5 unchanged sentences
As part of management’s oversight of cybersecurity, our Chief Security Officer (“CSO”) presents on our cybersecurity practices to the Nominating and Corporate Governance Committee of our Board of Directors (the “NCG Committee”) and to our full Board of Directors on a periodic basis.
−Removed: Our Senior Vice President, Internal Audit & Risk Management (the “Chief Audit Executive”), periodically presents
−Removed: enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”).
−Removed: Our Chief Compliance Officer regularly attends meetings at the NCG Committee providing insights from the compliance perspective relating to cybersecurity.
+Added: Our Senior Vice President, Internal Audit & Risk Management (the “Chief Audit Executive”), periodically presents enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”).
+Added: Chief Compliance Officer regularly attends meetings of the NCG Committee to provide insights from the compliance perspective relating to cybersecurity.
Cyber risk management is a core component of the Company's governance structure.
−Removed: We utilize the National Institute of Standards and Technology’s Cybersecurity Framework (“NIST CSF”) as a guide in cyber risk management to identify, assess, and assist the CSO in managing cybersecurity risks.
+Added: We utilize the National Institute of Standards and Technology’s Cybersecurity Framework as a guide in cyber risk management to identify, assess, and assist the CSO in managing cybersecurity risks.
Cyber risk management encompasses partnerships among teams that are responsible for cyber governance, prevention, detection, and remediation activities within the Company’s cybersecurity environment.
14 unchanged sentences
As previously disclosed, in August 2021, we experienced a cybersecurity incident that resulted in numerous lawsuits, including mass arbitration claims and multiple class action lawsuits.
−Removed: In January 2023, we experienced another cybersecurity incident that also resulted in consumer class actions and regulatory inquires.
+Added: In January 2023, we experienced another cybersecurity incident that also resulted in consumer class actions and regulatory inquiries.
As a result of the August 2021 cyberattack and the January 2023 cyberattack, we have incurred and may continue to incur significant costs or experience other material financial impacts, which may not be covered by, or may exceed the coverage limits of, our cyber liability insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
6 unchanged sentences
The Transformation and Chief Information & Digital Officer under the direction of the Company’s Chief Executive Officer, is responsible for overseeing the Company’s information technology systems, digital capabilities, and cybersecurity practices.
−Removed: CSO, under the direction of the Transformation and Chief Information & Digital Officer, is responsible for overseeing the cybersecurity organization and promoting a security-centric culture throughout our business and operational functions.
+Added: The CSO, under the direction of the Transformation and Chief Information & Digital Officer, is responsible for overseeing the
+Added: cybersecurity organization and promoting a security-centric culture throughout our business and operational functions.
The CSO is at the forefront of enhancing our cybersecurity framework and strengthening the overall cybersecurity program.
8 unchanged sentences
Our Enterprise Risk & Compliance Committee is comprised of a collective of senior management representatives and subject matter experts from across the Company.
−Removed: The Enterprise Risk & Compliance Committee is chaired by the Chief Financial Officer (“CFO”) of the Company, with the Executive Vice President & General Counsel as the co-chair and comprises core members including the Transformation and Chief Information & Digital Officer, while the CSO serves in an advisory capacity.
+Added: The Enterprise Risk & Compliance Committee is chaired by the Chief Financial Officer of the Company, with the Executive Vice President & General Counsel as the co-chair and comprises core members including the Transformation and Chief Information & Digital Officer, while the CSO serves in an advisory capacity.
The purpose of the Enterprise Risk & Compliance Committee is to oversee and govern the Company’s risk management, environmental, social, corporate governance, cybersecurity, and operational compliance activities, as well as provide a means of bringing risk issues to the attention of management.
1 unchanged sentence
Disclosure of the Board’s Roles and Responsibilities
−Removed: Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NGC Committee and Audit Committee and various executive roles.
+Added: Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NCG Committee and Audit Committee and various executive roles.
Additionally, our Transformation and Chief Information & Digital Officer and CSO report on cybersecurity to the full Board.
12 unchanged sentences
These include an enterprise-wide risk assessment that highlights cybersecurity risks and cybersecurity risk mitigation actions.
−Removed: Additionally, the Audit Committee receives updates on significant incidents and cybersecurity risks that have been presented to or discussed with the Enterprise Risk and Compliance Committee.
+Added: Additionally, the Audit Committee receives updates on significant incidents and cybersecurity risks that have been presented to or discussed with the Enterprise Risk & Compliance Committee.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.