1 unchanged sentence
CYBERSECURITY
−Removed: Under our “Cloud First, Cloud Now” strategy, we are increasingly relying on cloud-based technology to enable more innovation, enhance customer service, and keep up with the complex demands of the ever-changing trucking and logistics landscape.
−Removed: We are incorporating cybersecurity into this strategy by investing in key technology and skillset development to help protect the confidentiality, integrity, and availability of our systems and electronic data.
−Removed: In addition, we are committed to using reasonable efforts, given identified or reasonably anticipated threats, to prevent information security breaches.
−Removed: We have not experienced any such breach in any of the three years shown in the financial statements in this filing or in 2024 through the date hereof, and cybersecurity threat risks have not materially affected our business strategy, results of operations or financial condition.
−Removed: Based on our analysis of the current threat environment, we do not believe that any such material impacts are reasonably likely to occur.
−Removed: See Item 1A of Part I of this Form 10-K for a discussion of risks and uncertainties related to our information systems and technology infrastructure.
−Removed: We employ a dedicated cybersecurity team.
−Removed: In coordination with our Chief Information Officer, the team assesses and manages cybersecurity threat risks with a focus on identity verification, system access and security, and governance, risk, and compliance.
−Removed: Our Chief Information Officer has extensive information technology and strategic leadership experience, including modernizing and securing business applications and technology stacks.
−Removed: Our director of cybersecurity is a certified information systems security professional with broad experience in cybersecurity, much of which was gained working for the U.S.
−Removed: Various members of the cybersecurity team hold industry certifications.
−Removed: The Chief Information Officer regularly shares cybersecurity developments and concerns with the Chief Executive Officer and with other executive officers as concerns arise that impact their areas.
−Removed: The Audit Committee of the Board is responsible for oversight of risk management related to cybersecurity and policies and procedures related to the protection of Company proprietary and customer information and compliance with data privacy requirements.
−Removed: The Audit Committee receives quarterly updates from our Chief Information Officer.
−Removed: Reports may address evolving trends in cybersecurity, major threat developments, and technologies, solutions, policies, and procedures we use to detect, prevent, mitigate and remediate threats, respond to incidents and crises, and educate employees on information security importance and requirements.
−Removed: The Audit Committee has regular opportunities to suggest adjustments to the Company’s cybersecurity practices.
−Removed: It regularly reports to the Board on fulfillment of its responsibilities, which include cybersecurity risk management oversight.
−Removed: To design and update our cybersecurity strategy, including awareness, prevention, detection, response and recovery components, we strive to align with a respected maturity framework, and we periodically, with the help of a third-party, analyze our alignment.
−Removed: We use a variety of tools to help identify anomalous activity on our systems, including without limitation logs, artificial intelligence, software programs, and data analyses.
−Removed: In addition to internal resources, we use third-party services and software to monitor our cyber environment for detected risks, including without limitation risks from cyber-attackers, employees, and third-parties that we allow to access or contribute to our information technology systems, and to block threats.
−Removed: To assess system vulnerability, we periodically simulate threats, and following such exercises, we assess penetration results and determine and implement remediations.
−Removed: Executive management fosters a cybersecurity threat awareness and risk mitigation culture by supporting regular educational phishing simulations and advocating the importance of cybersecurity in communications to employees.
−Removed: We maintain information security policies to promote employee use of our information technology in a safe manner that helps protect our systems and data from cybersecurity events, and we require periodic enterprise-wide security training and testing and analyze test results.
−Removed: Cybersecurity is integrated with our overall risk management program through cyber coverage as an important component of our insurance portfolio.
−Removed: We maintain cyber insurance to help protect against potential loss or expense arising from a cybersecurity incident or data breach.
−Removed: As part of our cyber insurance renewal, we coordinate with our insurance broker cyber experts to assess our cybersecurity program and align our coverages with our risk management framework.
−Removed: Our oversight processes for reviewing threats from third-parties that we allow to access or contribute to our information technology systems are also important to overall risk management.
−Removed: We subject such third-parties to a variety of cybersecurity analyses, which include our use of risk assessments or scorecards and receipt of third-party audit or other reports related to information security.
−Removed: We have a program for organized response in the event of a cybersecurity incident.
−Removed: Our Chief Information Officer receives alerts disseminated via the program and reports to the Chief Executive Officer as deemed prudent.
−Removed: In the event the incident rises to the level of a crisis, the cyber component of our crisis management plan is triggered.
−Removed: The plan guides a cyber crisis management team, including representatives from our legal, information technology, finance and operations areas, in analyzing the type, scope, cause, impact and other details of the crisis.
−Removed: Our analysis includes without limitation identifying affected systems and exposed data, and in making key decisions to abate, mitigate or respond to the crisis, drawing on pre-identified third-party sources of forensic and other expertise as deemed necessary or advisable.
−Removed: Responsive steps include oversight of any warranted or required communications, including without limitation potential outreach to law enforcement, and inform ing the Board or Audit Committee of the incident as required by the plan.
−Removed: A final step is for the team to review lessons learned during the incident with the purpose of strengthening future crisis response.
−Removed: The team periodically reviews and practices its protocols to enhance its effectiveness.
+Added: Under our “Cloud First, Cloud Now” strategy, we prioritize usage of cloud-based technologies to foster innovation, enhance customer service, and meet the demands of the evolving logistics landscape.
+Added: Cybersecurity is integrated into this strategy through investments in technology and skill development to help protect the confidentiality, integrity, and availability of our systems and electronic data.
+Added: During the period covered by this Form 10-K and through the date of its filing, we have not experienced, to our knowledge, an information security breach or identified cybersecurity threat risks that have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition.
+Added: However, we recognize that cybersecurity threats are continually evolving, as further addressed in Item 1A of Part I of this Form 10-K.
+Added: Our dedicated cybersecurity team, in coordination with our Chief Information Officer (“CIO”) , assesses and manages risks by focusing on identity verification, system access controls, and governance, risk, and compliance processes.
+Added: The CIO, with extensive information technology (“IT”) and strategic leadership experience, is supported by a director of cybersecurity, a Certified Information Systems Security Professional with significant military cybersecurity expertise, and a team holding various industry certifications and having collective cybersecurity experience of over 75 years.
+Added: The CIO regularly reports cybersecurity matters to the Chief Executive Officer and executive leadership, for alignment with broader organizational goals.
+Added: The Audit Committee of the Board is responsible for oversight of risk management related to cybersecurity, policies and procedures related to the protection of Company proprietary and customer information, and compliance with data privacy requirements.
+Added: It receives quarterly updates from our CIO on trends, threats, and technologies used to prevent, detect and respond to risks;
+Added: reviews and provides feedback on employee education initiatives, crisis response strategies, and remediation measures;
+Added: and reports to the Board on fulfillment of its cybersecurity risk management oversight.
+Added: We strive to align with the National Institute of Standards and Technology (NIST) cybersecurity maturity framework and leverage a range of tools, including artificial intelligence, software programs, logs, and data analyses, to detect anomalous activity and identify risks across our systems.
+Added: Threat simulations, such as penetration testing, are conducted periodically to assess vulnerabilities, analyze results, and implement remediations.
+Added: Additionally, we employ third-party services for monitoring risks posed by cyber-attackers, employees, and third-party vendors accessing or contributing to our systems.
+Added: Our oversight of such vendors includes requiring them to undergo cybersecurity analyses through risk assessments, scorecards, and audits.
+Added: Depending on the services performed, we require certain vendor agreements to contain security and privacy addenda and require vendors to report to us cybersecurity breaches on their systems and/or impacts to our data.
+Added: We place high importance on conducting tabletop exercises to test and enhance our readiness for cybersecurity incidents.
+Added: These exercises involve our Crisis Management Team, which includes representatives from executive management, legal, information technology, finance, operations, and marketing.
+Added: The Crisis Management Team focuses on analyzing the scope, impact, and root cause of simulated incidents, while the marketing and legal departments, along with a team of executives, plan the messaging to customers, employees and other stakeholders deemed necessary or advisable in the circumstances.
+Added: For compliance readiness, we monitor the legal and regulatory landscape associated with cybersecurity incidents.
+Added: These exercises and activities provide valuable insights to improve transparency, messaging, response protocols, stakeholder confidence and organizational resilience in the event of a cyber crisis.
+Added: To manage material risks and enhance preparedness, we maintain a cyber insurance program integrated into our overall risk management framework.
+Added: During insurance renewals, we collaborate with brokers and cyber experts to assess our program and align coverages with identified risks.
+Added: In the event of a cybersecurity incident, our crisis management plan is triggered, mobilizing the Crisis Management Team to assess the situation and oversee critical decisions related to abatement, mitigation, and response.
+Added: Responsive steps, each as deemed necessary or advisable and in addition to other elements of the plan, include engaging third-party forensic and other experts, coordinating communications with stakeholders, contacting law enforcement, and reporting incidents to the Board or Audit Committee.
+Added: In a post-incident review, lessons learned are analyzed for incorporation into future protocols.
+Added: We foster a culture of cybersecurity awareness through regular phishing simulations, enterprise-wide security training, employee education on safe technology practices, and information security policies.
+Added: We continue to evaluate cybersecurity risks and enhance our strategy to safeguard our operations and data as part of our commitment to operational resilience and innovation.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.