2 unchanged sentences
Cybersecurity
−Removed: The federal bank regulatory agencies have adopted guidelines for establishing information security standards and cybersecurity programs for implementing safeguards under the supervision of a financial institution’s board of directors.
+Added: The federal bank regulatory agencies have guidelines establishing information security standards and cybersecurity programs for implementing safeguards under the supervision of a financial institution’s board of directors.
These guidelines, along with related regulatory materials, increasingly focus on risk management and processes related to information technology and the use of third parties in the provision of financial products and services.
−Removed: The federal bank regulatory agencies expect financial institutions to establish lines of defense and to ensure that their risk management processes address the risk posed by compromised customer credentials, and also expect financial institutions to maintain sufficient business continuity planning processes to ensure rapid recovery, resumption, and maintenance of the institution’s operations after a cyberattack.
−Removed: If the Company or the Bank fails to meet the expectations set forth in this regulatory guidance, the Company or the Bank could be subject to various regulatory actions and any remediation efforts may require significant resources of the Company or the Bank.
−Removed: On November 18, 2021, the federal bank regulatory agencies issued a final rule, with compliance required as of May 1, 2022, imposing new notification requirements for cybersecurity incidents.
−Removed: The rule requires financial institutions to notify their primary federal regulator as soon as possible and no later than 36 hours after the institution determines that a cybersecurity incident has occurred that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the institution’s:
+Added: The federal bank regulatory agencies expect financial institutions to establish lines of defense and to ensure that their risk management processes address the risk posed by compromised customer credentials.
+Added: The federal bank regulatory agencies also expect financial institutions to maintain sufficient business continuity planning processes to ensure rapid recovery, resumption, and maintenance of the institution’s operations after a cyberattack.
+Added: The federal bank regulatory agencies require financial institutions to notify their primary federal regulator as soon as possible, and no later than 36 hours after the institution determines that a cybersecurity incident has occurred that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the institution’s:
(i) ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business, (ii) business line(s), including associated operations, services, functions, and support, that upon failure would result in a material loss of revenue, profit, or franchise value, or (iii) operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States.
−Removed: To date, we have not experienced cybersecurity incidents that we believe has, or is reasonably likely to, materially affect our business operations, strategy, or financial condition.
+Added: SEC rules also require disclosure of material cybersecurity incidents.
+Added: The Bank maintains a documented process to evaluate the materiality of cybersecurity incidents for purposes of SEC and banking‑regulator reporting.
+Added: This process considers potential impacts on financial results, operations, customer harm, legal and regulatory exposure, and investor decision‑making, and supports timely reporting obligations under applicable rules.
+Added: To date, we have not experienced a cybersecurity incident that we believe has, or is reasonably likely to, materially affect our business, operations, strategy, or financial condition.
However, we continually assess the potential impact of cybersecurity threats, ensuring that any incident is evaluated for materiality in relation to our business strategy, operational results, and financial condition.
Cybersecurity risk is a key factor in assessing the Company’s overall operational and regulatory risk and is a component of our overall information security protocols.
−Removed: The Company maintains a formal information security management program designed, in part, to identify risks to sensitive information, protect that information, detect threats and events, and maintain an appropriate response and recovery capability to help ensure resilience against information security incidents.
−Removed: The program includes, among other things, 24/7 monitoring of all critical infrastructure, active threat hunting, and endpoint Extended Detection and Response (“XDR”) capabilities, to assist with prevention of attacks from advanced adversaries.
−Removed: This monitoring and response is reinforced with regular vulnerability scanning/remediation and penetration testing and includes an annual risk assessment that looks to threats on the Company’s own information technology platforms, and also assesses potential threats, owing to our use of third-party information technology platforms and services.
−Removed: As part of these processes, we engage well-established and professional third-party information security consultants to aid in the assessment and development of our monitoring and threat-detection processes and work with our internal information technology and audit teams.
−Removed: Additionally, all employees receive security training upon hiring, annual refresher training for all employees, and phishing exercises to raise employee awareness.
−Removed: Our cybersecurity program is led by our Chief Information Security Officer who has served in this capacity for 8 years and brings an additional 16 years of experience in information security program management, global cybersecurity operations and incident response.
−Removed: This experience extends to the strategic design, implementation, and management of security programs tailored to mitigate risks.
−Removed: His expertise is underscored by a Certified Information Systems Security Professional (CISSP) and multiple technology certifications.
+Added: The Company maintains a formal, Board‑approved Cybersecurity and Information Security Program aligned with the Federal Financial Institution Examination Council Information Security Handbook, the National Institute of Standards and Technology Cybersecurity Framework, and the GLB Act Safeguards Rule.
+Added: This program is designed to identify risks to sensitive information, protect that information, detect threats and events, and maintain a robust response and recovery capability to ensure resilience against cybersecurity incidents.
+Added: Our processes for assessing, identifying, and managing material cybersecurity risks include:
+Added: enterprise‑wide risk assessments and control testing;
+Added: 24/7 monitoring of critical infrastructure;
+Added: active threat hunting;
+Added: endpoint Extended Detection and Response (XDR);
+Added: continuous security monitoring and alerting;
+Added: vulnerability scanning, remediation, and penetration testing;
+Added: identity and access management with multi‑factor authentication;
+Added: data‑loss prevention and information classification;
+Added: oversight of third‑party and vendor information security practices;
+Added: and a documented Incident Response Plan governing detection, containment, investigation, recovery, and post‑incident review.
+Added: These processes apply across our on‑premises and cloud environments, critical business functions, customer data, and third‑party service providers.
+Added: To support these activities, the Bank engages established third‑party information security consultants to assist in monitoring, threat detection, and program development, and collaborates closely with internal information technology and audit teams.
+Added: All employees receive security training at onboarding, annual refresher training, and regular phishing simulations to strengthen awareness and reduce human‑related risk.
+Added: The Bank’s cybersecurity program is led by the Chief Information Security Officer , who has served in this capacity for 10 years and possesses an additional 18 years of experience in information security program management, global cybersecurity operations, and incident response.
+Added: His expertise includes the strategic design, implementation, and management of security programs tailored to mitigate emerging risks and is supported by a Certified Information Systems Security Professional (CISSP) credential and multiple technology certifications.
Information security protocols are a part of the Company’s Information Security Policy that is reviewed and approved annually by the Company’s Board.
The ongoing oversight of cybersecurity risk is accomplished primarily through the Information Technology Steering Committee, comprised of management, the Regulatory Risk Committee, Technology Committee and the Enterprise Risk Management Committee, each comprised of management and members of the Board.
−Removed: Through these committees the Company keeps abreast of significant matters of actual, threatened, or potential breaches of cybersecurity protocols, monitors the effectiveness of the
−Removed: information security program through regular review of key metrics and assessment reports, discusses topical events requiring consideration, and if necessary, recommends changes to the Information Security Policy for approval by the Company’s Board, which retains the ultimate responsibility for overseeing our enterprise risk management, including cybersecurity.
+Added: Through these committees the Company keeps abreast of significant matters of actual, threatened, or potential breaches of cybersecurity protocols, monitors the effectiveness of the information security program through regular review of key metrics and assessment reports, discusses topical events requiring consideration, and if necessary, recommends changes to the Information Security Policy for approval by the Company’s Board, which retains the ultimate responsibility for overseeing our enterprise risk management, including cybersecurity.
In addition to regular reports from these committees, the Board receives regular reports from management on material cybersecurity risks and the Company's efforts to combat threats to its digital infrastructure.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.