1 unchanged sentence
VF Corporation Fiscal 2025 Form 10-K 21
+Added: Table of Conten ts
CYBERSECURITY.
8 unchanged sentences
Audit Committee Primary oversight responsibility for cybersecurity, including internal controls designed to identify, assess, and manage risks related to cybersecurity
−Removed: Management Our Chief Information Security Officer ("CISO”), General Counsel, Chief Strategy and Business Development Officer (“CSBDO”), and other senior members of our digital and technology and risk teams are responsible for identifying, assessing, and managing risks related to these topics, and reporting to the Audit Committee and/or the full Board of Directors
−Removed: Management receives a cybersecurity and information security maturity assessment from a third-party assessor biannually to gain a third-party view of our cybersecurity and information security program.
+Added: Management Our Chief Information Security Officer ("CISO”), Chief Operating Officer (“COO”), Chief Legal Officer, and other senior members of our digital and technology and risk teams are responsible for identifying, assessing, and managing risks related to these topics, and reporting to the Audit Committee and/or the full Board of Directors
+Added: Management receives a cybersecurity and information security maturity assessment from a third-party assessor biennially to gain a third-party view of our cybersecurity and information security program.
We have integrated the identification, assessment and management of cybersecurity risks into VF’s enterprise risk management program, ensuring alignment with our overall approach to risk oversight by the Board, its committees, and management.
6 unchanged sentences
In addition, we have a cybersecurity and information security training and compliance program in place to support our teams who work in areas of cybersecurity and information security risk.
−Removed: As part of this program, VF associates who have access to confidential information receive training at least annually on cybersecurity and information security.
−Removed: To respond to the threat of security breaches and cyberattacks, VF maintains a program, overseen by VF’s CISO and CSBDO, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information and systems owned by, or in the care of, VF.
+Added: As part of this program, VF employees who have access to confidential information receive training at least annually on cybersecurity
+Added: and information security.
+Added: To respond to the threat of security breaches and cyberattacks, VF maintains a program, overseen by VF’s CISO and COO, that is designed to protect and preserve the confidentiality, integrity and continued availability of all information and systems owned by, or in the care of, VF.
This program also includes a cyber incident response plan that provides processes for timely and accurate reporting of any material cybersecurity incident.
−Removed: Our CISO has over thirty years of experience as a cybersecurity professional, including experience as the CISO of two large retailers, and reports to our CSBDO, who leads our digital and technology functions and has nearly twenty years of experience enabling digital transformation for
−Removed: global companies.
+Added: Our CISO has over thirty years of experience as a cybersecurity professional, including experience as the CISO of two large retailers, and reports to our COO, who leads our digital and technology functions and has nearly twenty years of experience enabling digital transformation for global companies.
In addition, members of VF’s information security, IT and privacy teams have broad experience and expertise in selecting, deploying and operating cybersecurity technologies, initiatives and processes around the world.
1 unchanged sentence
VF also maintains a cybersecurity risk insurance policy.
−Removed: VF’s IT systems have been subject to cybersecurity incidents in the past, including the previously disclosed December 2023 cybersecurity incident (the “Cyber Incident”).
−Removed: We believe the impacts of the Cyber Incident were not material to VF’s financial condition or results of operations.
−Removed: In addition, we do not believe that risks from cybersecurity threats have materially affected VF’s business strategy, financial condition, or results of operations.
−Removed: However, there is no guarantee that future cybersecurity incidents will not have a material impact in the future.
−Removed: Furthermore, processes designed to manage cyber risks, including those described herein, may not be effective.
−Removed: To learn more about risks from cybersecurity threats, as well as risks from the Cyber Incident, see the following risk factors in Item 1A of this Part I, under the headings, "VF relies significantly on information technology.
−Removed: Any inadequacy, interruption, integration failure or security failure of this technology could harm VF’s ability to effectively operate its business," "VF is subject to data and information security and privacy risks that could negatively affect its business operations, results of operations or reputation,” and "We experienced a significant data security breach in December 2023 which could result in a number of potentially unknown outcomes, including but not limited to, litigation, regulatory investigations or enforcement actions, or reputational harm, any of which could have a material impact on our business operations, financial condition, or results of operations." Additional risks and uncertainties not currently known or that may currently be deemed to be immaterial also may materially adversely affect VF’s business strategy, financial condition, or results of operations.
−Removed: VF is seeking reimbursement of costs, expenses and losses stemming from the Cyber Incident by submitting claims to VF’s cybersecurity insurers.
−Removed: The timing and amount of any such reimbursements are not known at this time.
+Added: VF’s IT systems have been subject to cybersecurity incidents in the past and there is no guarantee that future cybersecurity incidents will not have a material impact in the future.
+Added: To learn more about risks from cybersecurity threats, see the following risk factors in Item 1A of this Part I, under the headings, "VF relies significantly on information technology.
+Added: Any inadequacy, interruption, integration failure or security failure of this technology could harm VF’s ability to effectively operate its business," and "VF is subject to cybersecurity, information security and privacy risks that could negatively affect its business operations, results of operations or reputation.”
22 VF Corporation Fiscal 2025 Form 10-K
+Added: Table of Conten ts
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.