7 unchanged sentences
Our Information Security (“IS”) Program consists of policies, procedures and guidelines to ensure the security, availability, and confidentiality of systems and customer information.
−Removed: The IS Program is led by our Information Security Officer (“ISO”) under the direction of the Chief Information Officer (“CIO”) and is subject to oversight by our IT Steering Committee .
+Added: The IS Program is led by our Information Security Officer (“ISO”) under the direction of the President/ Chief Operations Officer (“COO”) and is subject to oversight by our IT Steering Committee .
The IT Steering Committee is a cross-functional management committee with overall responsibilities for identifying and approving the IT Strategic plan, identifying and approving strategic technology based initiatives that improve/enhance the security posture and mitigation efforts of cybersecurity threats, monitoring of the technology infrastructure and systems, monitoring critical vendors, monitoring cybersecurity threats and issues, and conducting, reviewing, and monitoring IT based risk assessments.
20 unchanged sentences
Any gaps or improvement areas identified by routine testing are addressed in a timely manner to help improve future testing and response.
−Removed: The processes and controls related to data security are regularly tested by the IS department and Internal Audit.
−Removed: Additional internal security assessments may be performed at the request of the CISO, CIO, the Internal Auditor, Management or our Board.
+Added: The processes and controls related to data security are regularly tested by the IS team and Internal Audit.
+Added: Additional internal security assessments may be performed at the request of the ISO, CIO, the Internal Auditor, Management or our Board.
Audit and assessment results are presented to the Audit Committee of the Board, and to the IT Steering Committee.
4 unchanged sentences
Notwithstanding the strength of CSB’s defensive measures, the threat from cyber-attacks is severe, attacks are sophisticated and increasing in volume, and attackers respond rapidly to changes in defensive measures .
−Removed: While to date, CSB has not detected a significant compromise, significant data loss or any material financial losses related to cybersecurity attacks, CSB’s systems and those of its customers and third-party service providers are under constant threat and it is possible that CSB could experience a significant event in the future.
+Added: While to date, CSB has not detected a significant compromise, significant data loss or any material financial losses related to cybersecurity attacks, nor has identified any cybersecurity incidents or threats that have materially affected, or are reasonably likely to materially affect, our business strategy, results of operations, or financial condition.
+Added: CSB’s systems and those of its customers and third-party service providers are under constant threat and it is possible that CSB could experience a significant event in the future.
Risks and exposures related to cybersecurity attacks are expected to remain high for the foreseeable future due to the rapidly evolving nature and sophistication of these threats, as well as the expanding use of internet banking, mobile banking and other technology-based products and services by the Company and its customers.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.