4 unchanged sentences
We have adopted a cybersecurity program designed to identify, assess, and manage material risks from cybersecurity threats and have integrated cybersecurity risk into our broader enterprise risk management framework.
−Removed: We incorporate third-party assessments into our risk management program using recognized standards that are relevant to our business and we periodically self-assess various functional areas of our organization.
+Added: We incorporate periodic third-party assessments into our risk management program , leveraging appropriate benchmarks and recognized standards and frameworks that are relevant to our business (such as the NIST Cybersecurity Framework), and we periodically self-assess various functional areas of our organization.
We use a variety of strategies and techniques designed to identify cybersecurity risks and reduce the risk of unauthorized access to our organization’s confidential information (including customer, vendor, and Associate data) and critical business systems.
This approach includes various assessment activities (e.g.
−Removed: threat actor emulation and penetration testing), tabletop exercises, security awareness and training activities (e.g.
+Added: threat actor emulation and penetration testing), tabletop exercises, a vulnerability management program, tools designed to monitor our networks, systems, and data for suspicious activity, security awareness and training activities (e.g.
simulated phishing campaigns and specialized training for cybersecurity personnel), encryption of certain types of information, and certain controls governing access to TJX facilities and systems, among other threat- and risk-based safeguards.
3 unchanged sentences
Within our Cybersecurity department, our Security Operations Center provides threat detection and incident response capabilities.
−Removed: We also have an incident response plan which describes roles and responsibilities for internal stakeholders in responding to and escalating potential cybersecurity incidents.
+Added: We also have an incident response plan which includes processes to investigate, contain, escalate, and remediate potential cybersecurity incidents as well as to comply with potentially applicable legal obligations and mitigate reputational harm.
We periodically test this plan through tabletop exercises with relevant stakeholders across various functions of our business, including members of senior management.
+Added: In the event that a cybersecurity incident is determined to be potentially material, we will assess materiality and, as appropriate, disclose such incident in accordance with applicable regulatory requirements.
We also have processes in place designed to identify and mitigate risks from third party technology and service providers , including, as appropriate, pre-contractual due diligence, review of contractual terms addressing cybersecurity and data protection, and periodic re-assessment based on assessed vendor risk.
7 unchanged sentences
Our information security program is overseen by our CISO , who has over thirty-five years of cybersecurity, information governance, and IT experience in critical infrastructure, private industry, and government.
−Removed: Our CISO reports to our CIO, who has more than twenty-eight years of global information technology leadership experience.
+Added: Our CISO reports to our CIO, who has more than thirty years of global information technology leadership experience.
Our CISO is informed about and monitors the prevention, detection and mitigation of cybersecurity threats through his management of, and participation in, the cybersecurity risk management and strategy processes described above, including the operation of our incident response plan.
2 unchanged sentences
While some of these attempts have resulted in cybersecurity incidents, the unauthorized intrusion into our network discovered late in 2006 is the only such cybersecurity incident to date that has been material to the results of our operations.
−Removed: For more information, see “Compromises of our cybersecurity, disruptions in our information technology systems, or failure to satisfy the information technology needs of our business could result in material loss or liability, materially impact our operating results or materially harm our reputation.
−Removed: ” in Item 1A in this Form 10-K.
+Added: For more information, see “Compromises of our cybersecurity, disruptions in our information technology systems, or failure to satisfy the information technology needs of our business could result in material loss or liability, materially impact our operating results or materially harm our reputation.” in Item 1A in this Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.