19 unchanged sentences
Incident Response Plans
−Removed: Visa’s global cyber security incident response team provides monitoring of Visa networks and digital assets across three cyber fusion centers in the U.S., United Kingdom, and Singapore.
+Added: Visa’s global cybersecurity incident response team provides monitoring of Visa systems and digital assets from three cyber fusion centers in the U.S., United Kingdom, and Singapore.
In addition, Visa’s threat intelligence and research teams monitor commercial and government intelligence sources for new and emerging threats.
−Removed: Our cybersecurity awareness team regularly publishes and shares information with Visa employees on emerging threats, such as deepfake and generative AI-powered social engineering schemes.
+Added: Our cybersecurity awareness team regularly publishes and shares information with Visa employees on emerging threats, such as deepfake and GenAI-powered social engineering schemes.
To address significant cybersecurity incidents and other crisis events, we maintain a business incident response plan, which identifies key stakeholders, defines escalation processes, and sets the thresholds above which our cybersecurity, legal, and crisis management teams will inform management’s Executive and Disclosure Committees as well as when the CEO and his designee will inform the board of directors of an incident.
18 unchanged sentences
As noted in our risk factors in Item IA of this report, our third-party risk management framework may not be implemented effectively or may not be successful or sufficient to mitigate all of our risks.
−Removed: When we become aware that a service provider, vendor, supplier, or other third party has experienced any compromise or failure in the cybersecurity infrastructure owned or controlled by such third party, we may attempt to mitigate our risk, including by terminating such third party’s connection to our information and technology assets where appropriate.
+Added: When we become aware that a service provider, vendor, supplier, or other third party has experienced any compromise or failure in the technology infrastructure owned or controlled by such third party, we may attempt to mitigate our risk, including by terminating such third party’s connection to our information and technology assets where appropriate.
+Added: We also regularly and proactively engage relevant vendors and other third parties to assess risk to Visa information assets when a new vulnerability or compromise is reported that may affect those third parties .
Management’s Role and Responsibilities
4 unchanged sentences
Since joining Visa in November 2015, he has been a core part of building Visa's Zero Trust Architecture and advancing VisaNet's cybersecurity defense capabilities.
−Removed: Our current President of Technology joined Visa in November 2013 and has over 30 years of experience in leading the development and deployment of commerce and transaction technologies, which includes overseeing cybersecurity risk and transformational technology initiatives.
+Added: Our current President of Technology joined Visa in November 2013 and has over 30 years of experience in leading the development, deployment and operations of broad technology platforms including commerce and transaction technologies, which includes overseeing cybersecurity risk and transformational technology initiatives.
At Visa, our President of Technology is responsible for the Company’s technology innovation and investment strategy, product engineering, cybersecurity, global IT, and operations infrastructure, and for accelerating the integration of engineering and product teams.
4 unchanged sentences
The updates to the ARC and the full board of directors provide an overview of our cybersecurity performance, progress against goals, cybersecurity threat landscape, and other relevant developments.
+Added: Our corporate headquarters are located in the San Francisco Bay Area.
+Added: As of September 30, 2025, we owned or leased office locations around the world, including four global data centers located in the U.S., the United Kingdom and Singapore.
+Added: We believe that these facilities are suitable and adequate to support our ongoing business needs.
+Added: Legal Proceedings
+Added: Refer to Note 20—Legal Matters to our consolidated financial statements included in Item 8 of this report.
+Added: Mine Safety Disclosures
+Added: Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.