3 unchanged sentences
Xerox Holdings maintains a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
−Removed: This program is integrated within the Company’s enterprise risk management system and addresses both the corporate information technology environment and customer-facing products and services.
+Added: This program is integrated within the Company’s enterprise risk management program and addresses both the corporate information technology environment and customer-facing products and services.
The underlying controls of the cyber risk management program are based on recognized leading practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and the International Organization for Standardization (ISO) 27001 Information Security Management System Requirements.
−Removed: Xerox 2024 Annual Report 24
−Removed: Table of Contents Legal Sign-off 2.24.25
−Removed: The risk management program is primarily focused on safeguarding the organization's digital assets, ensuring continuous business operations, and minimizing the potential impact of cyber threats.
+Added: The Company's risk management program is primarily focused on safeguarding the organization's digital assets, ensuring continuous business operations, and minimizing the potential impact of cyber threats on the confidentiality, availability, and integrity of our systems and data.
The structured risk management process is designed to comprehensively identify and assess risks, implement effective mitigation and remediation strategies, enhance overall cybersecurity resilience, and provide transparent reporting.
4 unchanged sentences
A formal process exists grounded in the enterprise risk management program where material risks, interdependencies, and the associated remediation plans that are tracked to completion at a minimum on a monthly basis are presented and discussed cross-functionally.
−Removed: In addition to the normal discourse on emerging risks, a focused drill down into cybersecurity risk is presented annually at the enterprise risk steering committee meeting.
+Added: In addition to the normal discourse on emerging risks, a focused drill down into cybersecurity risk is presented at least annually at the enterprise risk steering committee meeting.
All employees and contractors play an important role in protecting the organization from cyber threats.
10 unchanged sentences
A thorough due diligence process is conducted on all prospective third parties to evaluate their overall security posture and alignment with Xerox Holdings' organizational standards.
−Removed: Additionally, ongoing assessments are regularly conducted on selected existing vendors and partners to confirm their continuous compliance with Xerox Holdings' cybersecurity standards and policies.
+Added: Additionally, ongoing assessments are regularly conducted on selected existing vendors and partners to confirm their continuous compliance with Xerox Holdings' cybersecurity and data privacy standards and policies.
Where applicable, we also include security and data privacy addendums in our third-party contracts.
−Removed: Xerox Holdings also engages with external managed security service providers to support certain day-to-day operational activities in addition to in-house cybersecurity staff as part of the cybersecurity program.
+Added: Xerox Holdings also
+Added: Xerox 2025 Annual Report 27
+Added: Table of Conten t s
+Added: engages with external managed security service providers to support certain day-to-day operational activities in addition to in-house cybersecurity staff as part of the cybersecurity program.
To date, no cybersecurity incident has resulted in any material impact on our business, operations or financial results or our ability to service our customers or run our business.
3 unchanged sentences
It is responsible for establishing appropriate security policies, safeguards and controls to prevent, detect and respond to cyber threats, meet regulatory and compliance requirements, secure Xerox Holdings' intellectual property, products and services, and supply chain in collaboration with business, product, and IT partners.
−Removed: The information security organization is led by the Chief Information Security Officer (CISO) who reports to the Chief Administrative Officer and Global Head of Operations.
+Added: The information security organization is led by the Chief Information Security Officer (CISO) who reports to the President and Chief Operating Officer (COO).
With more than twenty years of experience in security, the CISO began his security career serving in the United States Marine Corps (USMC), leading physical security and executive protection for Marine One.
1 unchanged sentence
Cyber Command and the Pentagon, advised Fortune 500 clients on cybersecurity and crisis response matters as an Advisory Director at PwC, and has held positions as CISO or Deputy CISO for public and private companies.
−Removed: The CISO is currently pursuing a Master of Business Administration (MBA), and is a Certified Information Systems
−Removed: Xerox 2024 Annual Report 25
−Removed: Table of Contents Legal Sign-off 2.24.25
−Removed: Security Professional (CISSP) and Certified Information Security Manager (CISM).
+Added: The CISO has a Master of Business Administration (MBA), and is a Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM).
He has extensive experience in multiple security domains, including security operations, incident detection and response, security architecture, identity and access management, cloud security, vulnerability and threat management, application/product security, policy, and compliance.
The Audit Committee of the Board of Directors provides governance and oversight of the cybersecurity program and approves the information security program annually.
−Removed: Regular updates are presented to the Audit Committee by the CISO on the current state of the cybersecurity program, providing transparency including progress on initiatives, operational and compliance metrics, risks, cybersecurity and data privacy incidents (if any), and appropriate remediation actions.
+Added: Regular updates are presented to the Audit Committee by the CISO on the current state of the cybersecurity program, providing transparency concerning progress on initiatives, operational and compliance metrics, risks, cybersecurity and data privacy incidents (if any), and appropriate remediation actions.
The outcomes of these cross-functional risk discussions noted above are submitted quarterly to the Audit Committee of the Board of Directors.
1 unchanged sentence
There are two committees comprised of Company leadership, including the enterprise risk management steering committee, which meets monthly, and the Xerox Holdings management audit committee, which meets at least quarterly, to discuss the current operational and security compliance metrics, cybersecurity incidents, and risks.
+Added: Xerox 2025 Annual Report 28
+Added: Table of Conten t s
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.