Unresolved Staff Comments
+Added: Not applicable.
Cybersecurity
5 unchanged sentences
In addition to regular risk assessments, we rely on independent assessments, audits, and cybersecurity feeds from vendors, including directly into patch and vulnerability management tools.
−Removed: Our processes and practices are reviewed by audits, regulators, and independent reviews of information security and cybersecurity practices and processes carried out by professional services organizations retained by us against industry requirements, such as the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbooks, and the FFIEC Cybersecurity Assessment Tool.
+Added: Our processes and practices are reviewed by regulators, and independent reviews of information security and cybersecurity practices and processes carried out by professional services organizations retained by us against industry requirements, such as the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbooks, and the FFIEC Cybersecurity Assessment Tool.
These frameworks also provide guidance that we leverage for overseeing and identifying cybersecurity threats associated with the use of third-party service providers.
21 unchanged sentences
Our Information Security Program is managed by a dedicated Chief Information Security Officer (“CISO”), who leads our Information Security team responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes.
−Removed: Our CISO holds a BSc degree in the combined studies of Computer Science & History of Science from Herriot-Watt University and a graduate of the Carnegie Mellon University’s Heinz College of Information Systems and Public Policy + Software Engineering Institute’s Chief Risk Officer Executive Education and Certificate Program.
−Removed: He holds the following professional certifications from the Information Systems Audit and Control Association:
−Removed: Certified Information Systems Auditor (CISA), Certified in the Governance of Enterprise IT (CGEIT), and Certified in Risk and Information Systems Control (CRISC).
−Removed: Additionally, he has more than 20 years of experience in financial services, including management experience with Globally Systemically Important Banks, as well as experience in cybersecurity, information security & information technology risk management, governance, risk, and compliance.
The CISO provides periodic reports to the executive risk management committee and the board-level risk committees of the Company and the Bank, as well as the cross-functional management steering committee that oversees the information security and information technology programs.
These reports address key cybersecurity topics, including the implementation and operation of preventative controls and the detection, mitigation and remediation of cybersecurity incidents.
−Removed: Our CISO also provides reports to our Chief Executive Officer and other members of our senior management, as appropriate.
+Added: Our CISO also provides reports to our Chief Risk Officer and other members of our senior management, as appropriate.
The Chief Risk Officer and the board-level risk committees of the Company and the Bank report to the full board of directors on key cybersecurity risk management topics, as appropriate.
+Added: Our CISO holds the following professional certifications:
+Added: Cybersecurity Certificate course at the University of California, Irvine, Certified Technology Business Management Executive Certification, and Society of Information Management – Regional Leadership Foundation Certification.
+Added: Additionally, he is a U.S.
+Added: Army veteran and has more than 25 years of experience in information security, technology leadership, and enterprise risk management across highly regulated industries.
+Added: He has held senior security and technology leadership roles, including CISO positions, where he led large‑scale security transformations, modernized control environments, and embedded risk‑based governance into enterprise operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.