high match confidence
Sentence-level differences:
- Reworded sentence: "Information security risks for payments and technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, “hacktivists”, terrorists, nation-states, state-sponsored actors and other external parties."
- Reworded sentence: "In addition, to access our products and services, our customers and account holders increasingly use personal smartphones, tablet PCs and other mobile devices that may be beyond our control."
- Reworded sentence: "Geopolitical events and resulting government activity could also lead to information security threats and attacks by affected or sympathizing jurisdictions or other actors, which could put our information and assets at risk, as well as result in network disruption."
- Reworded sentence: "However, future attacks or breaches could lead to security breaches of the networks, systems (including third-party provider systems) or devices that our customers use to access our products and services, which in turn could result in the unauthorized disclosure, release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary, sensitive and personal information (including account data information) or data security compromises."
- Reworded sentence: "If such attacks are not detected immediately, or disclosed as required by law, their effect could be compounded."
Current (2024):
Information security risks for payments and technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and…
Read full text
Information security risks for payments and technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, “hacktivists”, terrorists, nation-states, state-sponsored actors and other external parties. These threats may derive from fraud or malice on the part of our employees or third parties, or may result from human error, software bugs, server malfunctions, software or hardware failure or other technological failure. These threats include cyber-attacks such as computer viruses, denial-of-service attacks, malicious code (including ransomware), social-engineering attacks (including phishing attacks) or information security breaches and could lead to the misappropriation or loss of consumer account and other information and identity theft. These types of threats have risen significantly due to a significant portion of our workforce working in a hybrid environment. These threats also may be further enhanced in frequency or effectiveness through threat actors’ use of AI. Our operations rely on the secure transmission, storage and other processing of confidential, proprietary, sensitive and personal information and technology in our computer systems and networks, as well as the systems of our third-party providers. Our customers and other parties in the payments value chain, as well as account holders, rely on our digital technologies, computer systems, software and networks to conduct their operations. In addition, to access our products and services, our customers and account holders increasingly use personal smartphones, tablet PCs and other mobile devices that may be beyond our control. We, like other financial technology organizations, routinely are subject to cyber-threats and our technologies, systems and networks, as well as the systems of our third-party providers, have been subject to attempted cyber-attacks. Because of our position in the payments value chain, we believe that we are likely to continue to be a target of such threats and attacks. Geopolitical events and resulting government activity could also lead to information security threats and attacks by affected or sympathizing jurisdictions or other actors, which could put our information and assets at risk, as well as result in network disruption. To date, we have not experienced any material impact relating to cyber-attacks or other information security breaches. However, future attacks or breaches could lead to security breaches of the networks, systems (including third-party provider systems) or devices that our customers use to access our products and services, which in turn could result in the unauthorized disclosure, release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary, sensitive and personal information (including account data information) or data security compromises. Such attacks or breaches could also cause service interruptions, malfunctions or other failures in the physical infrastructure, networks or operations systems that support our business and customers (such as the lack of availability of our value-added services), as well as the operations of our customers or other third parties. In addition, they could lead to damage to our reputation with our customers, other stakeholders and the broader payments ecosystem, additional costs to us (such as repairing systems, adding new personnel or protection technologies or compliance costs), regulatory penalties, financial losses to both us and our customers and partners and the loss of customers and business opportunities. These consequences could be further pronounced in jurisdictions in which we are deemed critical national infrastructure. If such attacks are not detected immediately, or disclosed as required by law, their effect could be compounded. 34 MASTERCARD 2023 FORM 10-K 34 MASTERCARD 2023 FORM 10-K 34 MASTERCARD 2023 FORM 10-K PART IITEM 1A. RISK FACTORS PART I ITEM 1A. RISK FACTORS In addition to information security risks for our systems and networks, we also routinely encounter account data compromise events involving merchants and third-party payment processors that process, store or transmit payment transaction data, which affect millions of Mastercard, Visa, Discover, American Express and other types of account holders. Further events of this type may subject us to reputational damage and/or lawsuits involving payment products carrying our brands. Damage to our reputation or that of our brands resulting from an account data breach of either our systems and networks or the systems and networks of our customers, merchants and other third parties could decrease the use and acceptance of our products and services. Such events could also slow or reverse the trend toward electronic payments. In addition to reputational concerns, the cumulative impact of multiple account data compromise events could increase the impact of the fraud resulting from such events by, among other things, making it more difficult to identify consumers. Moreover, while most of the lawsuits resulting from account data breaches do not involve direct claims against us and while we have releases from many issuers and acquirers, we could still face damage claims, which, if upheld, could materially and adversely affect our results of operations. While we offer cyber and intelligence products that are designed to prevent, detect and respond to fraud and cyber-attacks, there can be no assurance that such security solutions will perform as expected or address all possible security threats. Real or perceived defects, failures, errors or vulnerabilities in our security solutions, such as our cyber and intelligence products, could adversely impact our reputation, customer confidence in our solutions and our business and may subject us to litigation, governmental audits and investigation or other liabilities. Such events could have a material adverse impact on our transaction volumes, results of operations and prospects for future growth, or increase our costs by leading to additional regulatory burdens being imposed on us. In addition, fraudulent activity and increasing cyber-attacks have encouraged legislative and regulatory intervention, and could damage our reputation and reduce the use and acceptance of our products and services or increase our compliance costs. Criminals are using increasingly sophisticated methods to capture consumer personal information to engage in illegal activities such as counterfeiting or other fraud and may see their effectiveness enhanced by the use of AI. As outsourcing and specialization become common in the payments industry, there are more third parties involved in processing transactions using our payment products. While we are continuing to take measures to make card and digital payments more secure, increased fraud levels involving our products and services, or misconduct or negligence by third parties switching or otherwise servicing our products and services, could lead to legislative or regulatory intervention, such as enhanced security requirements and liabilities, as well as damage to our reputation. See “Risk Factors - Privacy, Data Protection, AI and Information Security Compliance” in this Part I, Item 1A for more detail concerning related legal risks and obligations. Despite various mitigation efforts that we undertake, there can be no assurance that we will not suffer material breaches and resulting losses in the future. While we maintain insurance coverage, such coverage may not be adequate to protect us from such losses as well as any liabilities or damages with respect to claims alleging compromises of our confidential, proprietary, sensitive or personal information or our technologies, systems or networks. In addition, we cannot be sure that our existing insurance coverage will continue to be available on acceptable terms or at all, or that our insurers will not deny coverage as to any future claim. Our risk and exposure to these matters remain heightened due to, among other things, the evolving nature of these threats, our prominent role in the global payments ecosystem, our continued implementation of our strategic priorities, our extensive use of third-party vendors and potential vulnerabilities from previous and future acquisitions, strategic investments or related opportunities. As a result, information security and the continued development and enhancement of our controls, processes and practices designed to protect our computer systems, software, data and networks from attack, damage or unauthorized access remain a priority for us. As cyber-threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities. Any of the risks described above could materially adversely affect our overall business and results of operations.
View prior text (2023)
Information security risks for payments and technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists and other external parties. These threats may derive from fraud or malice on the part of our employees or third parties, or may result from human error or accidental technological failure. These threats include cyber-attacks such as computer viruses, malicious code (including ransomware), phishing attacks or information security breaches and could lead to the misappropriation of consumer account and other information and identity theft. These types of threats have risen significantly due to a significant portion of our workforce working in a remote or hybrid environment. Our operations rely on the secure processing, transmission and storage of confidential, proprietary and other information and technology in our computer systems and networks, as well as the systems of our third-party providers. Our customers and other parties in the payments value chain, as well as account holders, rely on our digital technologies, computer systems, software and networks to conduct their operations. In addition, to access our integrated products and services, our customers and account holders increasingly use personal smartphones, tablet PCs and other mobile devices that may be beyond our control. We, like other financial technology organizations, routinely are subject to cyber-threats and our technologies, systems and networks, as well as the systems of our third-party providers, have been subject to attempted cyber-attacks. Because of our position in the payments value chain, we believe that we are likely to continue to be a target of such threats and attacks. In response to U.S. and European sanctions against Russia earlier this year, we saw increased information security threats from state sponsored actors. Other geopolitical events and resulting government activity could also lead to information security threats and attacks by affected or sympathizing jurisdictions or other actors, which could put our information and assets at risk, as well as result in network disruption. To date, we have not experienced any material impact relating to cyber-attacks or other information security breaches. However, future attacks or breaches could lead to security breaches of the networks, systems (including third-party provider systems) or devices that our customers use to access our integrated products and services, which in turn could result in the unauthorized disclosure, release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary and other information (including account data information) or data security compromises. Such attacks or breaches could also cause service interruptions, malfunctions or other failures in the physical infrastructure or operations systems that support our businesses and customers (such as the lack of availability of our value-added services), as well as the operations of our customers or other third parties. In addition, they could lead to damage to our reputation with our customers, other stakeholders and the broader payments ecosystem, additional costs to us (such as repairing systems, adding new personnel or protection technologies or compliance costs), regulatory penalties, financial losses to both us and our customers and partners and the loss of customers and business opportunities. These consequences could be further pronounced in jurisdictions in which we are deemed critical national infrastructure. If such attacks are not detected immediately, their effect could be compounded. Despite various mitigation efforts that we undertake, there can be no assurance that we will be immune to these risks and not suffer material breaches and resulting losses in the future, or that our insurance coverage would be sufficient to cover all losses. Our risk and exposure to these matters remain heightened because of, among other things, the evolving nature of these threats, our prominent size and scale and our role in the global payments and technology industries, our plans to continue to implement our digital and mobile channel strategies and develop additional remote connectivity solutions to serve our customers and account holders when and how they want to be served, our global presence, our extensive use of third-party vendors and future joint venture and merger and acquisition opportunities. As a result, information security and the continued development and enhancement of our controls, processes and practices designed to protect our systems, computers, software, data and networks from attack, damage or unauthorized access remain a priority for us. As cyber-threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities. Any of the risks described above could materially adversely affect our overall business and results of operations. MASTERCARD 2022 FORM 10-K 33 MASTERCARD 2022 FORM 10-K 33 MASTERCARD 2022 FORM 10-K 33 PART IITEM 1A. RISK FACTORS PART I ITEM 1A. RISK FACTORS In addition to information security risks for our systems, we also routinely encounter account data compromise events involving merchants and third-party payment processors that process, store or transmit payment transaction data, which affect millions of Mastercard, Visa, Discover, American Express and other types of account holders. Further events of this type may subject us to reputational damage and/or lawsuits involving payment products carrying our brands. Damage to our reputation or that of our brands resulting from an account data breach of either our systems or the systems of our customers, merchants and other third parties could decrease the use and acceptance of our integrated products and services. Such events could also slow or reverse the trend toward electronic payments. In addition to reputational concerns, the cumulative impact of multiple account data compromise events could increase the impact of the fraud resulting from such events by, among other things, making it more difficult to identify consumers. Moreover, while most of the lawsuits resulting from account data breaches do not involve direct claims against us and while we have releases from many issuers and acquirers, we could still face damage claims, which, if upheld, could materially and adversely affect our results of operations. Such events could have a material adverse impact on our transaction volumes, results of operations and prospects for future growth, or increase our costs by leading to additional regulatory burdens being imposed on us.