1 unchanged sentence
CYBERSECURITY
−Removed: We rely extensively on
−Removed: various information systems and other electronic resources to operate our business.
−Removed: nearly all of our customers, service providers and other business partners on whom
−Removed: we depend, including the providers of
−Removed: our online banking, mobile banking and accounting systems, use their own electronic information
−Removed: systems can be compromised, including by employees, customers and other individuals
−Removed: who are authorized to use them,
−Removed: and bad actors using sophisticated and a constantly evolving set of software, tools
−Removed: and strategies to do so.
−Removed: The threats are
−Removed: domestic and international and range from small to large, including state
−Removed: sponsored, terrorist and criminal organizations
−Removed: with substantial funds, and technical and other resources
+Added: We rely extensively
+Added: on various information systems and other electronic resources to operate our business.
+Added: nearly all of our customers, service providers and other business partners on
+Added: whom we depend, including the providers of
+Added: our online banking, mobile banking and accounting systems, use their own
+Added: electronic information systems.
+Added: systems can be compromised by employees, customers and other
+Added: authorized individuals, and bad actors using sophisticated
+Added: and constantly evolving sets of software, tools and strategies, which may include
+Added: artificial intelligence, to do so.
+Added: threats are domestic and international and range from small to large,
+Added: including state sponsored, terrorist and criminal
+Added: organizations with substantial funds, and technical
+Added: and other resources
As a bank, we and our vendors, service providers and customers may be attractive targets,
1 unchanged sentence
cybersecurity threats.
−Removed: Insurance to fully cover these risks is unavailable in sufficient
−Removed: amounts at reasonable costs.
+Added: Insurance to fully cover these risks is unavailable in sufficient amounts at reasonable
believe the more effective approach is taking active measures to
detect, deter and reduce cybersecurity threats, and be
−Removed: prepared to address and remediate any breaches and prevent similar breaches in the
+Added: prepared to address and remediate any breaches and prevent similar breaches
+Added: in the future.
See “Risks Related to
1 unchanged sentence
in Item 1A of this Form 10-K for
+Added: additional information.
Accordingly, we have devoted
4 unchanged sentences
operations and governance;
−Removed: Establishing an IT Steering Committee of the Board that is responsible for security administration,
−Removed: conducting regular assessments of our information systems, existing controls, vulnerabilities
−Removed: and potential
−Removed: improvements;
−Removed: Implementing layers of controls and not allowing excessive reliance on any single control;
+Added: Establishing an IT Steering Committee that includes participation by directors that
+Added: is responsible for security
+Added: administration, including reviewing assessments of our information
+Added: systems, existing controls, vulnerabilities
+Added: and potential improvements;
+Added: Implementing layers of controls and not allowing excessive reliance on
+Added: any single control;
Employing a variety of preventative and detective tools designed to monitor,
1 unchanged sentence
regarding suspicious activity;
−Removed: Continuously evaluating tools that can detect and help respond to cybersecurity threats
−Removed: in real-time;
−Removed: Leveraging people, processes and technology to manage and maintain cybersecurity controls;
−Removed: Maintaining a vendor management program with periodic review processes, and
−Removed: a third-party risk
−Removed: management program designed to identify, assess and manage risks associated
−Removed: with external service providers;
−Removed: Monitoring our systems and related software and programming periodically to update
−Removed: programing, including updating data protection elements,
−Removed: and requiring that our service providers also engage
−Removed: in similar programs that are reasonably designed to deter cybersecurity breaches;
−Removed: Performing initial and ongoing due diligence with respect to our third-party service
−Removed: providers, including their
−Removed: cybersecurity practices and safeguards, and service levels based on the risk they pose to the Bank;
−Removed: Engaging third-party cybersecurity consultants, who conduct periodic
−Removed: penetration testing, vulnerability
−Removed: assessments and other procedures to identify potential weaknesses in our systems and
+Added: Continuously evaluating tools that can detect and help respond to cybersecurity
+Added: threats in real-time;
+Added: Leveraging people, processes and technology to manage and maintain cybersecurity
+Added: Maintaining a vendor management program with pre-engagement and periodic
+Added: review processes thereafter,
+Added: and a third-party risk management program designed to identify, assess and manage
+Added: risks associated with
+Added: external service providers;
+Added: Monitoring our systems and related software and programming periodically
+Added: to update software and
+Added: programing, including updating data protection elements, and requiring
+Added: that our service providers also engage
+Added: in similar programs that are reasonably designed to deter cybersecurity
+Added: Performing initial and ongoing due diligence with respect to our third-party
+Added: service providers, including their
+Added: cybersecurity practices and safeguards, and service level standards
+Added: based on the risk they pose to the Bank;
+Added: Engaging third-party cybersecurity consultants, who conduct periodic penetration
+Added: testing, vulnerability
+Added: assessments and other procedures to identify potential weaknesses in our
+Added: systems and processes;
Conducting periodic cybersecurity training for our employees and the Company’s
board of directors.
−Removed: Our Information Security Program is a key part of our overall risk management system,
−Removed: which is administered by our IT
−Removed: Steering Committee and evaluated by our IT Steering Committee and chief risk officer.
+Added: Our Information Security Program is a key part of our overall risk management
+Added: system, which is administered by our IT
+Added: Steering Committee and evaluated by our IT Steering Committee and chief
+Added: risk officer.
The program includes
−Removed: administrative, technical and physical safeguards to help protect the security and confidentiality
−Removed: and availability of
+Added: administrative, technical and physical safeguards to help protect the security
+Added: and confidentiality and availability of
customer records and information.
−Removed: From time-to-time, we have identified cybersecurity threats that require us to
−Removed: make changes to our processes, equipment
+Added: From time-to-time, we have identified cybersecurity threats
+Added: that require us to make changes to our processes and equipment
and to implement additional safeguards.
−Removed: While none of these identified threats or incidents
−Removed: have materially affected us, it is
−Removed: possible that threats and incidents we identify in the future could have a material adverse effect
−Removed: on our business strategy,
+Added: While none of these identified
+Added: threats or incidents have materially affected us, it is
+Added: possible that threats and incidents we identify in the future could have a material
+Added: adverse effect on our business strategy,
customer service, data privacy and security,
1 unchanged sentence
The Company’s Chief Technology
−Removed: Officer is responsible for the day-to-day management of
−Removed: cybersecurity risks we face and
−Removed: oversees the IT Steering Committee, which is chaired by a director of the Company’s
+Added: Officer is responsible for the day-to-day management of cybersecurity
+Added: risks we face and
+Added: oversees the IT Steering Committee, which is chaired by a director of
+Added: the Company’s board.
The IT Steering Committee
−Removed: oversees the information security assessment, development of policies, standards
−Removed: and procedures, testing, training and
+Added: oversees the information security assessment, development of policies,
+Added: standards and procedures, testing, training and
security report processes.
−Removed: The IT Steering Committee is comprised of directors and officers
−Removed: with the appropriate expertise
−Removed: and authority to oversee the Information Security Program.
−Removed: Our Chief Technology Officer,
−Removed: along with the information technology department, is accountable for managing our
+Added: The IT Steering Committee is comprised of officers with the appropriate
+Added: expertise and authority
+Added: to oversee the Information Security Program, and includes the participation
+Added: of certain directors.
+Added: Our Chief Technology
+Added: Officer, along with the information
+Added: technology department, is accountable for managing our
enterprise information security and delivering our information security program.
−Removed: department, as a whole, consists of
−Removed: information security professionals with varying degrees of education and experience.
−Removed: The Chief Technology Officer
+Added: The department, as a whole, consists of
+Added: information security professionals with varying degrees of education
+Added: and experience.
+Added: The Chief Technology
subject to professional education and certification requirements.
In particular,
−Removed: our Chief Technology
−Removed: Officer, who is also
+Added: our Chief Technology Officer,
designated as our Information Security Officer,
1 unchanged sentence
risk management.
−Removed: In addition, the Company’s Board,
−Removed: both as a whole and through its IT Steering Committee is responsible for the oversight
−Removed: of risk management, including cybersecurity risks.
−Removed: In that role, the Company’s
−Removed: Board and the IT Steering Committee, with
−Removed: support from the Company’s management and third
−Removed: party cybersecurity advisors, are responsible for ensuring that the risk
−Removed: management processes designed and implemented by management are adequate
−Removed: and functioning as designed.
−Removed: reviews and approves an information security program, vendor management policy (incl
−Removed: uding third-party service
−Removed: providers), acceptable use policy,
−Removed: incident response policy and business continuity planning policy on an annual basis.
−Removed: the aforementioned policies are developed and implemented by Company management.
−Removed: To carry out their duties,
−Removed: receives updates at least quarterly from the Chief Technology
+Added: In addition, the Company’s
+Added: Board, both as a whole and through directors participating in the IT Steering
+Added: Committee, is
+Added: responsible for the oversight of risk management, including cybersecurity
+Added: In that role, the Company’s Board
+Added: IT Steering Committee, with support from the Company’s
+Added: management and third-party cybersecurity advisors, are
+Added: responsible for implementing and maintaining risk management processes
+Added: designed and implemented by management that
+Added: are adequate and functioning as designed.
+Added: The Board reviews and approves an information security program, vendor
+Added: management policy (including third-party service providers), acceptable
+Added: use policy, incident response procedures
+Added: business continuity planning policy on at least an annual basis.
+Added: All the aforementioned
+Added: policies are developed and
+Added: implemented by Company management.
+Added: carry out their duties, the Board receives updates at least quarterly from the
+Added: Chief Technology
Officer regarding cybersecurity risks and the Company’s
−Removed: efforts to prevent, detect, mitigate and remediate any cybersecurity incidents.
+Added: efforts to prevent, detect, mitigate and
+Added: remediate any cybersecurity incidents.
DESCRIPTION OF PROPERTY
−Removed: The Bank conducts its business from its main office and seven full-service
−Removed: The Bank also operates a loan
−Removed: production office in Phenix City,
−Removed: The Bank owns its main campus in downtown Auburn, Alabama, which comprises
−Removed: over 4 acres and includes the newly
−Removed: constructed AuburnBank Center,
−Removed: which was completed in May 2022 and had its grand opening in June 2022.
+Added: The Bank conducts its business from its main office,
+Added: seven full-service branches,
+Added: and a loan production office.
+Added: The Bank owns its main campus in downtown Auburn, Alabama, which
+Added: comprises over 4 acres and includes the newly
+Added: constructed AuburnBank Center, which
+Added: was completed in May 2022 and had its grand opening in June 2022.
AuburnBank Center has approximately 90,000 square feet of space.
The AuburnBank Center includes the Bank’s
−Removed: office, Auburn loan production office, and all of its back-office
+Added: office, Auburn loan production office, and
+Added: all of its back-office operations.
The main office branch offers the full line of
6 unchanged sentences
teller window.
−Removed: The Bank has approximately 46,000 square feet of office space
−Removed: and approximately 5,000 square feet of
−Removed: retail space in the new AuburnBank Center building available for lease to
−Removed: third party tenants.
−Removed: In February 2022, the Company entered into an agreement to sell a parcel of approximately 0.85
−Removed: acres to a hotel developer.
−Removed: As part of the agreement, the Bank negotiated a long-term lease with the hotel developer
−Removed: for 100 to 150 parking spaces in
−Removed: the Bank’s parking deck.
−Removed: In October 2022, the Company closed the sale at the agreed upon price
−Removed: of $4.3 million, and
−Removed: recognized a $3.2 million gain.
+Added: The Bank has approximately 46,000 square feet of Class A office space
+Added: and approximately 5,000 square
+Added: feet of retail space in the new AuburnBank Center building available for
+Added: lease to third party tenants, of which
+Added: approximately 21,000 square feet is currently leased and occupied.
The Opelika branch is located in Opelika, Alabama.
−Removed: This branch, built in 1991,
−Removed: is owned by the Bank and has
+Added: This branch, built
+Added: in 1991, is owned by the Bank and has
approximately 4,000 square feet of space.
−Removed: This branch offers the full line of the
−Removed: Bank’s services and has drive-through
+Added: This branch offers
+Added: the full line of the Bank’s services and
+Added: has drive-through
windows and an ATM.
This branch offers parking for approximately 36 vehicles.
−Removed: The Bank’s Notasulga branch was opened
−Removed: in August 2001.
−Removed: This branch is located in Notasulga, Alabama, about 15
−Removed: west of Auburn, Alabama.
+Added: The Notasulga branch was opened in August 2001.
+Added: This branch is located
+Added: in Notasulga, Alabama, about 15 miles west of
+Added: Auburn, Alabama.
This branch is owned by the Bank and has approximately 1,344
square feet of space.
−Removed: leased the land for this branch from a third party.
−Removed: In May 2022, the Bank’s land lease renewed
+Added: The Bank leased
+Added: the land for this branch from a third party.
+Added: In May 2024, the Bank’s land lease renewe
for another one-year term.
−Removed: This branch offers the full line of the Bank’s
−Removed: services including safe deposit boxes and a drive-through window and parking
−Removed: for approximately 11 vehicles, including a handicapped
+Added: branch offers the full line of the Bank’s
+Added: services including safe deposit boxes and a drive-through window
+Added: and parking for
+Added: approximately 11 vehicles, including
+Added: a handicapped ramp.
In November 2002, the Bank opened a loan production office
2 unchanged sentences
south of Auburn, Alabama.
−Removed: In November 2022, the Bank renewed its lease for another
−Removed: In February 2009, the Bank opened a branch located on Bent Creek Road in Auburn,
+Added: In November 2023, the Bank renewed
+Added: its lease for another 2 years.
+Added: In February 2009, the Bank opened a branch located on Bent Creek Road in
+Added: Auburn, Alabama.
This branch is owned by the
4 unchanged sentences
This branch offers parking for approximately 29 vehicles.
−Removed: In December 2011, the Bank opened a branch located
−Removed: on Fob James Drive in Valley,
+Added: In December 2011, the Bank opened a branch
+Added: located on Fob James Drive in Valley,
Alabama, about 30 miles northeast of
2 unchanged sentences
This branch offers
−Removed: the full line of the Bank’s services and has drive-through
−Removed: windows and a drive-up ATM.
+Added: the full line of the Bank’s services and
+Added: has drive-through windows and a drive-up ATM.
This branch offers parking for
approximately 35 vehicles.
−Removed: Prior to December 2011, the Bank had operated
−Removed: a loan production office in Valley,
+Added: Prior to December 2011, the Bank had operated a
+Added: loan production office in Valley,
originally opened in September 2004.
−Removed: In February 2015, the Bank relocated its Auburn Kroger branch to a new location
−Removed: within the Corner Village Shopping
−Removed: Center, in Auburn, Alabama.
−Removed: In February 2015,
−Removed: the Bank entered into a new lease agreement for five years with options for
−Removed: two 5-year extensions.
−Removed: In February 2020, the Bank exercised its option to renew the lease
−Removed: for another five years.
−Removed: leases approximately 1,500 square feet of space for the Corner Village
−Removed: Prior to relocation, the Bank’s
−Removed: Kroger branch was located in the Kroger supermarket in the same shopping center
−Removed: since August 1988.
−Removed: The current Corner
−Removed: Village branch offers the
−Removed: full line of the Bank’s deposit and other services including
−Removed: but does not maintain safe
−Removed: deposit boxes.
+Added: In February 2015, the Bank relocated its branch in the Auburn Kroger store
+Added: to a new leased location within the Corner
+Added: Village Shopping Center in
+Added: After careful consideration of the Bank’s customers,
+Added: branch usage, parking issues, the
+Added: lack of a drive through window and the close proximity to our other locations
+Added: in Auburn, the Bank closed the Corner
+Added: Village branch on December
+Added: 31, 2024, and its lease expired January 31, 2025.
In September 2015, the Bank relocated its Auburn Wal
−Removed: -Mart Supercenter branch in south Auburn, which had been opened
−Removed: in 2004 to a new building, which the Bank built in 2015 at the intersection of S.
−Removed: Avenue and E.
+Added: -Mart Supercenter branch in south Auburn, which had been
+Added: in 2004 to a new building, which the Bank built in 2015 at the intersection
+Added: Donahue Avenue
+Added: University Drive
in Auburn, Alabama.
5 unchanged sentences
for approximately 28 vehicles.
−Removed: In May 2017, the Bank relocated its Opelika Kroger branch to a new location the Bank purchased
−Removed: in August 2016 near the
+Added: In May 2017, the Bank relocated its Opelika Kroger branch to a new location the
+Added: Bank purchased in August 2016 near the
Retail Shopping Center and the intersection of U.S.
−Removed: Highway 280 and Frederick
−Removed: Road in Opelika, Alabama.
+Added: Highway 280 and Frederick Road
+Added: in Opelika, Alabama.
The Tiger Town
1 unchanged sentence
Prior to relocation, the Bank’s
−Removed: Opelika Kroger branch was located inside the Kroger supermarket in the Tiger
−Removed: Town retail center in Opelika,
−Removed: Opelika Kroger branch was
−Removed: originally opened in July 2007.
+Added: Opelika Kroger branch was located inside the Kroger supermarket in
+Added: the Tiger Town
+Added: retail center in Opelika, Alabama.
+Added: Opelika Kroger branch was originally opened in July 2007.
Town branch offers
2 unchanged sentences
This branch offers parking for approximately 36 vehicles.
−Removed: In addition to the eight ATMs
−Removed: at various branch locations, mentioned above, the Bank also has four
−Removed: various locations within our primary service area.
−Removed: In September 2018, the Bank opened a loan production office on East Samford
−Removed: Avenue in Auburn,
−Removed: has approximately 2,500 square feet of space and is leased through 2028.
−Removed: This loan production office was relocated to the
−Removed: newly developed AuburnBank Center in June 2022.
−Removed: The Company entered into a three year sublease agreement, during
−Removed: 2022, with a tenant, which has an option to renew that lease for three additional years.
+Added: In addition to the seven ATMs
+Added: at various branch locations, the Bank also has three ATMs
+Added: located at various locations
+Added: within our primary service area.
+Added: The Bank had a 2,500 square feet loan production office on
+Added: East Samford Avenue
+Added: in Auburn, Alabama.
+Added: When this loan
+Added: production office was relocated to the AuburnBank Center in June
+Added: 2022, the Company entered into a three-year sublease
+Added: agreement during 2022.
+Added: The sublessee has an option exercisable by September 2025 to renew the sublease for
+Added: remaining term of the
+Added: Bank’s lease ending in 2028.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.