4 unchanged sentences
Cybersecurity is a critical component of this program, given the increasing reliance on technology and potential of cyber threats.
−Removed: Our Vice President, Technology is primarily responsible for this cybersecurity component and is a key member of the risk management organization, reporting directly to the President and Chief Executive Officer, as discussed below, periodically to our board of directors.
+Added: Our fully managed IT partner, Entrusted Technology Solutions, along with the IT Manager are primarily responsible for this cybersecurity component and the IT Manager is a key member of the risk management organization, reporting directly to the President and Chief Executive Officer, as discussed below, periodically to our board of directors.
Our objective for managing cybersecurity risk is to avoid or minimize the impacts of external threat events or other efforts to penetrate, disrupt or misuse our system or information.
−Removed: The structure of our information security
−Removed: program is designed around the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, regulatory guidance, and other industry standards.
+Added: The structure of our information security program is designed around the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, regulatory guidance, and other industry standards.
In addition, we leverage certain industry and government associations, third-party benchmarking, audits, and threat intelligence fees to facilitate and promote program effectiveness.
−Removed: Our Vice President, Technology reports directly to our Chief Executive Officer, regularly collaborate with peer banks, industry groups, and policymakers to discuss cybersecurity trends and issues and identify best practices.
+Added: Our IT Manager reports directly to our Chief Executive Officer, regularly collaborate with peer banks, industry groups, and policymakers to discuss cybersecurity trends and issues and identify best practices.
The information security program is reviewed by such personnel with the goal of addressing changing threats and conditions.
4 unchanged sentences
We engage in regular assessments of our infrastructure, software systems, and network architecture, using third-party cybersecurity experts .
−Removed: We also maintain a third-party risk management program designed to identify, assess, and manage risks, including cybersecurity risks, associated with external service providers and our supply chain.
+Added: We also maintain a third-party risk management program designed to identify, assess, and
+Added: manage risks, including cybersecurity risks, associated with external service providers and our supply chain.
We also actively monitor our email gateways for malicious phishing email campaigns and monitor remote connections.
1 unchanged sentence
We maintain an Incident Response Plan that provides a documented framework for responding to actual or potential cybersecurity incidents, including timely notification of and escalation to the appropriate Board-approved management committees, as discussed further below, and to the board of directors.
−Removed: The Incident Response Plan is coordinated through the Vice President, Technology and key members of management are embedded into the Plan by its design.
+Added: The Incident Response Plan is coordinated through the IT Manager and the Risk Management Committee.
+Added: Key members of management are embedded into the Plan by its design.
The Incident Response Plan facilitates coordination across multiple parts of our organization and is evaluated at least annually.
1 unchanged sentence
Our internal systems, processes, and controls are designed to mitigate loss from cyber-attacks and, while we have experienced cybersecurity incidents in the past, risks from cybersecurity threats have not materially affected our company.
−Removed: Our Vice President , Technology is accountable for managing our enterprise information security function and delivering our information security program.
+Added: Our fully managed IT partner, along with the IT Manager , are accountable for managing our enterprise information security function and delivering our information security program.
The responsibilities of this position include cybersecurity risk assessment, defense operations, incident response, vulnerability assessment, threat intelligence, identity access governance, third-party risk management, and business resilience.
4 unchanged sentences
The board of directors is responsible for overseeing our information security and technology programs, including management’s actions to identify, assess, mitigate, and remediate or prevent material cybersecurity issues and risks.
−Removed: Our Vice President , Technology provide quarterly reports to the board of directors regarding the information security program and the technology program, key enterprise cybersecurity initiatives, and other matters relating to cybersecurity processes.
−Removed: The board of directors reviews and approves our information security and technology budgets and strategies annually.
−Removed: Additionally, the board of directors reviews our cybersecurity risk profile on a quarterly basis.
+Added: Our I T Manager, with input from the fully managed IT partner, provide bi-monthly reports to the Risk Management Committee and ultimately to the board of directors regarding the information security program and the technology program, key enterprise cybersecurity initiatives, and other matters relating to cybersecurity processes.
+Added: The board of directors’ reviews and approves our information security policy, IT risk assessment, technology budgets and strategies annually.
We conduct our business through our headquarters in Kaukauna and branches in Appleton, Freedom, and Kimberly, Wisconsin.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.