10 unchanged sentences
• Review and assess the Program and its maturity
−Removed: • Advise our Board of Directors and management regarding the structure and oversight of the program, incident response services and various cybersecurity related matters
We also have processes to oversee and identify material cybersecurity risks associated with our use of third-party service providers and their information systems.
1 unchanged sentence
We require third-party service providers to promptly notify us of any actual or suspected breach impacting our data or operations.
−Removed: Additionally, we obtain System and Organization Controls (“SOC”) 1 or SOC 2 reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk associated with our relationship with the host vendor.
−Removed: If a host vendor is not able to provide a SOC 1 or SOC 2 report, we take additional steps to assess information security risk associated with the relationship.
−Removed: Over 98% of our restaurants are owned and operated by franchisees who themselves are at risk of cyber-attacks or security incidents.
−Removed: There is limited direct connectivity between the Company’s network and the networks on which our franchisees operate.
−Removed: We have established minimum information security standards for our franchisees, which are in process of being adopted.
+Added: Additionally, we obtain Type 1 and Type 2 System and Organization Controls (“SOC”) 2 reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk associated with our relationship with the host vendor.
+Added: If a host vendor is not able to provide a SOC 2 report, we take additional steps to assess information security risk associated with the relationship.
+Added: The vast majority ( 98 %) of our restaurants are owned and operated by franchisees who themselves are at risk of cyber-attacks or security incidents.
+Added: Whilst some of those franchisees do operate their restaurants utilizing the Company’s networks and systems, many use networks and systems which they manage themselves.
+Added: In such instances, there is limited direct connectivity between the networks that the Company manages and the networks which our franchisees manage.
+Added: We have established minimum information security standards for our franchisees through our Franchise Agreement Policy Manuals and Brand Standards and those minimum information security standards are in the process of being adopted.
Despite the security measures implemented as part of our Program, the current cyber threat environment presents increased risks for all companies, and we are a frequent target of cyber-attacks and have experienced security incidents.
12 unchanged sentences
At a management level, our Program is led by our CISO, who reports to the Company’s Chief Digital and Technology Officer.
−Removed: Our CISO has expertise in cybersecurity risk management through, among other things, his past service in information security roles at the Company, prior IT and security leadership positions at other public companies, and certain technology and information security matters certifications.
+Added: Our CISO has expertise in cybersecurity risk management through, among other things, over 30 years of information security experience, prior CISO and security leadership positions at other public companies, and certain technology and information security matters certifications.
Additionally, we have a formal data privacy management committee made up of privacy professionals, operational experts and specialist legal counsel which is overseen by our Chief Legal Officer.
2 unchanged sentences
The Plan provides that the Response Team is responsible for assessing, investigating and responding to any cybersecurity event elevated for its consideration by our CISO.
−Removed: In addition, under the Plan, we have established a cross-functional management group comprised of our Chief Legal Officer, Chief Financial Officer, Vice President Internal Audit, Vice President Compliance, Senior Vice President Finance & Corporate Controller and CISO.
+Added: In addition, under the Plan, we have established a cross-functional management group comprised of our Chief Legal Officer, Chief Financial Officer, Chief Digital and Technology Officer, Vice President Internal Audit, Chief Compliance Officer, Senior Vice President Finance & Corporate Controller and CISO.
The Plan provides that any cybersecurity incident that is elevated for the review of the Response Team will also be reviewed by this group to determine whether any such incident is material for securities laws purposes and whether public disclosure is required or advisable in connection therewith, following any necessary consultation with the Company’s senior management, Disclosure Committee, Audit Committee and/or Board of Directors.
−Removed: Our CISO and Chief Digital and Technology Officer advise the Audit Committee at least four times a year, and the Board of Directors regularly, on our management and oversight of information security risks, including data privacy and data protection risks.
+Added: Our CISO and Chief Digital and Technology Officer advise the Audit Committee at least four times a year, and the Board of Directors regularly, on our management and oversight of information security risks and data protection risks.
The Audit Committee also receives periodic updates on data privacy from members of management within our data privacy group in addition to the regular updates from our CISO.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.