Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
We maintain processes designed to assess and manage cybersecurity risks
on an ongoing basis, including regular and on-going education and training for employees, company-wide policies and incident response
planning. Our information security and third-party risk management programs are integrated into our overall enterprise risk management
framework and evaluate cybersecurity threats posed by internal and external factors and support daily operational functions that prevent
unauthorized access or compromise. Given the rapidly changing cybersecurity landscape, we evaluate our cyber risk management practices
regularly, which may include testing the security of our information technology infrastructure, incident response planning, employee training,
engaging third parties to conduct independent reviews and audits, scanning for internal vulnerabilities and adopting measures designed
to help our clients stay protected against cybersecurity threats.
Our programs are largely aligned to, among others, the U.S. National
Institute of Standards and Technology Cybersecurity Framework to assess, identify and manage material risks from cybersecurity threats.
We regularly assess and improve our programs to address the changing landscape of potential threats and the needs of our business. These
threats include cybersecurity attacks, ransomware attacks, denial-of-service attacks, unauthorized access and misuse, and theft of our
sensitive and confidential data.
As of the date of this Report, the Company has not identified any cybersecurity
incidents materially affecting its business strategy, results of operations, or financial condition. Recognizing cybersecurity threats
continue to evolve, the Company maintains a focus on enhancing its detection, response, and resilience capabilities. The Company cannot
assure the prevention of future cybersecurity incidents. “See Item 1A, Risk Factors—Risks Related to Technology and Cybersecurity—“We
are dependent on our information technology and telecommunications systems and third-party servicers, and systems failures or interruptions
or breaches of security could have a material adverse effect on our financial condition and results of operations, as well as cause legal
or reputational harm.”
Governance
Our Board , both directly and through its committees, is responsible
for overseeing our risk management processes. In addition, the Audit Committee’s responsibility for overseeing enterprise-wide risks
related to information security and cybersecurity, the Risk Committee in coordination with the IT Steering Committee oversees the Bank’s
cybersecurity initiatives and strives to ensure that the Bank’s information technology infrastructure aligns with strategic goals
while managing related risks, particularly cybersecurity threats. Under the oversight of our Audit Committee, the Risk Committee in coordination
with the IT Steering Committee also reviews and updates the Bank’s cybersecurity policies, evaluates information technology controls,
and monitors the performance of internal and third-party IT service providers as part of its efforts to enhance the Bank’s defense
mechanisms.
Our senior management is responsible for implementing our risk management
processes, including by assessing and managing the risks we face on a day-to-day basis, and reporting to our Board regarding our
risk management processes. Our senior management is also responsible for creating and recommending to our Board for approval appropriate
risk appetite metrics reflecting the aggregate levels and types of risk we are willing to accept in connection with the operation of our
business and pursuit of our business objectives.
In carrying out its responsibility, management provides updating reports
to the Audit Committee and/or our Board at their regularly scheduled meetings, with topics including management’s information security
efforts to prevent, detect, mitigate and remediate cybersecurity incidents, as well as trends in the information security space that impact
us or our industry. Our cybersecurity incident response plan requires management to report timely to the Audit Committee cybersecurity
incidents that have the potential to materially impact our business strategy, results of operations or financial condition for our Audit
Committee to evaluate the nature, scope, timing and impact to us of such incidents.
One member of our Audit Committee previously served in a senior
executive role as chief operating officer in the financial services industry. Through this role he developed experience in
overseeing operational risk management and information technology-related operations.
49