11 unchanged sentences
We also have processes to oversee and identify material cybersecurity risks associated with our use of third-party service providers and their information systems.
−Removed: As part of these processes, we conduct cybersecurity due diligence around significant third-party service providers who access our information technology systems before their engagement.
−Removed: We require third-party service providers to promptly notify us of any actual or suspected breach impacting our data or operations.
−Removed: Additionally, we obtain Type 1 and Type 2 System and Organization Controls (“SOC”) 2 reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk associated with our relationship with the host vendor.
+Added: As part of these processes, we conduct cybersecurity due diligence around significant third-party service providers who access our information technology systems before and/or during their engagement.
+Added: We require third-party service providers to promptly notify us of any actual breach impacting our data or operations.
+Added: Additionally, we seek to obtain System and Organization Controls (“SOC”) 2 reports on an annual basis from vendors that host our significant financial applications to aid in our assessment of information security risk associated with our relationship with the host vendor.
If a host vendor is not able to provide a SOC 2 report, we take additional steps to assess information security risk associated with the relationship.
1 unchanged sentence
Whilst some of those franchisees do operate their restaurants utilizing the Company’s networks and systems, many use networks and systems which they manage themselves.
−Removed: In such instances, there is limited direct connectivity between the networks that the Company manages and the networks which our franchisees manage.
−Removed: We have established minimum information security standards for our franchisees through our Franchise Agreement Policy Manuals and Brand Standards and those minimum information security standards are in the process of being adopted.
+Added: There is limited direct connectivity between the networks that the Company manages and the networks which our franchisees manage.
+Added: We have established minimum information security standards for our franchisees through our Franchise Agreement Policy Manuals and Brand Standards.
+Added: Those minimum information security standards are reviewed and updated on a regular basis and franchisees are given time to adjust and comply with changes as they occur.
Despite the security measures implemented as part of our Program, the current cyber threat environment presents increased risks for all companies, and we are a frequent target of cyber-attacks and have experienced security incidents.
2 unchanged sentences
In addition, although data was taken from our network, the affected data was limited to certain personal information of former and current employees, and we have no evidence that customer databases were accessed.
−Removed: We have incurred, and may continue to incur, certain expenses related to this attack, including expenses to respond to, remediate and investigate this matter.
−Removed: In addition, several separate putative class actions have been filed in U.S.
+Added: Several separate putative class actions have been filed in U.S.
federal and state court by current and/or former employees alleging violations of privacy and other rights in connection with the ransomware incident.
+Added: As a result, we have incurred and may continue to incur expenses relating to this litigation.
We do not believe that any risks we have identified to date from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition.
4 unchanged sentences
The Audit Committee oversees the Company’s business and financial technology risk exposure, which includes data privacy and data protection, information security and cybersecurity, as well as the controls in place to monitor and mitigate these risks.
+Added: Our CISO and Chief Digital and Technology Officer advise the Audit Committee at least four times a year, and the Board of Directors regularly, on our management and oversight of information security risks and data protection risks.
+Added: The Audit Committee also receives periodic updates on data privacy from members of management within our data privacy group in addition to the regular updates from our CISO.
+Added: The Audit Committee provides a summary to the full Board at each regular Board meeting of the information security risk review together with any other risk related subjects discussed at the Audit Committee meeting.
At a management level, our Program is led by our CISO, who reports to the Company’s Chief Digital and Technology Officer.
6 unchanged sentences
The Plan provides that any cybersecurity incident that is elevated for the review of the Response Team will also be reviewed by this group to determine whether any such incident is material for securities laws purposes and whether public disclosure is required or advisable in connection therewith, following any necessary consultation with the Company’s senior management, Disclosure Committee, Audit Committee and/or Board of Directors.
−Removed: Our CISO and Chief Digital and Technology Officer advise the Audit Committee at least four times a year, and the Board of Directors regularly, on our management and oversight of information security risks and data protection risks.
−Removed: The Audit Committee also receives periodic updates on data privacy from members of management within our data privacy group in addition to the regular updates from our CISO.
−Removed: The Audit Committee provides a summary to the full Board at each regular Board meeting of the information security risk review together with any other risk related subjects discussed at the Audit Committee meeting.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.