4 unchanged sentences
The Partnership’s processes used to identify, assess, and mitigate cybersecurity risks are integrated into the Partnership’s broader risk management system and processes, including through the risk management activities of the Board and its Audit Committee, our Enterprise Risk Management Committee (“ERM Committee”), and our internal audit and information technology functions.
+Added: Refer to Part I, Item 1A, “Risk Factors— We are subject to cybersecurity risks and may experience cyber incidents resulting in disruption or harm to our businesses ” of this Report for further discussion of our processes for managing cybersecurity risks.
Board Oversight of Cybersecurity Matters
−Removed: The board of directors of the Partnership’s general partner (the “Board”) considers oversight of CVR Partners’ risks and risk management activities, including those related to cybersecurity risk, to be a responsibility of the entire Board.
−Removed: The Board also delegates certain risk oversight responsibilities to certain of its committees, and oversight of the Partnership’s cybersecurity
−Removed: December 31, 2023 | 31
−Removed: risk is delegated by the Board to its Audit Committee.
−Removed: The Audit Committee receives regular reports, typically on a quarterly basis, from management regarding information technology, cybersecurity risk, and efforts to prevent and mitigate such risks.
−Removed: The Chairperson of the Audit Committee subsequently reports on the Partnership’s cybersecurity risk, monitoring, and mitigation activities to the full Board, which equips the Board and its committees to fulfill their risk oversight role.
+Added: The Board considers oversight of CVR Partners’ risks and risk management activities, including those related to cybersecurity risk, to be a responsibility of the entire Board.
+Added: The Board also delegates certain risk oversight responsibilities to certain of its committees, and oversight of the Partnership’s cybersecurity risk is delegated by the Board to its Audit Committee.
+Added: The Audit Committee receives regular reports, typically on a quarterly basis, from management regarding information technology, cybersecurity risk, AI use and governance, and efforts to prevent and mitigate such risks.
+Added: The Audit Committee subsequently reports on these activities to the full Board, which equips the Board and its committees to fulfill their risk oversight role.
The Board and Audit Committee are supported in their oversight capacity by the Partnership’s ERM Committee, and internal audit and information technology functions.
3 unchanged sentences
Several members of the ERM Committee have functional responsibility for the Partnership’s information technology and cybersecurity risk monitoring activities and provide expertise to the ERM Committee in those areas.
−Removed: Likewise, the Partnership’s internal audit function periodically performs audit engagements focused on information technology processes and cybersecurity risks.
−Removed: These audits have provided the Partnership with assessments of the effectiveness and efficiency of our information technology and cyber threat management processes with the goal of safeguarding Partnership assets and information.
+Added: December 31, 2024 | 31
+Added: Similarly, the Partnership’s internal audit function periodically performs audit engagements focused on information technology processes and cybersecurity risks.
+Added: These audits have provided the Partnership and its Board with assessments of the effectiveness and efficiency of our information technology and cyber threat management processes with the goal of safeguarding Partnership assets and information.
Management of Cybersecurity Matters
−Removed: At the management level, the Partnership’s cybersecurity risk management activities are integrated into the day-to-day activities of the Partnership’s information technology function led by our Chief Information Officer, who operates under the supervision of our Chief Financial Officer.
+Added: At the management level, the Partnership’s cybersecurity risk management activities are led by our Chief Executive Officer and his executive team and is integrated into the day-to-day activities of the Partnership’s information technology function and Chief Information Officer, who operates under the supervision of our Chief Financial Officer, and reports regularly to the Audit Committee on cybersecurity risks, typically on a quarterly basis.
The Partnership’s information technology function has a dedicated cybersecurity team comprised of employees with, on average, nearly 20 years of experience and expertise in cybersecurity, and includes individuals with degrees in Computer Studies and cybersecurity-related certifications including Certified Information Systems Security Specialist (CISSP), Certified in Risk and Information Systems Controls (CRISC), and Certified Information Security Manager (CISM).
Management utilizes certain tools and controls to detect, monitor, prevent, mitigate, and remediate cybersecurity threats to our systems, networks, applications, and data.
−Removed: Management also conducts annual cybersecurity training and periodic phishing tests, which provide contemporaneous feedback and instruction to our employees and strengthen the Partnership’s defenses against cyber threats.
+Added: Management also conducts annual cybersecurity training and periodic phishing tests, which provide contemporaneous feedback and instruction to our employees and seek to strengthen the Partnership’s defenses against cyber threats.
+Added: Management also monitors AI usage and has implemented a framework that tracks use and is governed by CVR Energy’s Artificial Intelligence Policy and includes a review and approval process for adopting use of AI tools.
+Added: Such governance activities are designed to mitigate the risks presented by AI.
Lastly, management maintains information security incident response processes to guide response and mitigate impact in the event of a cybersecurity incident.
4 unchanged sentences
Material Impact on Partnership
−Removed: During 2023 , the Partnership did not experience any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect the Partnership , including its business strategy, results of operations, or financial condition.
+Added: During 2024, 2023, and 2022 , the Partnership did not experience any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect the Partnership , including its business strategy, results of operations, or financial condition.
Refer to Part I, Item 1, “Facilities” of this Report for more information on our core business properties.
CVR Energy also leases property for our executive and marketing offices in Sugar Land, Texas and Kansas City, Kansas, respectively.
−Removed: December 31, 2023 | 32
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.