4 unchanged sentences
Our Board of Directors has delegated to the Audit Committee the oversight responsibility to review and discuss with management the Company’s privacy and data security, including cybersecurity, risk exposures, policies and practices, and the steps management has taken to detect, monitor and control such risks and the potential impact of those exposures on our business, financial results, operations and reputation.
−Removed: The full Board and Audit Committee regularly receives reports and presentations on privacy and data security, which address relevant cybersecurity issues and risks and span a wide range of topics.
+Added: The full Board and Audit Committee regularly receive reports and presentations on privacy and data security, which address relevant cybersecurity issues and risks and span a wide range of topics.
These reports and presentations are provided by officers with responsibility for privacy and data security, who include our Chief Information Security Officer (CISO), Chief Technology Officer (CTO) and AT&T’s Legal team .
17 unchanged sentences
Our program encompasses the CSO and its policies, platforms, procedures and processes for assessing, identifying, and managing risks from cybersecurity threats, including third-party risk from vendors and suppliers.
−Removed: and the program is generally designed to identify and respond to security incidents and threats in a timely manner to minimize the loss or compromise of information assets and to facilitate incident resolution.
+Added: The program is integrated into our overall risk management framework and is generally designed to identify and respond to security incidents and threats in a timely manner to minimize the loss or compromise of information assets and to facilitate incident resolution.
We maintain continuous and near-real-time security monitoring of the AT&T network for investigation, action and response to network security events.
1 unchanged sentence
We assess, identify and manage risks from cybersecurity threats through various mechanisms, which from time to time may include tabletop exercises to test our preparedness and incident response process, business unit assessments, control gap analyses, threat modeling, impact analyses, internal audits, external audits, penetration tests and engaging third parties to conduct analyses of our information security program.
+Added: When circumstances warrant, we also retain external cybersecurity experts to assist the CSO.
We conduct vulnerability testing and assess identified vulnerabilities for severity, the potential impact to AT&T and our customers, and likelihood of occurrence.
1 unchanged sentence
We also obtain cybersecurity threat intelligence from recognized forums, third parties and other sources as part of our risk assessment process.
−Removed: In addition, as a critical infrastructure entity, we collaborate with numerous agencies in the U.S.
+Added: In addition, as a critical infrastructure entity, we collaborate
+Added: Dollars in millions except per share amounts
+Added: with numerous agencies in the U.S.
government to help protect U.S.
communications networks and critical infrastructure, which, in turn, informs our cybersecurity threat intelligence.
−Removed: Dollars in millions except per share amounts
With respect to incident response, the Company has adopted a Cybersecurity Incident Response Plan, as well as a Data Privacy Incident Response Plan that applies if customer information has been compromised (together, the “IRPs”), to provide a common framework for responding to security incidents.
7 unchanged sentences
Impact of Cybersecurity Risk
−Removed: In 2023, we did not identify and were not aware of any cybersecurity breaches that we believe have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
−Removed: For a discussion of cybersecurity risk, please see the information contained under the heading “Cyberattacks impacting our networks or systems may have a material adverse effect on our operations” of Item 1A.
+Added: In 2024, we did not identify and were not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that we believe have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition.
+Added: For a discussion of cybersecurity risk, please see the information contained under the heading “Cyberattacks impacting our networks, systems or data or those of our suppliers or vendors may have a material adverse effect on our operations or results of operations” of Item 1A.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.