4 unchanged sentences
At Western Digital, our management team is charged with managing risk and bringing to our Board of Directors’ attention all material risk exposures to our company.
−Removed: Our enterprise risk management (“ERM”) process is designed to facilitate the identification, assessment, management, reporting and monitoring of material risks our company may face over the short-term and long-term and assure regular communication with our Board of Directors and its committees regarding these risks.
−Removed: Through our ERM process, we have determined that the compromise, damage or interruption of our technology infrastructure, information systems or products by cybersecurity incidents is a key risk to our company that may have a material negative impact on our business.
+Added: Our enterprise risk management (“ERM”) process is designed to facilitate the identification, assessment, management, reporting and monitoring of material risks our company may face over the short-term and long-term and promote regular communication with our Board of Directors and its committees regarding these risks.
+Added: Through our ERM process, we have determined that the compromise, damage and interruption of our technology infrastructure, information systems or products by cybersecurity incidents are key risks to our company that may have a material negative impact on our business.
To help mitigate the potential impact of cybersecurity incidents on our business and protect against cybersecurity threats, we have established organizational structures, procedural measures and response plans that define roles and responsibilities related to cybersecurity risk management.
−Removed: Western Digital’s Information Security organization addresses cybersecurity risks with a broad spectrum of technologies, controls, and processes that focus on mitigating these risks.
+Added: Our Information Security organization addresses cybersecurity risks with a broad spectrum of technologies, controls, and processes that focus on mitigating these risks.
Our cybersecurity strategy is designed to be dynamic and adaptive to combat the rapidly-evolving cybersecurity threat landscape and is influenced by commonly leveraged frameworks such as the NIST-CSF (National Institute of Standard and Technologies – CyberSecurity Framework).
4 unchanged sentences
Additionally, we have established a Cyber Incident Response Plan that follows the structure of the Incident Handling Guide published by the U.S.
−Removed: National Institute of Standards and Technology (SP 800-61r2) and that serves as an operational guide for handling cybersecurity incidents at Western Digital.
+Added: National Institute of Standards and Technology (SP 800-61r2) and that serves as an operational guide for handling cybersecurity incidents.
Our Cyber Incident Response Plan provides procedural and strategic guidance that is designed to be flexible enough to apply to a variety of different incidents, but also specific enough to provide guidelines for incident prevention, detection, analysis, escalation and notification, and containment, eradication and recovery.
−Removed: As part of our ongoing information security program, Western Digital utilizes periodic independent third-party experts to conduct assessments of our program’s effectiveness.
+Added: As part of our ongoing information security program, we utilize periodic independent third-party experts to conduct assessments of our program’s effectiveness.
These experts are also leveraged to design and orchestrate tabletop exercises where multiple business functions and leadership levels must navigate complex incident scenarios to help determine our level of preparedness for various cybersecurity incidents.
−Removed: As part of our business operations, Western Digital engages with a number of third parties, including but not limited to, online software service providers, vendors, consultants, and partners.
−Removed: Each of these third-parties must be cleared through a formal cybersecurity risk assessment process before being allowed to integrate with Western Digital’s information systems, access confidential data, or provide electronic services to members of our workforce.
+Added: As part of our business operations, we engage with a number of third parties, including but not limited to, online software service providers, vendors, consultants, and partners.
+Added: Each of these third parties must be cleared through a formal cybersecurity risk assessment process before being allowed to integrate with our information systems, access confidential data, or provide electronic services to members of our workforce.
Additionally, further scrutiny is applied during the post-assessment onboarding process in order to fine-tune access rights to limit privileges to those necessary to enable the related service, resulting in a least-privilege level of access.
−Removed: Western Digital has in the past experienced cybersecurity incidents of varying degrees involving our technology infrastructure and information systems, including incidents in which unauthorized parties have obtained access to our information systems and networks.
+Added: We have in the past experienced cybersecurity incidents of varying degrees involving our technology infrastructure and information systems, including incidents in which unauthorized parties have obtained access to our information systems and networks.
While these incidents have at times resulted in some disruptions to our business operations, as of the date of this Annual Report on Form 10-K, we do not believe that known risks from cybersecurity threats, including as a result of any previous cybersecurity incident, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
1 unchanged sentence
Further details about the cybersecurity risks we face are described under “ The compromise, damage or interruption of our technology infrastructure, information systems or products by cybersecurity incidents, data security breaches, other security problems, design defects, information system failures or other events could have a material negative impact on our business” in Part I, Item 1A, Risk Factors, of this Annual Report on Form 10-K.
−Removed: Western Digital has implemented a governance framework related to cybersecurity that includes operational risk-mitigation practices and Board-level cybersecurity risk oversight.
+Added: We have implemented a governance framework related to cybersecurity that includes operational risk-mitigation practices and Board-level cybersecurity risk oversight.
Our management team is charged with managing cybersecurity risk and identifying material cybersecurity risk exposures to our company and carries out this function primarily through our Information Security organization, which is led by our Chief Information Security Officer who has a master’s degree in computer science, over a decade of information security leadership, and thirty years of combined IT leadership experience.
1 unchanged sentence
The Impact Assessment Committee is led by our Chief Information Security Officer and includes key representatives from the Company’s functional groups, including human resources, ethics and compliance, labor, privacy, internal audit, finance, communications, legal, risk and accounting.
−Removed: The Impact Assessment Committee receives updates and communications from the Security Operations Center on a fixed cadence determined by incident severity and follows our pre-established escalation framework to communicate with and include executive leadership, outside counsel and the Board of Directors, as appropriate.
−Removed: The Impact Assessment Committee works with the Company’s internal and external legal counsel to determine and facilitate appropriate communications with the Board of Directors.
+Added: The Impact Assessment Committee receives updates and communications from the Security Operations Center on a fixed cadence determined by incident severity and follows our pre-established escalation framework provided by our Security Incident Response Plan to communicate with and include executive leadership, outside counsel and our Board of Directors, as appropriate.
+Added: The Impact Assessment Committee works with our internal and external legal counsel to determine and facilitate appropriate communications with our Board of Directors.
Our Board of Directors is responsible for overseeing the cybersecurity risk management process and exercises this risk oversight through both our full Board of Directors and its Audit Committee.
−Removed: Our Board of Directors has delegated to the Audit Committee the responsibility to oversee risks related to cybersecurity threats, and our Audit Committee Charter requires the Audit Committee to review and discuss with management the Company’s policies with respect to risk assessment and enterprise risk management and to review the risk exposure of the Company related to the Committee’s areas of responsibility, including with respect to cybersecurity.
−Removed: In carrying out this role, the Audit Committee meets with our Chief Information Security Officer regularly and receives at least quarterly reports on cybersecurity matters.
+Added: Our Board of Directors has delegated to our Audit Committee the responsibility to oversee risks related to cybersecurity threats, and our Audit Committee Charter requires our Audit Committee to review and discuss with management the Company’s policies with respect to risk assessment and enterprise risk management and to review the risk exposure of the Company related to the Committee’s areas of responsibility, including with respect to cybersecurity.
+Added: In carrying out this role, our Audit Committee meets with our Chief Information Security Officer regularly and receives at least quarterly reports on cybersecurity matters.
Additionally, at least annually, our chief audit executive, who manages the day-to-day activities of our ERM program, reports to our Board of Directors on enterprise risk assessment under our ERM program, providing updates on key risks, status of mitigation efforts and residual risk trends, including an analysis of cybersecurity risks.
−Removed: Also at least annually, our Chief Information Security Officer reports to the full Board of Directors on cybersecurity matters related to or impacting our company and our business.
+Added: Also at least annually, our Chief Information Security Officer reports to our full Board of Directors on cybersecurity matters related to or impacting our company and our business.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.