STAFF COMMENTS
+Added: CYBERSECURITY
+Added: We rely extensively on
+Added: various information systems and other electronic resources to operate our business.
+Added: nearly all of our customers, service providers and other business partners on whom
+Added: we depend, including the providers of
+Added: our online banking, mobile banking and accounting systems, use their own electronic information
+Added: systems can be compromised, including by employees, customers and other individuals
+Added: who are authorized to use them,
+Added: and bad actors using sophisticated and a constantly evolving set of software, tools
+Added: and strategies to do so.
+Added: The threats are
+Added: domestic and international and range from small to large, including state
+Added: sponsored, terrorist and criminal organizations
+Added: with substantial funds, and technical and other resources
+Added: As a bank, we and our vendors, service providers and customers may be attractive targets,
+Added: and we confront continuous
+Added: cybersecurity threats.
+Added: Insurance to fully cover these risks is unavailable in sufficient
+Added: amounts at reasonable costs.
+Added: believe the more effective approach is taking active measures to
+Added: detect, deter and reduce cybersecurity threats, and be
+Added: prepared to address and remediate any breaches and prevent similar breaches in the
+Added: See “Risks Related to
+Added: Information Security and Business Interruption” section of the Risk Factors included
+Added: in Item 1A of this Form 10-K for
+Added: Accordingly, we have devoted
+Added: significant resources to assessing, identifying and managing risks associated
+Added: cybersecurity threats, including:
+Added: Implementing an Information Security Program that establishes policies and
+Added: procedures for security
+Added: operations and governance;
+Added: Establishing an IT Steering Committee of the Board that is responsible for security administration,
+Added: conducting regular assessments of our information systems, existing controls, vulnerabilities
+Added: and potential
+Added: improvements;
+Added: Implementing layers of controls and not allowing excessive reliance on any single control;
+Added: Employing a variety of preventative and detective tools designed to monitor,
+Added: block and provide alerts
+Added: regarding suspicious activity;
+Added: Continuously evaluating tools that can detect and help respond to cybersecurity threats
+Added: in real-time;
+Added: Leveraging people, processes and technology to manage and maintain cybersecurity controls;
+Added: Maintaining a vendor management program with periodic review processes, and
+Added: a third-party risk
+Added: management program designed to identify, assess and manage risks associated
+Added: with external service providers;
+Added: Monitoring our systems and related software and programming periodically to update
+Added: programing, including updating data protection elements,
+Added: and requiring that our service providers also engage
+Added: in similar programs that are reasonably designed to deter cybersecurity breaches;
+Added: Performing initial and ongoing due diligence with respect to our third-party service
+Added: providers, including their
+Added: cybersecurity practices and safeguards, and service levels based on the risk they pose to the Bank;
+Added: Engaging third-party cybersecurity consultants, who conduct periodic
+Added: penetration testing, vulnerability
+Added: assessments and other procedures to identify potential weaknesses in our systems and
+Added: Conducting periodic cybersecurity training for our employees and the Company’s
+Added: board of directors.
+Added: Our Information Security Program is a key part of our overall risk management system,
+Added: which is administered by our IT
+Added: Steering Committee and evaluated by our IT Steering Committee and chief risk officer.
+Added: The program includes
+Added: administrative, technical and physical safeguards to help protect the security and confidentiality
+Added: and availability of
+Added: customer records and information.
+Added: From time-to-time, we have identified cybersecurity threats that require us to
+Added: make changes to our processes, equipment
+Added: and to implement additional safeguards.
+Added: While none of these identified threats or incidents
+Added: have materially affected us, it is
+Added: possible that threats and incidents we identify in the future could have a material adverse effect
+Added: on our business strategy,
+Added: customer service, data privacy and security,
+Added: continuity of service and reputation, and our results of operations and financial
+Added: The Company’s Chief Technology
+Added: Officer is responsible for the day-to-day management of
+Added: cybersecurity risks we face and
+Added: oversees the IT Steering Committee, which is chaired by a director of the Company’s
+Added: The IT Steering Committee
+Added: oversees the information security assessment, development of policies, standards
+Added: and procedures, testing, training and
+Added: security report processes.
+Added: The IT Steering Committee is comprised of directors and officers
+Added: with the appropriate expertise
+Added: and authority to oversee the Information Security Program.
+Added: Our Chief Technology Officer,
+Added: along with the information technology department, is accountable for managing our
+Added: enterprise information security and delivering our information security program.
+Added: department, as a whole, consists of
+Added: information security professionals with varying degrees of education and experience.
+Added: The Chief Technology Officer
+Added: subject to professional education and certification requirements.
+Added: In particular,
+Added: our Chief Technology
+Added: Officer, who is also
+Added: designated as our Information Security Officer,
+Added: has relevant expertise in the areas of information security and cybersecurity
+Added: risk management.
+Added: In addition, the Company’s Board,
+Added: both as a whole and through its IT Steering Committee is responsible for the oversight
+Added: of risk management, including cybersecurity risks.
+Added: In that role, the Company’s
+Added: Board and the IT Steering Committee, with
+Added: support from the Company’s management and third
+Added: party cybersecurity advisors, are responsible for ensuring that the risk
+Added: management processes designed and implemented by management are adequate
+Added: and functioning as designed.
+Added: reviews and approves an information security program, vendor management policy (incl
+Added: uding third-party service
+Added: providers), acceptable use policy,
+Added: incident response policy and business continuity planning policy on an annual basis.
+Added: the aforementioned policies are developed and implemented by Company management.
+Added: To carry out their duties,
+Added: receives updates at least quarterly from the Chief Technology
+Added: Officer regarding cybersecurity risks and the Company’s
+Added: efforts to prevent, detect, mitigate and remediate any cybersecurity incidents.
DESCRIPTION OF PROPERTY
5 unchanged sentences
constructed AuburnBank Center,
−Removed: which was completed in May 2022 and held its grand opening in June 2022.
+Added: which was completed in May 2022 and had its grand opening in June 2022.
AuburnBank Center has approximately 90,000 square feet of space.
42 unchanged sentences
In November 2002, the Bank opened a loan production office
−Removed: in Phenix City, Alabama, about 35
−Removed: miles south of Auburn,
−Removed: In November 2022, the Bank renewed its lease for another year.
+Added: in a leased space in Phenix City,
+Added: Alabama, about 35 miles
+Added: south of Auburn, Alabama.
+Added: In November 2022, the Bank renewed its lease for another
In February 2009, the Bank opened a branch located on Bent Creek Road in Auburn,
18 unchanged sentences
originally opened in September 2004.
−Removed: In February 2015, the Bank relocated its Auburn Kroger branch to a new location within the
−Removed: Corner Village Shopping
+Added: In February 2015, the Bank relocated its Auburn Kroger branch to a new location
+Added: within the Corner Village Shopping
Center, in Auburn, Alabama.
6 unchanged sentences
Prior to relocation, the Bank’s
−Removed: Kroger branch was located in the Kroger supermarket in the same shopping
−Removed: center since August 1988.
+Added: Kroger branch was located in the Kroger supermarket in the same shopping center
+Added: since August 1988.
The current Corner
1 unchanged sentence
full line of the Bank’s deposit and other services including
−Removed: except safe deposit boxes.
+Added: but does not maintain safe
+Added: deposit boxes.
In September 2015, the Bank relocated its Auburn Wal
26 unchanged sentences
In addition to the eight ATMs
−Removed: at various branch locations, mentioned above, the Bank also has five
+Added: at various branch locations, mentioned above, the Bank also has four
various locations within our primary service area.
4 unchanged sentences
newly developed AuburnBank Center in June 2022.
−Removed: The Company has entered into a sublease agreement with a tenant for
−Removed: three years with an option to renew for three additional years.
+Added: The Company entered into a three year sublease agreement, during
+Added: 2022, with a tenant, which has an option to renew that lease for three additional years.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.