4 unchanged sentences
Unisys’ process for assessing, identifying and managing material risks from cybersecurity threats .
−Removed: Protecting information, including information of our clients, is a top priority.
+Added: Protecting information, including that of our clients, is a top priority.
+Added: Our overall cybersecurity and privacy strategy is to protect our customers’ information and assets as well as ours to enable agility in the business.
We have expertise, dedicated resources and technology to identify, assess, respond to and mitigate material risks from cybersecurity threats.
−Removed: Our Global Information Security organization (GIS), led by our Chief Information Security Officer (CISO), establishes and maintains our company-wide information security management program and provides guidance for information security activities and controls at Unisys.
−Removed: Through our GIS, we:
−Removed: • establish and maintain corporate information security policies and procedures for identifying, assessing and addressing cybersecurity events;
−Removed: • track and analyze data as it moves through the information systems;
−Removed: • analyze the overall cybersecurity risk to information and systems (including the physical security and cybersecurity);
−Removed: • remediate known cybersecurity vulnerabilities;
−Removed: • follow evolving information security regulatory guidance for countries in which we operate and adjust internal policies, processes and remediation actions, as necessary.
−Removed: Our process for integrating cybersecurity risk management into our overall risk management system
−Removed: Our overall cybersecurity and privacy strategy is to protect and enable the business.
−Removed: We aim to protect ours and our customers’ information and assets to enable agility in the business.
−Removed: Our GIS manages Unisys’ cybersecurity risk identification, assessment, response, remediation and mitigation processes, and interfaces with other departments, including business units, the information technology department and enterprise risk management, to facilitate the risk processes and ensure the policies and procedures established by the GIS are integrated into our overall enterprise risk management system.
−Removed: The GIS’s processes also work in tandem with the processes maintained by our Global Privacy Office (GPO).
−Removed: Through our GPO, we deploy functional and business unit-specific approaches to data and privacy compliance.
−Removed: Taking into consideration the processes established by the GIS, our GPO has developed a framework of policies, procedures and other initiatives that are implemented across Unisys to help meet data privacy requirements.
−Removed: • is supported by a network of data protection officers, attorneys and privacy specialists across Unisys;
−Removed: • manages privacy management software that is used across Unisys to facilitate privacy impact assessments, record data processing activities and map data flows;
−Removed: • follows evolving privacy regulatory guidance for countries in which it operates and adjusts standards, as necessary.
−Removed: We have also adopted physical, technological and administrative cybersecurity controls including, among other items:
−Removed: • a dedicated cybersecurity incident response team, the Security Incident Response Team (SIRT), which is comprised of internal resources and an external vendor, Managed Security Services Provider (MSSP).
−Removed: The MSSP triages based on a combination of predetermined rules.
−Removed: When the MSSP has validated a true positive event, it is communicated to the internal SIRT team for deeper investigation and response;
−Removed: • a written policy provided to all associates regarding identification, classification of severity and escalation of cybersecurity incidents;
+Added: Our Global Information Security organization (GIS), led by our Chief Information Security Officer (CISO), manages Unisys’ cybersecurity risk identification, detection, assessment, response, mitigation and remediation processes, and interfaces with other departments, including business units, the information technology and legal departments, and enterprise risk management, to facilitate the risk management processes and ensure the policies and procedures established by GIS are integrated into our overall enterprise risk management system.
+Added: GIS processes also work in tandem with the processes maintained by our Global Privacy Office (GPO).
+Added: Through our GPO, we deploy functional and business unit-specific approaches to data and privacy compliance sharing threat intelligence daily and collaborate closely with the Corporate Information Technology (CIT) organization to build process and playbooks for cyber-resiliency.
+Added: Taking into consideration the processes established by GIS and CIT, our GPO has developed a framework of policies, procedures and other initiatives that are implemented across Unisys to help meet data privacy requirements.
+Added: Our GPO is supported by a network of data protection officers, attorneys and privacy specialists;
+Added: and manages privacy software that is used across Unisys to facilitate privacy impact assessments.
+Added: The GPO also records data processing activities, maps data flows and follows evolving privacy regulatory guidance for countries in which we operate and adjusts standards as necessary.
+Added: Our dedicated cybersecurity incident response team, the Security Incident Response Team (SIRT), is comprised of internal resources and an external vendor, Managed Security Services Provider (MSSP).
+Added: The MSSP triages and validates true positive events and then communicates to the internal SIRT team for deeper investigation and response.
+Added: Our physical and technological cybersecurity controls include, among other items:
• perimeter and endpoints firewalls, intrusion prevention systems, endpoint detection and response, Attack Surface Management, multi-factor authentication and email protection;
−Removed: • annual and ongoing cybersecurity awareness training for our associates — including regular training on information security and data privacy policies.
• routine testing of and training on our IT systems, including test phishing emails and awareness training opportunities;
−Removed: • cybersecurity policies, standards and practices that follow recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards, and follow evolving information security regulatory guidance for countries in which we operate;
• automation and alerts via embedded tools and procedures to monitor data and notify us of threats or other potential unauthorized occurrences on or conducted through our systems;
−Removed: • sharing threat intelligence daily with each business unit;
• multiple mechanisms by which employees can report cybersecurity and data privacy concerns, including a “Report Phish” button in the email application;
−Removed: • internal audits on our cybersecurity and data privacy practices;
• a vulnerability management program designed to protect our external and internal networks and critical assets;
−Removed: • an ongoing process of identifying, assessing, reporting on, managing and remediating cybersecurity vulnerabilities across endpoints, workloads and systems;
−Removed: • a level of cybersecurity insurance that Unisys believes is appropriate, taking into consideration the material risks from cybersecurity threats.
−Removed: We engage third-party service providers to assist us with our cybersecurity risk management system
−Removed: Third-party cybersecurity experts regularly supplement our cybersecurity risk management efforts, including those we engage to conduct periodic cybersecurity risk assessments.
−Removed: During 2023, Unisys engaged cybersecurity risk experts and external legal counsel to conduct a review of, and advise us on, our cybersecurity risk management processes, current cybersecurity risk environment, leading board governance practices, strategic cyber reporting and cyber resiliency.
−Removed: Following the review, we have further revised our processes for identifying material cybersecurity incidents and enhanced our written policy regarding identification, classification of severity and escalation of cybersecurity incidents.
−Removed: In 2023, Unisys engaged a leading cybersecurity firm to consult on several technical matters relating to cyber resiliency.
−Removed: This resulted in significant changes to our security technical stack and improvements to our processes and organization.
−Removed: Our processes to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers
+Added: • bug bounty capability, enabling ethical hackers to simulate real-world attacks to identify and report vulnerabilities;
+Added: • secure coding and development;
+Added: • security and operations framework and tools.
+Added: We design and assess our cybersecurity policies, standards and practices following recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards.
+Added: We have established written policies that are provided to all associates regarding identification, classification of severity and escalation of cybersecurity incidents and we provide annual and ongoing cybersecurity awareness training for our associates — including regular training on information security and data privacy policies.
+Added: We also perform internal audits on our cybersecurity and data privacy practices.
+Added: We regularly engage third-party cybersecurity experts to supplement our cybersecurity risk management efforts, including those we engage to conduct periodic cybersecurity risk assessments.
+Added: During 2024, Unisys engaged an external security firm to
+Added: conduct several cybersecurity tabletop exercises.
+Added: Additionally, we worked with an audit firm and directed several audits related to cybersecurity.
Unisys recognizes the importance of overseeing and identifying material risks from cybersecurity threats associated with our use of third-party service providers.
1 unchanged sentence
Our TPRM program includes policies and standards requiring that we perform cybersecurity due diligence reviews on our vendors based on the risk profile of a particular supplier or service provider or the service they provide.
−Removed: We also monitor certain of our principal suppliers and service providers on an ongoing basis by conducting additional periodic reviews.
+Added: We also monitor certain of our principal suppliers and service providers on an ongoing basis by using an outside-in, hacker perspective of a company’s cybersecurity posture through an external service provider.
Whether any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect Unisys, including its business strategy, results of operations, or financial condition and if so, how.
−Removed: The information set forth under “Risk Factors” (Part I, Item 1A of this Form 10-K) — “We have been and could be vulnerable to disruption in our IT systems, cybers incidents, security breaches and loss of data (associate and client) that have occurred, and may continue to occur, and have resulted in and could continue to result in the incurrence of significant costs and harm to our business and reputation.” — on page 14 of this Annual Report on Form 10-K is hereby incorporated by reference.
+Added: The information set forth under “Risk Factors” (Part I, Item 1A of this Form 10-K) — “We have been and could be vulnerable to disruption in our IT systems, cyber incidents, security breaches and loss of data (associate and client) that have occurred, and may continue to occur, and have resulted in and could continue to result in the incurrence of significant costs and harm to our business and reputation.” — on page 15 of this Annual Report on Form 10-K is hereby incorporated by reference.
As of December 31, 2024, our financial condition, results of operations or business strategy have not been materially affected by risks from cybersecurity threats, including as a result of previously identified cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks or any future material incidents.
3 unchanged sentences
The Board of Directors is responsible for oversight of Unisys’ information security program, including compliance and risk management, and the review of cybersecurity risks.
−Removed: The Security and Risk Committee (S&RC), a Board committee comprised entirely of independent directors, assists the Board in these oversight responsibilities.
−Removed: The S&RC’s responsibilities include:
−Removed: • reviewing crisis preparedness and incident response plans;
−Removed: • monitoring Unisys’ enterprise risk profile and its ongoing and potential exposure to risks of various types;
−Removed: • reviewing summaries of any incidents or activities;
−Removed: • reviewing reports or presentations from management or advisors, including third-party experts, regarding the management of enterprise risk programs;
−Removed: • periodically meeting with the CISO and Chief Privacy Officer (CPO);
−Removed: • periodically briefing the full Board of Directors on cybersecurity matters.
−Removed: Our S&RC chair previously served as the Chief Information Officer of a large healthcare company from 2011 to 2020 and as a Global Chief Information Officer at another company from 2004 to 2011.
−Removed: Other members of the S&RC have over forty years of executive and operational leadership experience at several global technology and telecommunications companies.
−Removed: Additionally, the A&FC has general oversight over Unisys’ cybersecurity as it relates to responsibility for Unisys’ internal audit function, including cybersecurity practices, compliance with legal and regulatory requirements and internal control over financial reporting.
−Removed: In November 2023, the A&FC charter was amended to ensure that it, in conjunction with the S&RC, reviews Unisys’ cybersecurity and other information technology controls and procedures no less than annually.
+Added: The Security and Risk Committee (S&RC), a Board committee comprised entirely of independent directors, assists the Board of Directors in these oversight responsibilities.
+Added: Additionally, the Audit and Finance Committee has general oversight over Unisys’ cybersecurity as it relates to responsibility for Unisys’ internal audit function, including cybersecurity practices, compliance with legal and regulatory requirements, and internal control over financial reporting.
+Added: The S&RC’s responsibilities include monitoring Unisys’ enterprise risk profile and its ongoing and potential exposure to risks of various types and reviewing crisis preparedness;
+Added: incident response plans;
+Added: summaries of any incidents or activities;
+Added: and reports or presentations from management or advisors, including third-party experts, regarding the management of enterprise risk program.
+Added: The S&RC periodically meets with the CISO and Chief Privacy Officer (CPO) and briefs the full Board of Directors on cybersecurity matters.
+Added: Our S&RC chair has previously served in the role of Chief Information Officer at two large companies for over 15 years.
+Added: Other members of the S&RC have extensive years of executive and operational leadership experience at several global technology and telecommunications companies.
Management’s Role in Assessing and Managing the Company’s Material Risks from Cybersecurity Threats.
−Removed: The Disclosure Committee assists in fulfilling our obligations to maintain disclosure controls and procedures and coordinates and oversees the process of preparing our periodic securities filings with the Securities and Exchange Commission.
+Added: The Disclosure Committee, a senior executive leadership committee, assists in fulfilling our obligations to maintain disclosure controls and procedures and oversees the process of preparing our periodic securities filings with the Securities and Exchange Commission.
Cybersecurity incidents, based on their severity, are escalated to the Disclosure Committee by the SIRT.
−Removed: The Disclosure Committee is comprised of the Chief Executive Officer (CEO), Chief Operating Officer (COO), Chief Financial Officer, General Counsel, Chief Compliance Officer and Chief Accounting Officer.
−Removed: The COO represents the business units of the company and the CISO reports to the COO.
+Added: The Disclosure Committee is comprised of the Chief Executive Officer, Chief Operating Officer, Chief Financial Officer, General Counsel, Chief Compliance Officer and Chief Accounting Officer.
The Disclosure Committee meets on a quarterly basis and more often, if necessary, and invites subject matter experts to meetings as appropriate.
We have policies and procedures in place designed to provide appropriate information of any matters to our Disclosure Committee that should be considered in advance of applicable public filings, including cybersecurity matters, and to address the proper handling and escalation of information to management and the Board of Directors or a committee of the Board of Directors.
−Removed: In addition to the oversight of the Board of Directors, members of our management are responsible for assessing and managing material cybersecurity risks.
−Removed: Our CISO served as the CISO for Hertz Global Holdings, Inc.
−Removed: (Hertz), and prior to joining Hertz, held progressively senior information security roles at Hitachi Vantara LLC, Hewlett-Packard Company, Symantec Corp.
−Removed: and Marketo, Inc.
−Removed: Our CPO previously served as the Global Data Privacy Officer for Hitachi Vantara LLC and prior to that practiced at the law firm of Littler Mendelson, P.C.
−Removed: as an attorney specializing in data privacy among other areas.
+Added: In addition to the oversight by the Board of Directors, members of our management are responsible for assessing and managing material cybersecurity risks.
+Added: Our CISO has over 34 years of experience in cybersecurity, applications, infrastructure and networks in information security.
+Added: Our CPO has over 8 years of experience serving as a Global Data Privacy Officer and practicing law specializing in data privacy among other areas.
Our Chief Information Officer (CIO) has over 20 years at Unisys with experience and knowledge of IT infrastructure, systems and operations.
−Removed: and previously our CIO spent two years as the CIO for Whitney, Bradley & Brown, Inc.
At Unisys, the CIO partners with our CISO and CPO on cybersecurity risk management matters.
1 unchanged sentence
LEGAL PROCEEDINGS
−Removed: Information with respect to litigation is set forth in Note 18, “Litigation and contingencies,” of the Notes to Consolidated Financial Statements and is incorporated herein by reference.
+Added: Information with respect to litigation is set forth in Note 18, “Litigation and contingencies,” of the Notes to Consolidated Financial Statements in Part II, Item 8 of this Form 10-K and is incorporated herein by reference.
MINE SAFETY DISCLOSURES
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.