5 unchanged sentences
Management Role and Board Oversight .
−Removed: ● The cybersecurity program is overseen by the Chief Information Security Officer (“CISO”) reporting to the Chief Risk Officer (“CRO”);
−Removed: the Enterprise Risk Management Committee , which consists of the CEO, CFO, and CTO among others;
+Added: ● The cybersecurity program is overseen by the CISO reporting to the Chief Risk Officer (“CRO”);
+Added: the Enterprise Risk Management Committee , which consists of the Chief Executive Officer, Chief Operating Officer/ Chief Financial Officer, and Chief Technology Officer, among others;
and the Enterprise Risk Committee of the Board of Directors, which consists of three independent directors .
2 unchanged sentences
The CISO’s extensive knowledge and experience in the cybersecurity field are critical to executing our cybersecurity program.
−Removed: Our CISO oversees proactive initiatives, remediation plans
−Removed: of known risks, compliance with regulations and standards, Disaster Recovery, Business Continuity, and Incident Response efforts.
+Added: Our CISO oversees proactive initiatives, remediation plans of known risks, compliance with regulations and standards, Disaster Recovery, Business Continuity, and Incident Response efforts.
Additionally, the Bank’s Risk Management function is led by the CRO, who has extensive experience in risk management and audit .
1 unchanged sentence
Our Incident Response Team is chaired by our CISO and is comprised of executive management and designated managers throughout the organization.
−Removed: The purpose of the Incident Response Plan is to manage Information Security, and related incidents, efficiently and effectively to minimize loss and destruction, mitigate weaknesses, restore services, and notify customers, as required by state law, comply with regulatory requirements, and any third-party contractual obligations.
+Added: The purpose of the Incident Response Plan is to manage Information
+Added: Security, and related incidents, efficiently and effectively to minimize loss and destruction, mitigate weaknesses, restore services, and notify customers, as required by state law, comply with regulatory requirements, and any third-party contractual obligations.
● The CISO and CRO play a pivotal role in informing the Board of all cybersecurity risks.
20 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.