Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED
STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
We rely extensively
on various information systems and other electronic resources to operate our business. In
addition,
nearly all of our customers, service providers and other business partners on
whom we depend, including the providers of
our online banking, mobile banking and accounting systems, use their own
electronic information systems.
Any of these
systems can be compromised by employees, customers and other
authorized individuals, and bad actors using sophisticated
and constantly evolving sets of software, tools and strategies, which may include
artificial intelligence, to do so.
The
threats are domestic and international and range from small to large,
including state sponsored, terrorist and criminal
organizations with substantial funds, and technical
and other resources
As a bank, we and our vendors, service providers and customers may be attractive targets,
and we confront continuous
cybersecurity threats.
Insurance to fully cover these risks is unavailable in sufficient amounts at reasonable
costs.
We
believe the more effective approach is taking active measures to
detect, deter and reduce cybersecurity threats, and be
prepared to address and remediate any breaches and prevent similar breaches
in the future.
See “Risks Related to
Information Security and Business Interruption” section of the Risk Factors included
in Item 1A of this Form 10-K for
additional information.
Accordingly, we have devoted
significant resources to assessing, identifying and managing risks associated
with
cybersecurity threats, including:
•
Implementing an Information Security Program that establishes policies and
procedures for security
operations and governance;
•
Establishing an IT Steering Committee that includes participation by directors that
is responsible for security
administration, including reviewing assessments of our information
systems, existing controls, vulnerabilities
and potential improvements;
•
Implementing layers of controls and not allowing excessive reliance on
any single control;
•
Employing a variety of preventative and detective tools designed to monitor,
block and provide alerts
regarding suspicious activity;
•
Continuously evaluating tools that can detect and help respond to cybersecurity
threats in real-time;
•
Leveraging people, processes and technology to manage and maintain cybersecurity
controls;
•
Maintaining a vendor management program with pre-engagement and periodic
review processes thereafter,
and a third-party risk management program designed to identify, assess and manage
risks associated with
external service providers;
Table of Contents
54
•
Monitoring our systems and related software and programming periodically
to update software and
programing, including updating data protection elements, and requiring
that our service providers also engage
in similar programs that are reasonably designed to deter cybersecurity
breaches;
•
Performing initial and ongoing due diligence with respect to our third-party
service providers, including their
cybersecurity practices and safeguards, and service level standards
based on the risk they pose to the Bank;
•
Engaging third-party cybersecurity consultants, who conduct periodic penetration
testing, vulnerability
assessments and other procedures to identify potential weaknesses in our
systems and processes; and
•
Conducting periodic cybersecurity training for our employees and the Company’s
board of directors.
Our Information Security Program is a key part of our overall risk management
system, which is administered by our IT
Steering Committee and evaluated by our IT Steering Committee and chief
risk officer.
The program includes
administrative, technical and physical safeguards to help protect the security
and confidentiality and availability of
customer records and information.
From time-to-time, we have identified cybersecurity threats
that require us to make changes to our processes and equipment
and to implement additional safeguards. While none of these identified
threats or incidents have materially affected us, it is
possible that threats and incidents we identify in the future could have a material
adverse effect on our business strategy,
customer service, data privacy and security,
continuity of service and reputation, and our results of operations and financial
condition.
The Company’s Chief Technology
Officer is responsible for the day-to-day management of cybersecurity
risks we face and
oversees the IT Steering Committee, which is chaired by a director of
the Company’s board. The IT Steering Committee
oversees the information security assessment, development of policies,
standards and procedures, testing, training and
security report processes.
The IT Steering Committee is comprised of officers with the appropriate
expertise and authority
to oversee the Information Security Program, and includes the participation
of certain directors.
Our Chief Technology
Officer, along with the information
technology department, is accountable for managing our
enterprise information security and delivering our information security program.
The department, as a whole, consists of
information security professionals with varying degrees of education
and experience. The Chief Technology
Officer is
subject to professional education and certification requirements. In particular,
our Chief Technology Officer,
who is also
designated as our Information Security Officer,
has relevant expertise in the areas of information security and cybersecurity
risk management.
In addition, the Company’s
Board, both as a whole and through directors participating in the IT Steering
Committee, is
responsible for the oversight of risk management, including cybersecurity
risks. In that role, the Company’s Board
and the
IT Steering Committee, with support from the Company’s
management and third-party cybersecurity advisors, are
responsible for implementing and maintaining risk management processes
designed and implemented by management that
are adequate and functioning as designed.
The Board reviews and approves an information security program, vendor
management policy (including third-party service providers), acceptable
use policy, incident response procedures
and
business continuity planning policy on at least an annual basis. All the aforementioned
policies are developed and
implemented by Company management. To
carry out their duties, the Board receives updates at least quarterly from the
Chief Technology
Officer regarding cybersecurity risks and the Company’s
efforts to prevent, detect, mitigate and
remediate any cybersecurity incidents.
ITEM 2. DESCRIPTION OF PROPERTY
The Bank conducts its business from its main office,
seven full-service branches,
and a loan production office.
Table of Contents
55
The Bank owns its main campus in downtown Auburn, Alabama, which
comprises over 4 acres and includes the newly
constructed AuburnBank Center, which
was completed in May 2022 and had its grand opening in June 2022.
The
AuburnBank Center has approximately 90,000 square feet of space.
The AuburnBank Center includes the Bank’s
main
office, Auburn loan production office, and
all of its back-office operations.
The main office branch offers the full line of
the Bank’s services and has one
ATM.
The Bank’s drive-through facility located
on the main office campus was
constructed in October 2012.
This drive-through facility has five drive-through lanes, including an ATM,
and a walk-up
teller window.
The Bank has approximately 46,000 square feet of Class A office space
and approximately 5,000 square
feet of retail space in the new AuburnBank Center building available for
lease to third party tenants, of which
approximately 21,000 square feet is currently leased and occupied.
The Opelika branch is located in Opelika, Alabama. This branch, built
in 1991, is owned by the Bank and has
approximately 4,000 square feet of space. This branch offers
the full line of the Bank’s services and
has drive-through
windows and an ATM.
This branch offers parking for approximately 36 vehicles.
The Notasulga branch was opened in August 2001. This branch is located
in Notasulga, Alabama, about 15 miles west of
Auburn, Alabama. This branch is owned by the Bank and has approximately 1,344
square feet of space. The Bank leased
the land for this branch from a third party.
In May 2024, the Bank’s land lease renewe
d
for another one-year term. This
branch offers the full line of the Bank’s
services including safe deposit boxes and a drive-through window
and parking for
approximately 11 vehicles, including
a handicapped ramp.
In November 2002, the Bank opened a loan production office
in a leased space in Phenix City,
Alabama, about 35 miles
south of Auburn, Alabama. In November 2023, the Bank renewed
its lease for another 2 years.
In February 2009, the Bank opened a branch located on Bent Creek Road in
Auburn, Alabama. This branch is owned by the
Bank and has approximately 4,000 square feet of space. This branch offers
the full line of the Bank’s services and
has
drive-through windows and a drive-up ATM.
This branch offers parking for approximately 29 vehicles.
In December 2011, the Bank opened a branch
located on Fob James Drive in Valley,
Alabama, about 30 miles northeast of
Auburn, Alabama.
This branch is owned by the Bank and has approximately 5,000 square feet of space.
This branch offers
the full line of the Bank’s services and
has drive-through windows and a drive-up ATM.
This branch offers parking for
approximately 35 vehicles.
Prior to December 2011, the Bank had operated a
loan production office in Valley,
which was
originally opened in September 2004.
In February 2015, the Bank relocated its branch in the Auburn Kroger store
to a new leased location within the Corner
Village Shopping Center in
Auburn.
After careful consideration of the Bank’s customers,
branch usage, parking issues, the
lack of a drive through window and the close proximity to our other locations
in Auburn, the Bank closed the Corner
Village branch on December
31, 2024, and its lease expired January 31, 2025.
In September 2015, the Bank relocated its Auburn Wal
-Mart Supercenter branch in south Auburn, which had been
opened
in 2004 to a new building, which the Bank built in 2015 at the intersection
of S. Donahue Avenue
and E. University Drive
in Auburn, Alabama.
The South Donahue branch has approximately 3,600 square feet of space.
The South Donahue
branch offers the full line of the Bank’s
services and has drive-through windows and an ATM.
This branch offers parking
for approximately 28 vehicles.
In May 2017, the Bank relocated its Opelika Kroger branch to a new location the
Bank purchased in August 2016 near the
Tiger Town
Retail Shopping Center and the intersection of U.S. Highway 280 and Frederick Road
in Opelika, Alabama.
The Tiger Town
branch, built in 2017, has approximately 5,500 square feet of space.
Prior to relocation, the Bank’s
Opelika Kroger branch was located inside the Kroger supermarket in
the Tiger Town
retail center in Opelika, Alabama. The
Opelika Kroger branch was originally opened in July 2007. The Tiger
Town branch offers
the full line of the Bank’s
services and has drive-through windows and an ATM.
This branch offers parking for approximately 36 vehicles.
In addition to the seven ATMs
at various branch locations, the Bank also has three ATMs
located at various locations
within our primary service area.
The Bank had a 2,500 square feet loan production office on
East Samford Avenue
in Auburn, Alabama.
When this loan
production office was relocated to the AuburnBank Center in June
2022, the Company entered into a three-year sublease
agreement during 2022.
The sublessee has an option exercisable by September 2025 to renew the sublease for
the
remaining term of the
Bank’s lease ending in 2028.
Table of Contents
56