2 unchanged sentences
Cybersecurity Risk Management and Strategy
−Removed: We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.
−Removed: We design and assess our program based on the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF and AI Risk Management Framework).
−Removed: This does not mean that we meet any particular technical standards, specifications, or requirements, but only that we use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: Information about cybersecurity risks and our risk management processes is collected, analyzed and considered as part of our overall enterprise risk management program.
+Added: We maintain a cybersecurity risk management program intended to identify, assess, and manage risks to the confidentiality, integrity, and availability of our information technology systems and data that support our operations and financial reporting.
+Added: Our operations depend on a combination of proprietary and third-party systems, including transportation management, warehouse management, dispatch, billing, and customer-facing platforms.
+Added: Our cybersecurity risk management program is informed by, but does not purport to fully comply with, the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) and the NIST AI Risk Management Framework.
+Added: These frameworks are used as reference points to help identify and manage cybersecurity risks relevant to our business and operating environment.
+Added: Use of these frameworks does not imply that we meet any particular technical standards, specifications, or requirements.
+Added: Cybersecurity risks and related risk management activities are evaluated as part of our broader enterprise risk management processes and are considered alongside other operational, financial, and compliance risks.
+Added: Given the evolving nature of cybersecurity threats, the complexity of our information technology environment, and our reliance on third-party service providers, we face ongoing cybersecurity risks that may not be fully preventable.
Key components of our cybersecurity risk management program include:
−Removed: • risk assessments designed to help identify cybersecurity risks to our critical systems, information, services, and our broader enterprise IT environment;
−Removed: • a security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) architecture, implementation and monitoring of our security controls and infrastructure, and (3) our response to cybersecurity incidents;
−Removed: • the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes;
−Removed: • cybersecurity awareness training of our employees, incident response personnel and senior management;
−Removed: • a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
−Removed: At this time, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations, or financial condition.
−Removed: We face certain ongoing risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
−Removed: For an additional discussion of certain risks associated with cybersecurity see Item 1A, “Risk Factors” above.
+Added: • periodic risk assessments designed to identify cybersecurity risks to our systems, data, and operations;
+Added: • a dedicated security team responsible for cybersecurity risk assessment, security architecture, control implementation, monitoring, and incident response activities;
+Added: • the use of third-party service providers, where appropriate, to assist with security assessments, testing, monitoring, or advisory services;
+Added: • cybersecurity awareness and training programs for employees, including personnel involved in incident response and financial reporting processes;
+Added: • an incident response plan that outlines procedures for detecting, responding to, mitigating, and remediating cybersecurity incidents.
+Added: While we have not experienced a cybersecurity incident that has had a material impact on our business, operations, or financial condition, we have experienced, and may continue to experience, technology-related disruptions or challenges.
+Added: Cybersecurity incidents, including those resulting from ransomware, data breaches, system failures, or third-party vulnerabilities, could occur in the future and could adversely affect our operations, financial reporting, customer relationships, or reputation.
+Added: For additional discussion of cybersecurity-related risks, see Item 1A, “Risk Factors.”
Cybersecurity Governance
−Removed: Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of cybersecurity and other information technology risks.
−Removed: The Audit Committee oversees management’s implementation of our cybersecurity risk management program.
−Removed: The Audit Committee receives quarterly reports from management on our cybersecurity risks.
−Removed: In addition, management updates the Audit Committee, as necessary, regarding any significant cybersecurity incidents.
−Removed: The Audit Committee reports to the full Board regarding its activities, including those related to cybersecurity, and the full Board also receives a periodic briefing from management on our cyber risk management program.
−Removed: Our Cybersecurity team, led by our Vice President of Cyber Security, is responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: The team is led by individuals who, on a combined basis, have more than 30 years of IT and cybersecurity related experience across multiple industries.
−Removed: Our Vice President of Cyber Security has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and any retained external cybersecurity consultants.
−Removed: Our Cybersecurity team is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents through various means, which may include, among other things, briefings with internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us, and alerts and reports produced by security tools deployed in our IT environment.
−Removed: Our headquarters, where we maintain our corporate administrative offices, are in Warren, Michigan.
−Removed: We own our corporate administrative offices, as well as 24 terminal yards and other properties in the following locations:
+Added: Our Board of Directors oversees cybersecurity risk as part of its overall risk oversight responsibilities and has delegated primary oversight of cybersecurity and information technology risks to the Audit Committee.
+Added: The Audit Committee receives periodic updates from management regarding cybersecurity risks, program initiatives, and, as appropriate, significant incidents or emerging threat developments.
+Added: The Audit Committee reports to the full Board on matters within its oversight scope, and the full Board may also receive periodic briefings from management on cybersecurity and technology risks.
+Added: Management is responsible for the day-to-day management of cybersecurity risks.
+Added: Our cybersecurity risk management program is led by our Chief Technology Officer, who is supported by internal personnel and, as appropriate, external advisors.
+Added: Our Chief Technology Officer has over 20 years of cybersecurity experience.
+Added: Collectively, members of the cybersecurity leadership team have experience in information technology, cybersecurity, and risk management across multiple industries.
+Added: The Chief Technology Officer has primary responsibility for implementing and maintaining our cybersecurity risk management program and for coordinating incident response activities.
+Added: Management monitors cybersecurity risks and incidents through a combination of internal reporting , security tools deployed across our information technology environment, threat intelligence, and information obtained from governmental, public, and private sources, including third-party service providers.
+Added: Despite these efforts, no cybersecurity risk management program can eliminate all risks, and we may not be able to prevent or timely detect all cybersecurity incidents.
+Added: Our principal executive offices and corporate administrative headquarters are located in Warren, Michigan.
+Added: We own our headquarters facility, as well as a number of terminal yards and other operating properties located in the following U.S.
Dearborn, Michigan;
3 unchanged sentences
Jacksonville, Florida;
−Removed: Garden City, Georgia;
Savannah, Georgia;
15 unchanged sentences
and Clearfield, Utah.
−Removed: As of December 31, 2024, we also leased 78 operating, terminal and yard, and administrative facilities in various U.S.
−Removed: cities located in 24 states, in Windsor, Ontario;
−Removed: and in Monterrey, Mexico;
−Removed: San Luis Potosí, Mexico;
−Removed: and Toluca, Mexico.
−Removed: Generally, our facilities are utilized by our operating segments for various administrative, transportation-related or value-added services.
−Removed: We also deliver value-added services under our contract logistics segment inside or linked to 54 facilities provided by customers.
−Removed: Certain of our leased facilities are leased from entities controlled by our majority shareholders.
−Removed: These facilities are leased on either a month-to-month basis or extended terms.
−Removed: For more information on our lease arrangements, see Part II, Item 8:
−Removed: Notes 11, 13 and 16 to the Consolidated Financial Statements.
+Added: As of December 31, 2025, we also leased approximately 59 operating, terminal, yard, and administrative facilities located throughout the United States, Canada, and Mexico, including facilities in Windsor, Ontario, and in Monterrey, San Luis Potosí, and Saltillo, Mexico.
+Added: Our leased and owned facilities are generally used by our operating segments for administrative functions, transportation services, intermodal operations, and value-added contract logistics activities.
+Added: In addition, within our contract logistics segment, we provide value-added services at or adjacent to facilities owned or controlled by customers, under contractual arrangements, at approximately 50 customer-provided locations as of December 31, 2025.
+Added: Certain of our leased facilities are leased from entities controlled by our controlling stockholders.
+Added: These facilities are leased on either month-to-month terms or pursuant to longer-term lease arrangements.
+Added: We believe that all such leases are entered into on terms that are consistent with market conditions.
+Added: For additional information regarding our lease arrangements, including related-party leases, see Part II, Item 8—Notes 11, 13, and 16 to the Consolidated Financial Statements.
+Added: We believe that our existing facilities, together with facilities available through leasing arrangements and customer-provided locations, are adequate for our current operations and anticipated near-term growth.
+Added: From time to time, we may acquire, lease, or dispose of facilities in connection with changes in customer demand, operational requirements, or strategic initiatives.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.