3 unchanged sentences
Assessing, identifying and managing material risks from cybersecurity threats is critical for maintaining the security of the Company’s data and information systems, and is integrated into our enterprise risk management systems and processes.
−Removed: The Bank’s approach to cybersecurity risk management and strategy is based on the Federal Financial Institutions Examination Council (“FFIEC”) Cybersecurity Assessment Tool (“CAT”), which provides a repeatable and measurable process for evaluating cybersecurity preparedness and assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: The CAT incorporates cybersecurity-related principles from the FFIEC Information Technology Examination Handbook and regulatory guidance, and concepts from other industry standards, including the National Institute of Standards and Technology Cybersecurity Framework.
−Removed: The CAT consists of two parts:
−Removed: Cybersecurity Inherent Risk Profile and Cybersecurity Maturity.
−Removed: Completion of both parts of the CAT allow management and the Board to evaluate whether the Company’s cybersecurity risk and preparedness are aligned.
−Removed: The Cybersecurity Inherent Risk Profile is the level of risk posed to the Company by technologies and connection types, delivery channels, online/mobile products and technology services, organizational characteristics and external threats.
−Removed: Cybersecurity Maturity is designed to help management measure the Company’s level of risk and corresponding controls under the following five domains:
−Removed: (i) Cyber Risk Management and Oversight;
−Removed: (ii) Threat Intelligence and Collaboration;
−Removed: (iii) Cybersecurity Controls;
−Removed: (iv) External Dependency Management;
−Removed: and (v) Cyber Incident Management and Resilience.
−Removed: The Information Security Officer (“ISO”) and the Company’s Information Technology Committee conduct and review the CAT annually to identify changes to the Company’s inherent risk profile;
+Added: The Bank’s approach to cybersecurity risk management and strategy is based on the Cyber Risk Institute (“CRI”) Profile, which is a comprehensive, industry-standard cybersecurity framework tailored for the financial sector to assess risk and ensure regulatory compliance.
+Added: The CRI incorporates cybersecurity-related principles from the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, regulatory guidance, and concepts from other industry standards.
+Added: The CRI consists of two parts:
+Added: Impact tiering, which is used to identify the Bank’s cybersecurity maturity expectations;
+Added: and the risk assessment.
+Added: Completion of both parts of the CRI allows management and the Board to evaluate whether the Company’s cybersecurity risk and preparedness are aligned.
+Added: The CRI impact tiering is a self-assessment, prompting questions to customize the profile assessment, based on the institution’s risk and activities.
+Added: The risk assessment portion of the CRI contains diagnostic statements grouped by function, category and subcategory.
+Added: The risk assessment indicates the applicability of each diagnostic statement to each impact tier level.
+Added: Each statement is given an assessment rating with supporting rationale and evidence provided to justify the rating given.
+Added: Functions in the risk assessment portion include:
+Added: (ii) Identify;
+Added: (iii) Protect;
+Added: (vi) Recover;
+Added: and (vii) Extend.
+Added: The Information Security Officer (“ISO”) and the Company’s management-level Information Technology Committee conduct and review the CRI annually to identify changes to the Company’s inherent impact tier and risk profile;
when new threats arise or when considering changes to the business strategy, such as expanding operations, offering new products and services, or entering into new third-party relationships that support critical activities.
1 unchanged sentence
In an effort to continually share threat intelligence and increase awareness of cybersecurity trends, the Company has also implemented a Cybersecurity Education and Awareness Program.
−Removed: This program includes the following components:
+Added: Among others, this program includes the following components:
● Mandatory annual cybersecurity employee training for all employees;
● Training specifically targeted to Senior Management and Information Technology staff;
−Removed: ● Bimonthly review of emerging security trends by the Information Technology Committee;
+Added: ● Monthly cybersecurity phishing simulation campaigns;
+Added: ● Quarterly review of emerging security trends by the management-level Risk Management Committee;
● Mandatory annual cybersecurity Board training;
● Periodic communication to employees highlighting internal control requirements and information about common threats or fraud schemes.
−Removed: ● Periodic communication to the Bank’s customers highlighting emerging threats and good cybersecurity hygiene.
−Removed: To date, we have not experienced a cybersecurity incident that has materially impacted our business strategy, results of operations, or financial condition.
+Added: The Company retains external consultants to assist in the development and monitoring processes for assessing, identifying, and managing potential cybersecurity threats.
+Added: The Company engages third-party service providers to conduct evaluations of security controls including through penetration testing and independent assessments, and to provide consulting regarding recommended practices to address new challenges.
+Added: The Company also requires third-party service providers to report on cybersecurity incidents so the Bank can assess their impact.
+Added: As part of the Bank’s vendor management process, the Bank conducts information security due diligence of third-parties with whom the Bank will interact, including risk profiling and classification.
+Added: The Company’s
+Added: vendor risk management program includes regular reviews and oversight of all service providers in accordance with a risk profile classification.
+Added: To date, we have not experienced a cybersecurity incident that has, or is reasonably likely to have, materially impacted our business strategy, results of operations, or financial condition.
Despite our efforts, there can be no assurance that our cybersecurity risk management processes and measures described will be fully implemented, complied with, or effective in protecting our systems and information.
4 unchanged sentences
The Company’s Board of Directors recognizes the importance of maintaining the trust and confidence of our customers, employees, and shareholders, including the risks associated with cybersecurity threats.
−Removed: The Board of Directors’ responsibilities for cybersecurity risk management and strategy include the following:
−Removed: ● Engaging management in establishing the Bank’s vision, risk appetite, and overall strategic direction;
−Removed: ● Approving plans to ensure the use of the CAT;
−Removed: ● Reviewing management’s analysis of the CAT results, inclusive of any reviews or opinions on the results issued by independent risk management or internal audit functions regarding those results;
+Added: The Board of Directors’ responsibilities for cybersecurity risk management and strategy, some of which are delegated to the Audit Committee, include the following:
+Added: ● Engaging management in establishing the Bank’s vision, risk tolerance, and overall strategic direction;
+Added: ● Approving plans to ensure the use of the CRI;
+Added: ● Reviewing management’s analysis of the CRI results, inclusive of any reviews or opinions on the results issued by independent risk management or internal audit functions regarding those results;
● Reviewing management’s determination of whether the Bank’s cybersecurity preparedness is aligned with its risks;
−Removed: ● Reviewing and approving plans to address any risk management or control weaknesses;
+Added: ● Reviewing and approving plans to address and enhance any risk management procedures or controls;
● Reviewing the results of management’s ongoing monitoring of the Bank’s exposure to and preparedness for cyber threats.
−Removed: The Company has also appointed an ISO, who reports directly to the Audit Committee and to the Chief Executive Officer and shares a co-sourced relationship with a third party consultant.
+Added: The Board’s oversight of cybersecurity risk is supported by our ISO, who reports directly to the Audit Committee and to the Chief Legal Counsel and shares a co-sourced relationship with a third-party consultant.
+Added: The ISO attends Audit Committee meetings and provides cybersecurity updates to the Audit Committee.
+Added: The ISO also provides annual risk assessments and reports regarding the information security program to the full Board.
+Added: Cybersecurity risk metrics and program updates are reported to management and the Audit Committee on a regular cadence, with periodic director education sessions supporting oversight.
+Added: The Audit Committee is also involved in oversight of potentially significant cybersecurity incidents, which are evaluated for materiality without unreasonable delay, consistent with SEC rules.
The ISO has been with Bank First for over 12 years in various operational and administrative roles.
−Removed: For the past five years, he has served as the Bank’s Enterprise Risk Manager, and as ISO for the past three years.
+Added: For the past six years, he has served as the Bank’s VP-Enterprise Risk Manager, and as ISO for the past three years.
In 2022, he earned the Certified Banking Security Manager certification from SBS Cybersecurity.
−Removed: The ISO works closely with the Director of Technology to ensure that the Bank’s cybersecurity controls are in line with established internal culture, Board expectations and risk appetite, and all regulatory requirements.
+Added: The ISO works closely with the Chief Information Officer to ensure that the Bank’s cybersecurity controls are in line with established internal culture, Board expectations and risk appetite, and all regulatory requirements.
The ISO’s responsibilities include the following:
−Removed: ● Developing a plan to conduct and complete the CAT on an annual basis;
−Removed: ● Working with the VP-Director of Technology to evaluate the results of the CAT;
−Removed: ● Leading employee efforts during the CAT to facilitate timely responses from across the Bank;
−Removed: ● Setting the target state of cybersecurity preparedness that best aligns to the Board of Directors’ approved risk appetite;
−Removed: ● Reviewing, approving, and supporting plans to address risk management and control weaknesses;
−Removed: ● Analyzing and presenting the results of the CAT to the full Board of Directors;
+Added: ● Developing a plan to conduct and complete the CRI on an annual basis;
+Added: ● Working with the Chief Information Officer to evaluate the results of the CRI;
+Added: ● Leading employee efforts during the CRI to facilitate timely responses from across the Bank;
+Added: ● Setting the target state of cybersecurity preparedness that best aligns to the Board of Directors’ approved risk tolerance;
+Added: ● Reviewing, approving, and supporting plans to address risk management and enhancing controls;
+Added: ● Analyzing and presenting the results of the CRI to the full Board of Directors;
● Providing periodic cybersecurity updates to the full Board of Directors;
−Removed: ● Overseeing the performance of ongoing monitoring to remain nimble and agile in addressing evolving areas of cybersecurity risk;
+Added: ● Overseeing the performance of ongoing monitoring to address evolving areas of cybersecurity risk;
+Added: ● Overseeing frequent testing/auditing activities, cybersecurity risk assessments, vulnerability scanning, penetration testing, monitoring of external threat intelligence and supplier risk sources, and 24/7 incident monitoring to inform our understanding of the cybersecurity risk landscape;
● Overseeing the Bank’s cybersecurity preparedness.
−Removed: ● Finally, the Company has established an Information Technology Committee to support the ISO in implementing the CAT, document formal action plans to be presented to the Board of Directors, enforce and implement the controls established by the CAT, and ensure employee compliance with internal controls
+Added: Finally, the Company has established an Information Technology Committee to support the ISO in implementing the CRI, documenting formal action plans to be presented to the Board of Directors, enforcing and implementing the controls established by the CRI, and assisting in ensuring employee compliance with internal controls.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.