A Dark Vector Cognition product

Item 1C. Cybersecurity

5K characters. Original on sec.gov · Markdown

Item 1C. Cybersecurity

Technology Risk and Controls Committee (TRCC): The TRCC is used as a platform to assess risk and controls components across the information technology (IT) landscape including cybersecurity. It manages the risk assessment process, escalation and implementation of risk acceptance thresholds with the help of the GRC.

Regional, Country Risk and IT Risk Committees

  • Asia Pacific (APAC) Technology Risk and Controls (TRC) Forum

  • APAC - TRC Zone / Country Monthly Forums

  • Japan IT Risk Committee

  • Europe, Middle East and Africa region/UK and Latin America and Caribbean TRC Forum

The above forums are set up for regional focus on IT, cybersecurity, regulations and overall issue management. The forums engage with the Company's relevant IT leaders and functional leaders within Enterprise Risk Management, Legal, Compliance, and Internal Audit.

Each of the Board and regional and country leadership boards may receive periodic presentations and reports on cybersecurity risks. In the event of a material cybersecurity incident, the Board will receive prompt information and ongoing updates about the incident. The Company has an established issue escalation protocol for technology incidents, including cyber related incidents. The Company’s technology incidents and risks are tracked and rated. Items that are rated as "critical" are discussed in the TRCC, and escalated to the GRC as appropriate. At least once each year, the Board discusses the Company’s approach to cybersecurity risk management with the Company’s Global Chief Information Security Officer. The CISO and regional/country information security officers regularly present to the Company’s regional and country leadership boards on material cyber risks and the Company’s information security posture and strategy.

The CISO works collaboratively with business and functional colleagues to implement a program designed to protect the Company’s information system from cybersecurity threats and promptly respond to potential cybersecurity incidents. Multidisciplinary teams are deployed to respond to cybersecurity incidents in accordance with the Company’s incident response plans. Through ongoing communication from these teams, the CISO monitors the prevention, detection, mitigation and remediation of cybersecurity incidents in real time, and reports such incidents to the Board when appropriate.

The CISO reports to the CIO and is principally responsible for overseeing the Program, in partnership with other business leaders across the Company including regional information security and technology officers. The Company’s cybersecurity personnel maintain current knowledge through specific training programs, professional certifications, and participation in industry groups (e.g., Financial Services Sector Coordinating Council, Financial Services Information Sharing and Analysis Center, Analysis and Resilience Center, Securities Industry and Financial Markets Association, Cybersecurity and Infrastructure Security Agency, etc.). Company cybersecurity personnel expand and test their knowledge of cyber threats and countermeasures through additional on-the-job training and quarterly sponsored simulated exercises to practice their response to real-life threats. In addition, personnel are encouraged to obtain industry approved certifications as appropriate for their roles and responsibilities. Below are some examples of certifications held by the Company’s cybersecurity personnel: Certified in the Governance of Enterprise IT, Certified Information Systems Security Professional, Certified Information Security Manager, Certified Risk Information Systems Control, Global Information Assurance Certification (GIAC) Certified Incident Handler, GIAC Assessing and Auditing Wireless Networks, and GIAC Continuous Monitoring Certification.

Our CISO has more than 30 years’ leadership experience in the field of information technology, cybersecurity, and adjacent roles spanning both military, corporate, and advisory roles. He maintains multiple professional certifications and has completed various academic and professional training courses, including the Federal Bureau of Investigation CISO Academy. In addition, he continues to serve on cybersecurity advisory councils and on the faculty of educational institutions focused on network security and information technology.

There have been no material cybersecurity incidents that have affected AIG for the period covered by this annual report. For a discussion regarding risks associated with cybersecurity threats, see Part I, Item 1A. Risk Factors – Business and Operations – "Our risk management policies, standards and procedures may prove to be ineffective and leave us exposed to unidentified or unanticipated risk, which could adversely affect our businesses, results of operations, financial condition and liquidity" and “We are exposed to certain risks if we are unable to maintain the availability of our critical technology systems and data and safeguard the confidentiality and integrity of our data, which could compromise our ability to conduct business and adversely affect our consolidated business, results of operations, financial condition and liquidity.”

AIG | 2023 Form 10-K39

ITEM 2 | Properties

Previous: Item 1B. Unresolved Staff Comments · Next: Item 2. Properties