3 unchanged sentences
Assessing, identifying and managing material risks from cybersecurity threats is critical for maintaining the security of the Company’s data and information systems, and is integrated into our enterprise risk management systems and processes.
−Removed: The Bank’s approach to cybersecurity risk management and strategy is based on the FFIEC Cybersecurity Assessment Tool (“CAT”), which provides a repeatable and measurable process for evaluating cybersecurity preparedness and assessing, identifying, and managing material risks from cybersecurity threats.
+Added: The Bank’s approach to cybersecurity risk management and strategy is based on the Federal Financial Institutions Examination Council (“FFIEC”) Cybersecurity Assessment Tool (“CAT”), which provides a repeatable and measurable process for evaluating cybersecurity preparedness and assessing, identifying, and managing material risks from cybersecurity threats.
The CAT incorporates cybersecurity-related principles from the FFIEC Information Technology Examination Handbook and regulatory guidance, and concepts from other industry standards, including the National Institute of Standards and Technology Cybersecurity Framework.
14 unchanged sentences
This program includes the following components:
−Removed: ● Mandatory annual cybersecurity employee training;
+Added: ● Mandatory annual cybersecurity employee training for all employees;
● Training specifically targeted to Senior Management and Information Technology staff;
9 unchanged sentences
Board and Management Governance
−Removed: The Company’s Board of Directors recognizes the importance of maintaining the trust and confidence of our customers, employees, and shareholders.
+Added: The Company’s Board of Directors recognizes the importance of maintaining the trust and confidence of our customers, employees, and shareholders, including the risks associated with cybersecurity threats.
The Board of Directors’ responsibilities for cybersecurity risk management and strategy include the following:
5 unchanged sentences
● Reviewing the results of management’s ongoing monitoring of the Bank’s exposure to and preparedness for cyber threats.
−Removed: The Company has also appointed an ISO, who reports directly to the Audit Committee and shares a co-sourced relationship with an outside consulting firm.
+Added: The Company has also appointed an ISO, who reports directly to the Audit Committee and to the Chief Executive Officer and shares a co-sourced relationship with a third party consultant.
The ISO has been with Bank First for over 10 years in various operational and administrative roles.
−Removed: For the past four years, he has served as the Bank’s Enterprise Risk Manager, and as ISO for the past two years.
+Added: For the past five years, he has served as the Bank’s Enterprise Risk Manager, and as ISO for the past three years.
In 2022, he earned the Certified Banking Security Manager certification from SBS Cybersecurity.
−Removed: The ISO works closely with the head of Information Technology to ensure that the Bank’s cybersecurity controls are in line with established internal culture, Board expectations and risk appetite, and all regulatory requirements.
+Added: The ISO works closely with the Director of Technology to ensure that the Bank’s cybersecurity controls are in line with established internal culture, Board expectations and risk appetite, and all regulatory requirements.
The ISO’s responsibilities include the following:
−Removed: ● Developing a plan to conduct and complete the CAT;
+Added: ● Developing a plan to conduct and complete the CAT on an annual basis;
● Working with the VP-Director of Technology to evaluate the results of the CAT;
2 unchanged sentences
● Reviewing, approving, and supporting plans to address risk management and control weaknesses;
−Removed: ● Analyzing and presenting the results of the CAT to the Board of Directors;
−Removed: ● Providing periodic cybersecurity updates to the Board of Directors;
+Added: ● Analyzing and presenting the results of the CAT to the full Board of Directors;
+Added: ● Providing periodic cybersecurity updates to the full Board of Directors;
● Overseeing the performance of ongoing monitoring to remain nimble and agile in addressing evolving areas of cybersecurity risk;
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.