3 unchanged sentences
As described below, we have risk management and governance practices and processes designed to address these risks.
+Added: Eagle Bancorp, Inc 2025 Form 10-K
+Added: Cybersecurity
The Company has established an enterprise risk management framework that outlines the processes and procedures the Company uses to identify, assess, mitigate and monitor the risks faced by the Company, including cybersecurity risk.
3 unchanged sentences
The Board is responsible for the oversight of cybersecurity risk management, as well as the selection of a Chief Information Security Officer ("CISO"), the management official responsible for administering and executing the information security program.
−Removed: The Board’s Technology Oversight Committee (the “TOC”) assists the Board in its oversight of the information security program.
+Added: The Board’s Technology Oversight Committee ("TOC") assists the Board in its oversight of the information security program.
The TOC reviews information security metrics, oversees significant instances of non-compliance with the information security policy and monitors remediation of those instances, and reviews the appointment of the CISO for recommendation to the Board.
−Removed: At the management level, the Enterprise Risk Management Committee (the “ERMC”) is primarily responsible for cybersecurity risk management.
+Added: At the management level, the Enterprise Risk Management Committee ("ERMC") is primarily responsible for cybersecurity risk management.
As it pertains to the information security program, the ERMC assesses and monitors information security risks and approves the information security policy on at least an annual basis.
−Removed: Certain instances of non-compliance with the information security policy are escalated to the EMRC, which may further escalate to the TOC as appropriate.
+Added: Certain instances of non-compliance with the information security policy are escalated to the ERMC, which may further escalate to the TOC as appropriate.
Once escalated to a committee, the committee is responsible for overseeing related remediation.
11 unchanged sentences
The Information Security Policy is also approved by the TOC on an annual basis.
−Removed: Table o f Contents
The Company employs third parties in certain aspects of its information security and cybersecurity risk management.
For example, we utilize third parties to conduct certain security operations and maintain certain information security infrastructure.
−Removed: We have adopted a Third Party Risk Management Policy, which addresses the identification, measurement, monitoring, and management of our third-party service provider relationships, including those related to information security.
+Added: We have a Third Party Risk Management Policy, which addresses the identification, measurement, monitoring, and management of our third-party service provider relationships, including those related to information security.
The Director of Third-Party Risk Management, along with the CISO, assess and monitor information risks posed by third parties and any non-compliance with the controls created to address such risks.
2 unchanged sentences
However, the risk management and governance processes described above may not be sufficient to prevent cybersecurity incidents, and we could incur substantial costs and suffer other negative consequences from cybersecurity incidents.
−Removed: See “Part 1, Item IA.
−Removed: – Risk Factors” for more information on the cybersecurity risks facing the Company.
+Added: See "Risk Factors" for more information on the cybersecurity risks facing the Company.
+Added: Eagle Bancorp, Inc 2025 Form 10-K
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.