4 unchanged sentences
We have implemented processes for overseeing and identifying material risks from cybersecurity threats, and our cybersecurity processes are integrated into the Company’s overall risk management system and processes.
−Removed: As part of management’s oversight of cybersecurity, our Chief Security Officer (“CSO”) presents on our cybersecurity practices to the Nominating and Corporate Governance Committee of our Board of Directors (the “NCG Committee”) and to our full Board of Directors on a periodic basis.
−Removed: Our Senior Vice President, Internal Audit & Risk Management (the “Chief Audit Executive”), periodically presents enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”).
−Removed: Chief Compliance Officer regularly attends meetings of the NCG Committee to provide insights from the compliance perspective relating to cybersecurity.
+Added: As part of management’s oversight of cybersecurity, Mark Clancy, our Senior Vice President, Cybersecurity, presents on our cybersecurity practices to the Nominating, Corporate Governance and Compliance Committee of our Board of Directors (the “NCGC Committee”) and to our full Board of Directors on a periodic basis.
+Added: Our Chief Audit Executive periodically presents enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”).
+Added: Our Chief Compliance Officer regularly attends meetings of the NCGC Committee to provide insights from the compliance perspective relating to cybersecurity.
Cyber risk management is a core component of the Company's governance structure.
−Removed: We utilize the National Institute of Standards and Technology’s Cybersecurity Framework as a guide in cyber risk management to identify, assess, and assist the CSO in managing cybersecurity risks.
+Added: We utilize the National Institute of Standards and Technology’s Cybersecurity Framework as a guide in cyber risk management to identify, assess, and assist cybersecurity leadership in managing cybersecurity risks.
Cyber risk management encompasses partnerships among teams that are responsible for cyber governance, prevention, detection, and remediation activities within the Company’s cybersecurity environment.
2 unchanged sentences
Our management also conducts a quarterly enterprise-wide risk assessment that considers a wide spectrum of risks facing the Company, including cybersecurity.
−Removed: Through these quarterly risk assessments, management informs the Audit Committee on the cyber risk landscape facing the Company and the Company’s preparedness to manage such risk.
+Added: Through these quarterly risk assessments, management informs the Audit Committee of the cyber risk landscape facing the Company and the Company’s preparedness to manage such risk.
The enterprise-wide risk assessment is a top-down risk assessment that leverages the assessments performed by cyber risk management.
Engagement with External Experts
−Removed: The Company engages top-tier external cyber security firms, as needed, leveraging their expertise as part of our ongoing effort to evaluate and enhance our cybersecurity program.
+Added: The Company engages top-tier external cybersecurity firms, as needed, leveraging their expertise as part of our ongoing effort to evaluate and enhance our cybersecurity program.
They help with cyber defense capabilities (including staff enhancement of certain functions) and transformation to mitigate associated threats, reduce risk, enhance our cybersecurity posture, and meet the Company's evolving needs.
1 unchanged sentence
Our third-party risk management program includes processes for identifying and managing material cybersecurity risks arising from third-party providers.
−Removed: Our third-party risk management program actively engages with the enterprise-wide risk assessment process and partners with cyber risk management to report relevant risks to the NCG Committee, the Audit Committee and our internal Enterprise Risk & Compliance Committee.
+Added: Our third-party risk management program actively engages with the enterprise-wide risk assessment process and partners with cyber risk management to report relevant risks to the NCGC Committee, the Audit Committee and our internal Enterprise Risk & Compliance Committee.
Our third-party risk management program includes cybersecurity as an aspect of its risk assessment of third parties with the objective that key risks are identified and addressed.
3 unchanged sentences
In January 2023, we experienced another cybersecurity incident that also resulted in consumer class actions and regulatory inquiries.
−Removed: As a result of the August 2021 cyberattack and the January 2023 cyberattack, we have incurred and may continue to incur significant costs or experience other material financial impacts, which may not be covered by, or may exceed the coverage limits of, our cyber liability insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
+Added: Legal and other costs related to these proceedings and inquiries, as well as any potential future actions, may be substantial, and losses associated with any adverse judgments, settlements, penalties or other resolutions of such proceedings and inquiries could be material to our business, reputation, financial condition, cash flows and operating results.
For additional details regarding the impact of both cybersecurity incidents, see Note 18 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.
We have not identified other known risks from previous cybersecurity threats that have materially affected or are reasonably likely to materially affect us.
−Removed: However, we face ongoing risks from certain cybersecurity threats that, if realized, are reasonably likely to materially affect business strategy, results of operations, or financial condition.
−Removed: See “Risk Factors – We have experienced criminal cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties whose products and services we rely on in operating our business .”
+Added: However, we face ongoing risks from certain cybersecurity threats that, if realized, are reasonably likely to materially affect business strategy, financial condition or operating results.
+Added: See “Risk Factors – We have experienced cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties whose products and services we rely on in operating our business .”
Disclosure of Management’s Responsibilities
−Removed: Transformation and Chief Information & Digital Officer
−Removed: The Transformation and Chief Information & Digital Officer under the direction of the Company’s Chief Executive Officer, is responsible for overseeing the Company’s information technology systems, digital capabilities, and cybersecurity practices.
−Removed: The CSO, under the direction of the Transformation and Chief Information & Digital Officer, is responsible for overseeing the
−Removed: cybersecurity organization and promoting a security-centric culture throughout our business and operational functions.
−Removed: The CSO is at the forefront of enhancing our cybersecurity framework and strengthening the overall cybersecurity program.
+Added: Chief Information Officer
+Added: The Chief Information Officer is responsible for overseeing the Company’s information technology systems, digital capabilities, and cybersecurity practices.
+Added: Mark Clancy, our Senior Vice President, Cybersecurity , under the direction of the Chief Information Officer, is responsible for overseeing the cybersecurity organization and promoting a security-centric culture throughout our business and operational functions.
+Added: The Senior Vice President, Cybersecurity, is at the forefront of enhancing our cybersecurity framework and strengthening the overall cybersecurity program.
This involves upgrading tools and capabilities, which are part of a broader, multi-year strategy to continue to enhance security measures.
−Removed: The CSO oversees the cyber risk management function, which identifies cybersecurity threats, assesses cybersecurity risks and supports the Transformation and Chief Information & Digital Officer and the Company in managing such risks.
−Removed: As the Company’s Executive Vice President, Transformation and Chief Information & Digital Officer, Néstor Cano has served in several leadership positions at both the Company and Sprint, including as Sprint’s Chief Operating Officer, overseeing, among other things, Sprint’s digital architecture and delivery.
−Removed: Cano studied industrial engineering at Barcelona Polytechnic University, attended the Executive Distribution Academy by INSEAD Business School in Fontainebleau, France, and also completed his post-graduate degree in executive management at IESE Business School in Barcelona, Spain.
−Removed: As the Company’s CSO, Jeff Simon has extensive experience in risk management and information security, including serving as the Chief Information Security Officer at Fidelity National Information Services, Inc.
+Added: The Senior Vice President, Cybersecurity, oversees the cyber risk management function, which identifies cybersecurity threats, assesses cybersecurity risks and supports the Chief Information Officer and the Company in managing such risks.
+Added: As the Company’s Chief Information Officer, Jeff Simon has extensive experience in risk management and information security, including serving as the Chief Information Security Officer at Fidelity National Information Services, Inc.
Simon received his Master of Science in Computer Science, Software Engineering & Artificial Intelligence from the Johns Hopkins Whiting School of Engineering and Bachelor of Science in Business Administration and Applied Economics from Marquette University.
Simon is a Certified Information Systems Security Professional.
+Added: As the Company’s Senior Vice President, Cybersecurity, Mark Clancy has over 25 years of experience in information technology, information security, and cybersecurity, including serving as the Chief Information and Security Officer and Vice President of Cybersecurity and Fraud at Sprint Corporation.
+Added: Clancy received his Bachelor of Science in Electrical and Electronics Engineering from Drexel University.
Enterprise Risk & Compliance Committee
Our Enterprise Risk & Compliance Committee is comprised of a collective of senior management representatives and subject matter experts from across the Company.
−Removed: The Enterprise Risk & Compliance Committee is chaired by the Chief Financial Officer of the Company, with the Executive Vice President & General Counsel as the co-chair and comprises core members including the Transformation and Chief Information & Digital Officer, while the CSO serves in an advisory capacity.
+Added: The Enterprise Risk & Compliance Committee is chaired by the Chief Financial Officer of the Company, with the Chief Legal Officer and General Counsel as the co-chair and comprises core members including the Chief Information Officer, while the Senior Vice President, Cybersecurity, serves in an advisory capacity.
The purpose of the Enterprise Risk & Compliance Committee is to oversee and govern the Company’s risk management, environmental, social, corporate governance, cybersecurity, and operational compliance activities, as well as provide a means of bringing risk issues to the attention of management.
−Removed: Specific to cybersecurity, the Transformation and Chief Information & Digital Officer and the CSO have the expertise to provide insights into the nature of cyber threats, the Company’s readiness, and actions taken to mitigate such risks.
+Added: Specific to cybersecurity, the Chief Information Officer and the Senior Vice President, Cybersecurity, have the expertise to provide insights into the nature of cyber threats, the Company’s readiness, and actions taken to mitigate such risks.
Disclosure of the Board’s Roles and Responsibilities
−Removed: Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NCG Committee and Audit Committee and various executive roles.
−Removed: Additionally, our Transformation and Chief Information & Digital Officer and CSO report on cybersecurity to the full Board.
−Removed: Nominating and Corporate Governance Committee
−Removed: The NCG Committee oversees risks associated with data privacy and information security, which encompasses cybersecurity.
−Removed: Our CSO and Chief Compliance Officer, among other executives, provide periodic reports to the NCG Committee and also meet with the NCG Committee to discuss any material events when they arise.
−Removed: The periodic reports are designed to keep the NCG Committee abreast of the Company’s cybersecurity practices, risks and trends in cybersecurity threats.
−Removed: The NCG Committee also has discussions with management focused on evaluating the Company’s exposure to cybersecurity risks and cybersecurity practices in place to mitigate such risks.
−Removed: These discussions enable the NCG Committee to be informed of the steps management is taking to detect, monitor and manage cybersecurity risks.
−Removed: These reports to the NCG Committee typically include information on any significant incidents that have occurred, how they were managed, and any changes to the risk profile of the Company.
−Removed: The NCG Committee seeks updates to facilitate proactive governance and to allow the NCG Committee to address emerging cybersecurity issues with management.
+Added: Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NCGC Committee and Audit Committee and various executive roles.
+Added: Additionally, our Chief Information Officer and Senior Vice President, Cybersecurity, report on cybersecurity to the full Board.
+Added: Nominating, Corporate Governance and Compliance Committee
+Added: The NCGC Committee oversees risks associated with data privacy and information security, which encompasses cybersecurity.
+Added: Our Senior Vice President, Cybersecurity, and Chief Compliance Officer, among other executives, provide periodic reports to the NCGC Committee and also meet with the NCGC Committee to discuss any material events when they arise.
+Added: The periodic reports are designed to keep the NCGC Committee abreast of the Company’s cybersecurity practices, risks and trends in cybersecurity threats.
+Added: The NCGC Committee also has discussions with management focused on evaluating the Company’s exposure to cybersecurity risks and cybersecurity practices in place to mitigate such risks.
+Added: These discussions enable the NCGC Committee to be informed of the steps management is taking to detect, monitor and manage cybersecurity risks.
+Added: These reports
+Added: to the NCGC Committee typically include information on any significant incidents that have occurred, how they were managed, and any changes to the risk profile of the Company.
+Added: The NCGC Committee seeks updates to facilitate proactive governance and to allow the NCGC Committee to address emerging cybersecurity issues with management.
Audit Committee
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.