1.
We note that none of your risk factors, or other sections of your Form 10-K, specifically address any risks you may face from cyber attacks, such as attempts by third parties to gain access to your systems to compromise sensitive business information, to interrupt your systems or otherwise try to cause harm to your business and operations. In future filings, beginning with your next Form 10-Q, please provide risk factor disclosure describing the cybersecurity risks that you face or tell us why you believe such disclosure is unnecessary. If you have experienced any cyber attacks in the past, please state that fact in any additional risk factor disclosure in order to provide the proper context. Please refer to the Division of Corporation Finance's Disclosure Guidance Topic No. 2 at http://www.sec.gov/ divisions/corpfin/guidance/cfguidance-topic2.htm for additional information.
•
In response to the Staff's comment, as requested, beginning with Valero's Form 10-Q for the quarter ended June 30, 2012, we agree to provide risk factor disclosure describing the cybersecurity risks that Valero faces. Our risk factor disclosure will follow the guidance set forth in the Division of Corporation Finance's Disclosure Guidance Topic No. 2.
•
Valero is responsible for the adequacy and accuracy of the disclosure in the filing;
•
Staff comments or changes to disclosure in response to Staff comments do not foreclose the Commission from taking any action with respect to the filing; and
•
Valero may not assert Staff comments as a defense in any proceeding initiated by the Commission or any person under the federal securities laws of the United States.
Very truly yours,
/s/ Michael S. Ciskowski
Michael S. Ciskowski
Executive Vice President and
Chief Financial Officer
cc:
Clayton E. Killinger, Senior Vice President and Controller