Item 1B – Unresolved Staff Comments
−Removed: T able of C onten ts
Item 1C – Cybersecurity
16 unchanged sentences
The FFIEC framework offers a set of guidelines to help financial institutions effectively manage and mitigate cybersecurity risks.
−Removed: ISO/IEC 27001 is an international standard developed by the ISO specifically for Information Security, Cybersecurity and Privacy Protection (ISCPP).
+Added: ISO/IEC 27001 is an international standard developed by ISO specifically for Information Security, Cybersecurity and Privacy Protection (ISCPP).
These frameworks provide best practices for managing cybersecurity risks and ensuring information security, and we consider them to be aspirational benchmarks to help inform the design of our Information Security Program.
While our program is designed to be robust, the sophistication and evolving nature of cyber threats mean no system can fully eliminate risk.
−Removed: For more information on how cybersecurity risk may affect the Company’s business strategy, results of operations or financial condition, please refer to Item 1A, Risk Factors — Risks Related to Cybersecurity, Data and Fraud.
The Company uses a cross-functional approach to identify, prevent, and mitigate cybersecurity threats and incidents.
1 unchanged sentence
While cybersecurity risks could materially affect the Company, past incidents have not materially affected our business strategy, results of operations or financial condition.
−Removed: For further details on potential cybersecurity risks, see Item 1A, Risk Factors — Risks Related to Cybersecurity, Data and Fraud.
+Added: For more information on how cybersecurity risk may affect the Company’s business strategy, results of operations or financial condition, please refer to Item 1A, Risk Factors—Risks Related to Cybersecurity, Data and Fraud.
Our Board of Directors annually reviews and approves the Company’s Risk Appetite Statement, which defines key risk categories and associated metrics that are monitored quarterly by Management and reported to the Risk Committee.
5 unchanged sentences
In this role, she leverages more than 25 years of information technology experience.
−Removed: The Bank’s Chief Information Security Officer (CISO) has been with the Company for more than 13 years and has maintained various applicable cybersecurity and IT audit certifications.
+Added: The Bank’s Chief Information Security Officer (CISO) has been with the Company for more than a decade and has maintained various applicable cybersecurity and IT audit certifications.
Prior to joining the Bank, he worked for a Fortune 500 company and had 15 years of information technology experience working in networking, information security and information technology auditing.
−Removed: T able of C onten ts
Our Information Technology (IT) Management team is responsible for conducting risk assessments, designing the Information Security Program, overseeing service provider arrangements, establishing risk-based response programs for incidents involving unauthorized data access, providing staff training, conducting testing of key controls, systems, and procedures, and adjusting the program to reflect changes in people, processes, technology, sensitive information, threats, and the business environment (e.g., mergers, acquisitions, alliances, joint ventures, or outsourcing arrangements).
6 unchanged sentences
Both teams may engage cybersecurity legal counsel and other external experts in connection with their respective activities.
−Removed: An escalation process facilitates updates to internal governance groups, including the Company’s Disclosure Committee and/or the Board of Directors’ Audit Committee, each of which also receives a quarterly report from the ECEET chair.
+Added: An escalation process facilitates keeping internal governance groups, including the Company’s Disclosure Committee and/or the Board of Directors’ Audit Committee, informed, with each committee also receiving a quarterly report from the ECEET chair.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.