1 unchanged sentence
Cybersecurity
−Removed: The Company maintains a robust Information Security Program that sets forth the Company’s commitment to the continual review and improvement of policies, processes, procedures, and standards for evaluating electronic and physical methods of accessing, collecting, storing, using, transmitting, disposing, and protecting sensitive information including customer information under guidelines established as part of the Gramm Leach-Bliley Act (GLBA).
−Removed: The Company uses or adheres to relevant standards and frameworks from the Federal Financial Institutions Examination Council (FFIEC) and National Institute of Standards and Technology (NIST), among others, to assess information security risks and controls, as well as to assess the maturity and effectiveness of the Information Security Program.
−Removed: The Board of Directors and Executive Management are responsible for ensuring that the Information Security Program within Enterprise Risk Management identifies, measures, monitors, controls, and reports risk according to significance.
−Removed: If risks are determined to be undesired and beyond stated and aggregated Risk Appetites, the Board of Directors and Executive Management take appropriate action to ensure that excessive risk is mitigated or eliminated, which may include reducing risk exposure.
−Removed: The Board of Directors has final responsibility, after consultation with management, for ensuring the Information Security Program aligns with the overall business strategy and provides oversight to protect the Company from ongoing and emerging threats, including those related to cybersecurity.
−Removed: The Information Security Program is overseen by the Company’s Information Security Officer ("ISO") , who reports directly to the Chief Risk Officer.
−Removed: The ISO has held this position with the Company since May, 2024, and has worked at the Company in cybersecurity for almost 12 years and in the information technology industry for more than 16 years.
−Removed: The Chief Risk Officer has held the position at the Company since October 2016, when he joined the Company from the FDIC where he was employed for 24 years and held multiple positions including Senior Risk Examiner for the Division of Risk Management Supervision and Acting Regional Manager for the Division of Insurance and Research.
−Removed: During his tenure with the FDIC, the CRO served from time to time as the Examiner-in-Charge for Berkshire Bank and numerous other banks throughout New England.
−Removed: The ISO is responsible for the implementation, maintenance, and enforcement of the Information Security Program and related policies and standards.
−Removed: The program is evaluated and adjusted at least annually based on the results of testing, monitoring, and the adoption of best practices.
−Removed: Reporting occurs annually on the status of the Information Security Program to the Board’s Risk Management, Capital & Compliance Committee.
−Removed: Reporting includes the overall status of the program, material matters related to the program, Key Risk Indicators ("KRIs"), cyber risk assessments results, emerging risks, risk management and control decisions, control testing results, third party security assessments, penetration test results, security breaches or violations, and recommendations for changes to the program.
−Removed: The Company maintains a robust Third-Party Risk Management program to manage risks related to third-party relationships in a manner that is consistent with the Company’s strategic goals, organizational objectives, and risk appetite.
−Removed: This includes comprehensive risk and control assessments to ensure sensitive information is safeguarded appropriately.
+Added: As a financial services company, we face cybersecurity risks and threats, and our customers, suppliers, and third-party service providers face cybersecurity risks and threats.
+Added: As part of the operation of our business, the Company uses, stores, and processes data for our customers, employees, partners, and suppliers.
+Added: A cybersecurity incident impacting any of these entities could materially adversely affect our operations, performance, or results of operations.
+Added: In addition, as a financial services company we are subject to extensive regulatory compliance requirements, including those established by the FRB and MDOB.
+Added: The Company maintains a robust Information Security Program (the “Program”) that is designed to identify, assess and mitigate risks from cybersecurity threats to the data and our systems.
+Added: The Program establishes a regular cadence for review and update to the then current standards for evaluating electronic and physical methods of accessing, collecting, storing, using,
+Added: transmitting, disposing, and protecting sensitive information including customer information under guidelines established as part of GLBA.
+Added: The Company uses or adheres to relevant standards and frameworks from the FFFIEC and NIST, among others, to assess information security risks and controls, as well as to assess the maturity and effectiveness of the Program.
+Added: Risk Management Oversight and Governance
+Added: The Company’s Chief Security Officer ("CSO") has primary responsibility for assessing and managing the Program and reporting on cybersecurity matters to the Board of Directors.
+Added: The CSO reports directly to the Chief Information Officer.
+Added: The CSO is responsible for the implementation, maintenance, and enforcement of the Program.
+Added: The CSO has extensive experience managing information security systems and holds the Certification Information Systems Manager (CISM) designation.
+Added: Our CSO regularly updates members of executive management on developments surrounding cybersecurity.
+Added: The CSO reports to the Risk Committee of the Board of Directors and provides regular reports to the Risk Committee on emerging cybersecurity issues and the Company’s cybersecurity infrastructure.
+Added: The Program is overseen by the Board of Directors which has delegated certain responsibilities to the Risk Committee.
+Added: The Board of Directors oversees management’s processes for identifying and mitigating risks, including cyber risks, to assist in the alignment of the Company’s risk exposure with the Company’s overall risk tolerances.
+Added: The Board of Directors has also engaged an experienced information security advisor to assist with cybersecurity and data privacy oversight responsibilities.
+Added: This advisor provides the Board of Directors with independent updates on external market cybersecurity threats and emerging risks on a regular basis.
+Added: The Risk Committee, the Audit Committee, and the Board of Directors are active in understanding and evaluating cybersecurity risks.
+Added: The Risk Committee receives and reviews a quarterly Enterprise Risk Management (“ERM”) report from the Chief Risk Officer that is the cumulation of a process that involves discussions with leaders across the Company and incorporates a number of enterprise risk factors, including those related to cybersecurity threats.
+Added: The Audit Committee receives the results of internal and external penetration testing as well as any other audits applicable to the Company’s information security programs.
+Added: The Audit Committee actively engages management in discussions surrounding the outcome of these audits.
+Added: At least annually, the Risk Committee receives a report from the CSO covering the Company’s Program.
+Added: This report includes a review of the overall status of the Program, any material matters related to the Program, enhancements made or recommended to be made to the Program, a discussion of management’s actions to identify and detect threats, Key Risk Indicators and planned action steps in the event of an incident, an overview of the results of testing, any security breaches or violations, and an overview of employee training and engagement efforts.
+Added: The Chair of the Risk Committee reports to the Board of Directors on this presentation.
+Added: In addition, separately, on at least an annual basis, the Risk Committee receives updates from the CSO on the Company’s Incident Response Plan, which outlines steps to be followed in the event of an incident including detection, mitigation, recovery, and notification (including notification to senior management, the Board of Directors, and functional business areas), and remediation.
+Added: Cybersecurity Risk Management Program
+Added: The Program is designed to identify, assess, manage, mitigate, and respond to cyber threats with the goal of preventing cybersecurity incidents to the extent feasible, while also increasing our system resilience to minimize business disruption in the event we experience a cyber event.
+Added: Our program is structured to be nimble and adaptable to changes in cybersecurity threats over time and to respond to emerging threats in a timely and efficient manner.
+Added: Our Program consists of a layered cybersecurity approach and is incorporated into our overall ERM program.
+Added: The Program is evaluated on a regular basis, at least annually, and adjustments to the Program are made based on the results of these evaluations and changes to industry standards.
+Added: The Company maintains a Third-Party Risk Management program to manage risks related to third-party relationships in a manner that is consistent with the Company’s risk appetite.
+Added: This includes risk and control assessments to provide for the appropriate safeguarding of sensitive information.
The Company has a dedicated internal Security Operations Center ("SOC") and a Managed Detection and Response ("MDR") third party service that provides 24/7/365 monitoring of its environment to investigate and respond to security alerts.
2 unchanged sentences
Threat hunts operate both proactively and reactively to look for relevant behaviors and indicators of compromise from cybersecurity events or zero-day vulnerabilities.
−Removed: An Incident Response Plan is in place to ensure the timely and effective handing of security incidents.
−Removed: This includes providing the Company with a detailed outline of how to respond to a security incident, team responsibilities, contact information for key resources, definitions for determining the severity and escalation of security incidents, and pre-built playbooks to respond to the most common types of security incidents including ransomware.
+Added: The Company maintains an Incident Response Plan that is designed to timely and effectively address the handing of security incidents.
+Added: This includes providing the Company with a detailed outline of how
+Added: to respond to a security incident, team responsibilities, contact information for key resources, definitions for determining the severity and escalation of security incidents, and pre-built playbooks to respond to the most common types of security incidents including ransomware.
Incident response and escalation plans are tested and reviewed for improvements at least annually.
2 unchanged sentences
This includes incident response training on how to communicate potential or actual incidents.
−Removed: The Company continues to face risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations, or reputation.
−Removed: Although such risks have not materially affected us, we have experienced threats to and breaches of our data, including breaches caused by human error or breaches affecting third parties of the Company.
−Removed: For more information about the cybersecurity risks we face, see Item 1A-Risk Factors.
+Added: Our Company faces a number of cybersecurity risks in connection with the operation of our business which could have a material adverse effect on our business financial condition, results of operations, cash flows, or reputation.
+Added: Although, to date, such risks have not materially affected us, we have, from time to time, experienced threats to and breaches of our data, including breaches caused by human error or breaches affecting third parties of the Company.
+Added: For more information about the cybersecurity risks we face, see the risk factors entitled “ We face continuing and growing security risks to our information base, including the information we maintain relating to our customers .” and “ We rely on other companies to provide key components of our business infrastructure .” in Item 1A- Risk Factors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.