi Technologies, Inc.
As part of our cybersecurity risk management program, SoFi maintains a formal Third-Party Security Risk Management program that provides oversight of cybersecurity risks related to supplier relationships.
1 unchanged sentence
This program includes the provision of a cybersecurity risk assessment to these suppliers during onboarding as well as ongoing monitoring, assessment, and contract review.
−Removed: We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: For more information on risks to us from cybersecurity threats, see “ Cyberattacks and other security incidents and compromises could have an adverse effect on our business, harm our reputation and expose us to liability and adversely affect our ability to collect payments and maintain accurate accounts.
+Added: We have not identified any cybersecurity incidents, data breaches, or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
+Added: For more information on risks to us from cybersecurity threats, see “ Cyberattacks and other security incidents and compromises could have an adverse effect on our business and systems, harm our brand and our reputation and expose us to liability.
Efforts to prevent and respond to these attacks and incidents are costly ” in Part I, Item 1A.
6 unchanged sentences
Our CISO has primary responsibility for assessing and managing our cybersecurity program.
−Removed: The CISO has served in this role at SoFi for four years and has over twenty years of experience working in senior leadership positions in the cybersecurity industry.
−Removed: He previously served as the CISO at leading software and data analytics companies and co-founded a cybersecurity company.
+Added: The CISO has served in this role at SoFi since June 2025 and has over 25 years of experience working in senior leadership positions in the cybersecurity industry.
+Added: He previously served as the CISO at leading software and financial technology companies.
The CISO provides cybersecurity updates, including risks and threats to the Risk Committee as appropriate, on a quarterly basis.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.