4 unchanged sentences
The program is led by Busey’s Chief Information Security Officer (“CISO”) .
−Removed: Busey’s CISO has been in the role since September 2020 and has over 15 years of experience across external and internal audit, technology risk management, and cybersecurity matters, spanning various industries primarily within the financial services sector, but also including healthcare, technology, consumer products, and manufacturing for both regional and multinational corporations.
+Added: Busey’s CISO has been in the role since September 2020 and has over 15 years of experience across external and internal audit, technology risk management, and cybersecurity matters, primarily within the financial services sector, and also including additional industries such as healthcare, technology, consumer products, and manufacturing for both regional and multinational corporations.
Busey’s cyber security risk management program is a key part of the Company’s overall risk management system, which is administered by the Chief Risk Officer.
2 unchanged sentences
• Establishing an internal cybersecurity team that is responsible for conducting regular assessments of Busey’s information systems, existing controls, vulnerabilities, and potential improvements;
−Removed: First Busey Corporation (BUSE) | 2024 — 46
• Employing continuous monitoring tools that can detect and help respond to cybersecurity threats in real-time;
1 unchanged sentence
• Ongoing monitoring and assessment of third-party vendors' cybersecurity practices, including regular audits, compliance checks, and incident reporting requirements;
+Added: First Busey Corporation (BUSE) | 2025 — 48
• Engaging third-party cybersecurity consultants, who conduct periodic penetration testing, vulnerability assessments, and other procedures to identify potential weaknesses in Busey’s systems and processes;
7 unchanged sentences
Busey’s board of directors , as a whole and through its Enterprise Risk Committee (the “Risk Committee”), is responsible for the oversight of risk management.
−Removed: In that role, Busey’s board of directors and Risk Committee, with support from Busey’s cybersecurity advisors, are responsible for ensuring that the risk management processes developed and implemented by management are adequate and functioning as designed.
+Added: In that role, Busey’s board of directors and its Risk Committee, with support from Busey’s cybersecurity advisors, are responsible for ensuring that the risk management processes developed and implemented by management are adequate and functioning as designed.
To carry out those duties, both the board of directors and the Risk Committee receive quarterly reports from Busey’s management team regarding cybersecurity risks, and Busey’s efforts to prevent, detect, mitigate, and remediate any cybersecurity incidents.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.