9 unchanged sentences
(i) ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business, (ii) business line(s), including associated operations, services, functions, and support, that upon failure would result in a material loss of revenue, profit, or franchise value, or (iii) operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States.
−Removed: To date, we have not experienced a material cyber-attack that would require such reporting, though there can be no guarantee that such will not occur in the future, and any such attack could have a negative effect on our business and results of operations.
+Added: To date, we have not experienced cybersecurity incidents that we believe has, or is reasonably likely to, materially affect our business operations, strategy, or financial condition.
+Added: However, we continually assess the potential impact of cybersecurity threats, ensuring that any incident is evaluated for materiality in relation to our business strategy, operational results, and financial condition.
Cybersecurity risk is a key factor in assessing the Company’s overall operational and regulatory risk and is a component of our overall information security protocols.
2 unchanged sentences
This monitoring and response is reinforced with regular vulnerability scanning/remediation and penetration testing and includes an annual risk assessment that looks to threats on the Company’s own information technology platforms, and also assesses potential threats, owing to our use of third-party information technology platforms and services.
−Removed: As part of these processes, we engage well-established and professional third-party information security consultants to aid in the assessment and development of our monitoring and threat-detection processes and work with our internal teams.
−Removed: All employees receive security training upon hiring, annual refresher training for all employees, and phishing exercises to raise employee awareness.
+Added: As part of these processes, we engage well-established and professional third-party information security consultants to aid in the assessment and development of our monitoring and threat-detection processes and work with our internal information technology and audit teams.
+Added: Additionally, all employees receive security training upon hiring, annual refresher training for all employees, and phishing exercises to raise employee awareness.
+Added: Our cybersecurity program is led by our Chief Information Security Officer who has served in this capacity for 8 years and brings an additional 16 years of experience in information security program management, global cybersecurity operations and incident response.
+Added: This experience extends to the strategic design, implementation, and management of security programs tailored to mitigate risks.
+Added: His expertise is underscored by a Certified Information Systems Security Professional (CISSP) and multiple technology certifications.
Information security protocols are a part of the Company’s Information Security Policy that is reviewed and approved annually by the Company’s Board.
−Removed: The ongoing oversight of cybersecurity risk is accomplished primarily through the Information Technology Steering Committee, comprised of management, the Regulatory Risk Committee, and the Enterprise Risk Management Committee, both comprised of management and members of the Board.
−Removed: Through these committees the Company keeps abreast of significant matters of actual, threatened, or potential breaches of cybersecurity protocols, monitors the effectiveness of the information security program through regular review of key metrics and assessment reports, discusses topical events requiring consideration, and if necessary, recommends changes to the Information Security Policy for approval by the Company’s Board, which retains the ultimate responsibility for overseeing our enterprise risk management, including cybersecurity.
+Added: The ongoing oversight of cybersecurity risk is accomplished primarily through the Information Technology Steering Committee, comprised of management, the Regulatory Risk Committee, Technology Committee and the Enterprise Risk Management Committee, each comprised of management and members of the Board.
+Added: Through these committees the Company keeps abreast of significant matters of actual, threatened, or potential breaches of cybersecurity protocols, monitors the effectiveness of the
+Added: information security program through regular review of key metrics and assessment reports, discusses topical events requiring consideration, and if necessary, recommends changes to the Information Security Policy for approval by the Company’s Board, which retains the ultimate responsibility for overseeing our enterprise risk management, including cybersecurity.
In addition to regular reports from these committees, the Board receives regular reports from management on material cybersecurity risks and the Company's efforts to combat threats to its digital infrastructure.
The Company also maintains specific cyber insurance through its corporate insurance program, the adequacy of which is subject to review and oversight by the Company’s Board.
−Removed: With the increase in cyber-threat vectors and enhanced focus on
−Removed: cybersecurity, the Company and the Bank continue to monitor legislative, regulatory, and supervisory developments related thereto.
+Added: However, such insurance may not be sufficient to cover all of our potential losses and may not continue to be available to us on acceptable terms, or at all.
+Added: With the increase in cyber-threat vectors and enhanced focus on cybersecurity, the Company and the Bank continue to monitor legislative, regulatory, and supervisory developments related thereto.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.