Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED
STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
We rely extensively on
various information systems and other electronic resources to operate our business. In addition,
nearly all of our customers, service providers and other business partners on whom
we depend, including the providers of
our online banking, mobile banking and accounting systems, use their own electronic information
systems. Any of these
systems can be compromised, including by employees, customers and other individuals
who are authorized to use them,
and bad actors using sophisticated and a constantly evolving set of software, tools
and strategies to do so.
The threats are
domestic and international and range from small to large, including state
sponsored, terrorist and criminal organizations
with substantial funds, and technical and other resources
As a bank, we and our vendors, service providers and customers may be attractive targets,
and we confront continuous
cybersecurity threats. Insurance to fully cover these risks is unavailable in sufficient
amounts at reasonable costs.
We
believe the more effective approach is taking active measures to
detect, deter and reduce cybersecurity threats, and be
prepared to address and remediate any breaches and prevent similar breaches in the
future.
See “Risks Related to
Information Security and Business Interruption” section of the Risk Factors included
in Item 1A of this Form 10-K for
additional
information.
Accordingly, we have devoted
significant resources to assessing, identifying and managing risks associated
with
cybersecurity threats, including:
•
Implementing an Information Security Program that establishes policies and
procedures for security
operations and governance;
•
Establishing an IT Steering Committee of the Board that is responsible for security administration,
including
conducting regular assessments of our information systems, existing controls, vulnerabilities
and potential
improvements;
•
Implementing layers of controls and not allowing excessive reliance on any single control;
•
Employing a variety of preventative and detective tools designed to monitor,
block and provide alerts
regarding suspicious activity;
•
Continuously evaluating tools that can detect and help respond to cybersecurity threats
in real-time;
•
Leveraging people, processes and technology to manage and maintain cybersecurity controls;
Table of Contents
49
•
Maintaining a vendor management program with periodic review processes, and
a third-party risk
management program designed to identify, assess and manage risks associated
with external service providers;
•
Monitoring our systems and related software and programming periodically to update
software and
programing, including updating data protection elements,
and requiring that our service providers also engage
in similar programs that are reasonably designed to deter cybersecurity breaches;
•
Performing initial and ongoing due diligence with respect to our third-party service
providers, including their
cybersecurity practices and safeguards, and service levels based on the risk they pose to the Bank;
•
Engaging third-party cybersecurity consultants, who conduct periodic
penetration testing, vulnerability
assessments and other procedures to identify potential weaknesses in our systems and
processes; and
•
Conducting periodic cybersecurity training for our employees and the Company’s
board of directors.
Our Information Security Program is a key part of our overall risk management system,
which is administered by our IT
Steering Committee and evaluated by our IT Steering Committee and chief risk officer.
The program includes
administrative, technical and physical safeguards to help protect the security and confidentiality
and availability of
customer records and information.
From time-to-time, we have identified cybersecurity threats that require us to
make changes to our processes, equipment
and to implement additional safeguards. While none of these identified threats or incidents
have materially affected us, it is
possible that threats and incidents we identify in the future could have a material adverse effect
on our business strategy,
customer service, data privacy and security,
continuity of service and reputation, and our results of operations and financial
condition.
The Company’s Chief Technology
Officer is responsible for the day-to-day management of
cybersecurity risks we face and
oversees the IT Steering Committee, which is chaired by a director of the Company’s
board. The IT Steering Committee
oversees the information security assessment, development of policies, standards
and procedures, testing, training and
security report processes.
The IT Steering Committee is comprised of directors and officers
with the appropriate expertise
and authority to oversee the Information Security Program.
Our Chief Technology Officer,
along with the information technology department, is accountable for managing our
enterprise information security and delivering our information security program. The
department, as a whole, consists of
information security professionals with varying degrees of education and experience.
The Chief Technology Officer
is
subject to professional education and certification requirements. In particular,
our Chief Technology
Officer, who is also
designated as our Information Security Officer,
has relevant expertise in the areas of information security and cybersecurity
risk management.
In addition, the Company’s Board,
both as a whole and through its IT Steering Committee is responsible for the oversight
of risk management, including cybersecurity risks. In that role, the Company’s
Board and the IT Steering Committee, with
support from the Company’s management and third
party cybersecurity advisors, are responsible for ensuring that the risk
management processes designed and implemented by management are adequate
and functioning as designed.
The Board
reviews and approves an information security program, vendor management policy (incl
uding third-party service
providers), acceptable use policy,
incident response policy and business continuity planning policy on an annual basis.
All
the aforementioned policies are developed and implemented by Company management.
To carry out their duties,
the Board
receives updates at least quarterly from the Chief Technology
Officer regarding cybersecurity risks and the Company’s
efforts to prevent, detect, mitigate and remediate any cybersecurity incidents.
ITEM 2. DESCRIPTION OF PROPERTY
The Bank conducts its business from its main office and seven full-service
branches.
The Bank also operates a loan
production office in Phenix City,
Alabama.
Table of Contents
50
The Bank owns its main campus in downtown Auburn, Alabama, which comprises
over 4 acres and includes the newly
constructed AuburnBank Center,
which was completed in May 2022 and had its grand opening in June 2022.
The
AuburnBank Center has approximately 90,000 square feet of space.
The AuburnBank Center includes the Bank’s
main
office, Auburn loan production office, and all of its back-office
operations.
The main office branch offers the full line of
the Bank’s services and has one
ATM.
The Bank’s drive-through facility located
on the main office campus was
constructed in October 2012.
This drive-through facility has five drive-through lanes, including an ATM,
and a walk-up
teller window.
The Bank has approximately 46,000 square feet of office space
and approximately 5,000 square feet of
retail space in the new AuburnBank Center building available for lease to
third party tenants.
In February 2022, the Company entered into an agreement to sell a parcel of approximately 0.85
acres to a hotel developer.
As part of the agreement, the Bank negotiated a long-term lease with the hotel developer
for 100 to 150 parking spaces in
the Bank’s parking deck.
In October 2022, the Company closed the sale at the agreed upon price
of $4.3 million, and
recognized a $3.2 million gain.
The Opelika branch is located in Opelika, Alabama. This branch, built in 1991,
is owned by the Bank and has
approximately 4,000 square feet of space. This branch offers the full line of the
Bank’s services and has drive-through
windows and an ATM.
This branch offers parking for approximately 36 vehicles.
The Bank’s Notasulga branch was opened
in August 2001. This branch is located in Notasulga, Alabama, about 15
miles
west of Auburn, Alabama. This branch is owned by the Bank and has approximately 1,344
square feet of space. The Bank
leased the land for this branch from a third party.
In May 2022, the Bank’s land lease renewed
for another one year term.
This branch offers the full line of the Bank’s
services including safe deposit boxes and a drive-through window and parking
for approximately 11 vehicles, including a handicapped
ramp.
In November 2002, the Bank opened a loan production office
in a leased space in Phenix City,
Alabama, about 35 miles
south of Auburn, Alabama. In November 2022, the Bank renewed its lease for another
year.
In February 2009, the Bank opened a branch located on Bent Creek Road in Auburn,
Alabama. This branch is owned by the
Bank and has approximately 4,000 square feet of space. This branch offers
the full line of the Bank’s services and
has
drive-through windows and a drive-up ATM.
This branch offers parking for approximately 29 vehicles.
In December 2011, the Bank opened a branch located
on Fob James Drive in Valley,
Alabama, about 30 miles northeast of
Auburn, Alabama.
This branch is owned by the Bank and has approximately 5,000 square feet of space.
This branch offers
the full line of the Bank’s services and has drive-through
windows and a drive-up ATM.
This branch offers parking for
approximately 35 vehicles.
Prior to December 2011, the Bank had operated
a loan production office in Valley,
which was
originally opened in September 2004.
In February 2015, the Bank relocated its Auburn Kroger branch to a new location
within the Corner Village Shopping
Center, in Auburn, Alabama. In February 2015,
the Bank entered into a new lease agreement for five years with options for
two 5-year extensions. In February 2020, the Bank exercised its option to renew the lease
for another five years. The Bank
leases approximately 1,500 square feet of space for the Corner Village
branch. Prior to relocation, the Bank’s
Auburn
Kroger branch was located in the Kroger supermarket in the same shopping center
since August 1988. The current Corner
Village branch offers the
full line of the Bank’s deposit and other services including
an ATM,
but does not maintain safe
deposit boxes.
In September 2015, the Bank relocated its Auburn Wal
-Mart Supercenter branch in south Auburn, which had been opened
in 2004 to a new building, which the Bank built in 2015 at the intersection of S. Donahue
Avenue and E. University
Drive
in Auburn, Alabama.
The South Donahue branch has approximately 3,600 square feet of space.
The South Donahue
branch offers the full line of the Bank’s
services and has drive-through windows and an ATM.
This branch offers parking
for approximately 28 vehicles.
In May 2017, the Bank relocated its Opelika Kroger branch to a new location the Bank purchased
in August 2016 near the
Tiger Town
Retail Shopping Center and the intersection of U.S. Highway 280 and Frederick
Road in Opelika, Alabama.
The Tiger Town
branch, built in 2017, has approximately 5,500 square feet of space.
Prior to relocation, the Bank’s
Opelika Kroger branch was located inside the Kroger supermarket in the Tiger
Town retail center in Opelika,
Alabama. The
Opelika Kroger branch was
originally opened in July 2007. The Tiger
Town branch offers
the full line of the Bank’s
services and has drive-through windows and an ATM.
This branch offers parking for approximately 36 vehicles.
Table of Contents
51
In addition to the eight ATMs
at various branch locations, mentioned above, the Bank also has four
ATMs
located at
various locations within our primary service area.
In September 2018, the Bank opened a loan production office on East Samford
Avenue in Auburn,
Alabama.
The location
has approximately 2,500 square feet of space and is leased through 2028.
This loan production office was relocated to the
newly developed AuburnBank Center in June 2022.
The Company entered into a three year sublease agreement, during
2022, with a tenant, which has an option to renew that lease for three additional years.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.