1 unchanged sentence
Cybersecurity
−Removed: Viatris operates in a complex and rapidly changing environment that involves many potential risks, including IT and cybersecurity risks.
+Added: Viatris operates in a complex and rapidly changing environment that involves many potential risks, including IT, information security, cybersecurity, and AI risks.
Risk management is an enterprise-wide objective and is subject to oversight by the Viatris Board and its committees.
2 unchanged sentences
For each key or emerging risk identified, the Company establishes risk monitoring ownership, from which quarterly updates are collected for executive management and the Viatris Board’s Compliance and Risk Oversight Committee.
−Removed: With respect to IT and cybersecurity risks, Viatris maintains an information security program that is aligned with the National Institute of Standards and Technology Cybersecurity Framework, and which is designed to govern, identify, protect, detect, respond to and recover from cybersecurity threats.
−Removed: Viatris’ information security program includes policies, procedures, cybersecurity awareness communications, testing, and training for employees (including mandatory training programs for system users), system monitoring, risk reduction, vulnerability and patch management and monitoring of external developments.
−Removed: The information security team is responsible for defining and overseeing the execution of the Company’s information security program and strategy.
+Added: With respect to cybersecurity risks, Viatris maintains a cybersecurity program that is aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework, designed to govern, identify, protect, detect, respond to and recover from cybersecurity threats.
+Added: Viatris’ cybersecurity program includes policies, procedures, awareness communications, testing, and training for employees (including mandatory training programs for privileged users), as well as system monitoring, risk reduction, vulnerability and patch management and monitoring of external threats.
+Added: The Global Security team is responsible for defining and overseeing the execution of the Company’s cybersecurity program and strategy.
The Viatris IT team, led by the Chief Information Officer, is responsible for ongoing security operations such as maintaining firewalls and patch management.
−Removed: In addition, the delivery of many information security programs relies on IT resources to execute the selection, delivery and implementation of security solutions, such as end-point protection and end-of-life protocols.
−Removed: The Company’s Chief Information Security Officer & Head of Global Security , under the direction of the Company’s Chief Compliance Officer, reports quarterly to an internal risk committee of senior management, which includes the CEO, CFO, Chief Legal Officer, Chief People Officer, Chief Corporate Affairs Officer, Chief Information Officer, Chief Compliance Officer, Chief Quality Officer, Chief Supply Officer, Chief R&D Officer and Regional Presidents, as well as the Viatris Board on the progress of the information security program and overall security status.
−Removed: Viatris’ current Chief Information Security Officer & Head of Global Security has over 25 years of experience in information security within the pharmaceutical industry.
−Removed: As part of its information security program, Viatris has adopted a Cybersecurity Incident Response Plan (CIRP) to establish a guide for Viatris’ leadership and incident response stakeholders through an “incident” – a single event or a set of anomalous and adverse “events” or, for purposes of the CIRP, a change in a system, technology device or environment that could impact the confidentiality, integrity, availability or safety of Viatris’ data, employees or assets, caused by malicious intent or accident and impacting Viatris’ network, computing systems, digital information, employees or assets.
−Removed: The CIRP is managed by the Viatris global information security team and is reviewed at least annually.
−Removed: Viatris tests the CIRP through technical exercises semi-annually, reviews the CIRP with executive management annually, and periodically conducts executive tabletop exercises/scenarios.
−Removed: The CIRP provides an overview of critical actions to take through the incident response lifecycle and contains a severity matrix used to guide the Company’s incident response stakeholders on communication and escalation protocols.
−Removed: The severity of the incident guides the determination of the parties to whom the incident will be escalated, and the Company may decide to seek assistance from a third-party incident response vendor.
−Removed: Viatris’ Cybersecurity Incident Response Team (CIRT) reports to the Chief Information Security Officer & Head of Global Security and has the role of investigating and executing incident protocols.
−Removed: The CIRT is responsible for determining the potential impacts to the Company, including severity, notifying appropriate parties pursuant to the CIRP and determining whether to engage a third-party incident response vendor, among other responsibilities.
+Added: In addition, the delivery of many cybersecurity programs relies on IT resources to execute the selection, delivery and implementation of security solutions, such as identity and access management, end-point protection and end-of-life protocols.
+Added: The Company’s Chief Information Security Officer & Head of Global Security , under the direction of the Company’s Chief Administrative and Transformation Officer, reports quarterly to an internal risk committee of senior management, which includes the CEO, CFO, Chief Legal Officer, Chief Administrative and Transformation Officer, Chief People and Corporate Affairs Officer, Chief Information Officer, Chief Compliance Officer, Chief Supply Officer, Chief R&D Officer and Regional Presidents, as well as the Viatris Board on the progress of the cybersecurity program and overall security status.
+Added: Viatris’ current Chief Information Security Officer & Head of Global Security has over 30 years of experience in cybersecurity within the pharmaceutical industry.
+Added: As part of its cybersecurity program, Viatris has adopted a Cybersecurity Incident Response Plan (CIRP) to establish a guide for Viatris’ leadership and incident response stakeholders through an “incident” – a single event or a set of anomalous and adverse “events” or, for purposes of the CIRP, a change in a system, technology device or environment that could impact the confidentiality, integrity, availability or safety of Viatris’ data, employees or assets, caused by malicious intent or accident and impacting Viatris’ network, computing systems, digital information, employees or assets.
+Added: The CIRP is managed by the Viatris global security team and their managed security service providers and is reviewed at least annually.
+Added: Viatris tests the CIRP through semi-annual technical exercises and periodically conducts executive tabletop exercises/scenarios.
+Added: The CIRP provides an overview of critical actions to take throughout the incident response lifecycle and contains a severity matrix used to guide the Company’s incident response stakeholders on communication and escalation protocols.
+Added: The severity of the incident guides the determination of the parties to whom the incident will be escalated, and the Company may decide to seek assistance from third-party incident response vendors.
+Added: Viatris’ Cybersecurity Incident Response Team (CIRT) reports to the Chief Information Security Officer & Head of Global Security and has the role of responding to incidents and executing incident protocols.
+Added: The CIRT is responsible for determining the potential impacts to the Company, including type and severity, notifying appropriate parties pursuant to the CIRP and determining whether to engage a third-party incident response vendor, among other responsibilities.
Critical incidents require implementation of the global crisis plan and high severity incidents require notification to the executive leadership team once such an incident is confirmed.
−Removed: The Company’s Disclosure Controls and Procedures also require (i) the Company’s Information Security function to monitor and escalate, as appropriate, cybersecurity incidents or series of related incidents (including with respect to any third party provider to the Company of IT services) and (ii) the Disclosure Committee to determine, without unreasonable delay, the materiality of any such escalated cybersecurity incidents or series of related incidents with input from Global Compliance, Information Security, Legal, Finance and other groups, as appropriate.
+Added: The Company’s Disclosure Controls and Procedures also require (i) the Company’s Cybersecurity function to monitor and escalate, as appropriate, cybersecurity incidents or series of related “incidents” (including with respect to any third party provider to the Company of IT services) and (ii) the Disclosure Committee to determine, without unreasonable delay, the materiality of any such escalated cybersecurity incidents or series of related incidents with input from Global Compliance, Global Privacy, Global Security, Legal, Finance and other groups, as appropriate.
The Company participates in several industry and third-party threat monitoring and information-sharing services, and these engagements provide insight into vulnerabilities and threats which are incorporated into the security operations and IT remediation.
−Removed: Key aspects of the information security program are also provided by third-party managed security providers, including first- and second-line support for incident response and the Company’s vulnerability assessment process.
−Removed: Our suppliers, subcontractors and third-party service providers, including third-party managed security providers, are subject to cybersecurity obligations and controls.
−Removed: We conduct initial risk assessments of third-party suppliers and service providers based
−Removed: on various factors and then review and monitor these third-party suppliers and service providers based on their relative assessed level of risk.
+Added: Key aspects of the cybersecurity program are also provided by third-party managed security providers, including first- and second-line support for incident response and the Company’s vulnerability assessment process.
+Added: Our suppliers,
+Added: subcontractors and third-party service providers, including third-party managed security providers, are subject to cybersecurity obligations and controls.
+Added: We conduct initial risk assessments of third-party suppliers and service providers based on various factors and then review and monitor these third-party suppliers and service providers based on their relative assessed level of risk.
We also require our suppliers, subcontractors and third-party service providers to agree to cybersecurity-related contractual terms and conditions of purchase.
2 unchanged sentences
Otherwise, the Compliance and Risk Oversight Committee receives reports from executive management on data security, cybersecurity and information security-related matters on at least a quarterly basis, including with respect to related risks, risk management, risk reduction programs, and relevant legislative, regulatory, and technical developments.
−Removed: On a biannual basis, the Compliance and Risk Oversight Committee and chairs of each other Committee of the Viatris Board receive an information security update from the Company’s Chief Information Security Officer & Head of Global Security, the Chief Compliance Officer and the Chief Information Officer.
+Added: On a biannual basis, the Compliance and Risk Oversight Committee and chairs of each other Committee of the Viatris Board receive a cybersecurity update from the Company’s Chief Information Security Officer & Head of Global Security, the Chief Compliance Officer and the Chief Information Officer.
The full Viatris Board receives a report on the respective quarterly discussions from the Chair of the Compliance and Risk Oversight Committee each quarter.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.