5 unchanged sentences
The underlying controls of the cyber risk management program are based on recognized leading practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and the International Organization for Standardization (ISO) 27001 Information Security Management System Requirements.
+Added: Xerox 2024 Annual Report 24
+Added: Table of Contents Legal Sign-off 2.24.25
The risk management program is primarily focused on safeguarding the organization's digital assets, ensuring continuous business operations, and minimizing the potential impact of cyber threats.
6 unchanged sentences
In addition to the normal discourse on emerging risks, a focused drill down into cybersecurity risk is presented annually at the enterprise risk steering committee meeting.
−Removed: The outcomes of these discussions are submitted quarterly to the Audit Committee of the Board of Directors.
All employees and contractors play an important role in protecting the organization from cyber threats.
3 unchanged sentences
Our incident response process outlines actions required to triage, analyze, contain, remediate, and safely recover from cybersecurity incidents.
+Added: Our incident response program ensures management is informed and involved in monitoring and addressing security and privacy incidents.
+Added: The program uses a coordinated escalation model to engage relevant management and Board members as needed.
+Added: It includes regular training and simulations for preparedness, with periodic updates to the Board on the program’s status and significant incidents, ensuring robust oversight and governance.
Security incidents are evaluated to determine materiality as well as operational and business impacts and are reviewed for privacy impacts.
6 unchanged sentences
To date, no cybersecurity incident has resulted in any material impact on our business, operations or financial results or our ability to service our customers or run our business.
+Added: We maintain insurance coverage designed to mitigate our exposure to network security and privacy matters.
Refer to Item 1A Risk Factors for additional discussion of risks associated with cybersecurity threats to the Company.
−Removed: Xerox 2023 Annual Report 23
Xerox Holdings' Cybersecurity organization is a global organization and is dedicated to protecting its infrastructure, information, and digital assets.
−Removed: It is responsible for establishing appropriate security policies, safeguards and controls to prevent, detect and respond to cyber threats, meet regulatory and compliance requirements, securing Xerox Holdings' intellectual property, products and services, and supply chain in collaboration with business, product, and IT partners.
−Removed: The information security organization is led by the Chief Information Security Officer (CISO) who reports to the Chief Transformation and Administrative Officer.
−Removed: In his over 18-year career as a Cybersecurity professional, the CISO has served in various roles with Fortune 500 companies, including as Deputy CISO, Head of Cyber Defense & Security Architecture, Distinguished Technologist Security, and Specialist Master.
−Removed: The CISO holds a bachelor’s degree in Electrical and Electronics Engineering, is a Certified Information Systems Security Professional (CISSP), and has extensive experience in multiple security domains, including security operations, security architecture, identity and access management, cloud security, vulnerability management, and application/product security, policy, and compliance.
+Added: It is responsible for establishing appropriate security policies, safeguards and controls to prevent, detect and respond to cyber threats, meet regulatory and compliance requirements, secure Xerox Holdings' intellectual property, products and services, and supply chain in collaboration with business, product, and IT partners.
+Added: The information security organization is led by the Chief Information Security Officer (CISO) who reports to the Chief Administrative Officer and Global Head of Operations.
+Added: With more than twenty years of experience in security, the CISO began his security career serving in the United States Marine Corps (USMC), leading physical security and executive protection for Marine One.
+Added: He subsequently led cybersecurity programs for U.S.
+Added: Cyber Command and the Pentagon, advised Fortune 500 clients on cybersecurity and crisis response matters as an Advisory Director at PwC, and has held positions as CISO or Deputy CISO for public and private companies.
+Added: The CISO is currently pursuing a Master of Business Administration (MBA), and is a Certified Information Systems
+Added: Xerox 2024 Annual Report 25
+Added: Table of Contents Legal Sign-off 2.24.25
+Added: Security Professional (CISSP) and Certified Information Security Manager (CISM).
+Added: He has extensive experience in multiple security domains, including security operations, incident detection and response, security architecture, identity and access management, cloud security, vulnerability and threat management, application/product security, policy, and compliance.
The Audit Committee of the Board of Directors provides governance and oversight of the cybersecurity program and approves the information security program annually.
Regular updates are presented to the Audit Committee by the CISO on the current state of the cybersecurity program, providing transparency including progress on initiatives, operational and compliance metrics, risks, cybersecurity and data privacy incidents (if any), and appropriate remediation actions.
+Added: The outcomes of these cross-functional risk discussions noted above, are submitted quarterly to the Audit Committee of the Board of Directors.
The Board of Directors also considers cybersecurity topics on an ad hoc basis where appropriate, including for purposes of receiving briefings on developments in cybersecurity or cybersecurity incidents and assessing and managing potentially material risks arising from cybersecurity threats.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.