3 unchanged sentences
Financial institutions are expected to comply with such guidance and standards and to accordingly develop appropriate security controls and risk management processes.
−Removed: If we fail to observe such regulatory guidance or standards, we could be
−Removed: subject to various regulatory sanctions, including financial penalties.
+Added: If we fail to observe such regulatory guidance or standards, we could be subject
+Added: to various regulatory sanctions, including financial penalties.
In 2023, the SEC issued a final rule that requires disclosure of material cybersecurity incidents, as well as cybersecurity risk management, strategy and governance.
−Removed: this rule, banking organizations that are SEC registrants must generally disclose information about a material cybersecurity incident within four business days of determining it is material with periodic updates as to the status of the incident
−Removed: in subsequent filings as necessary.
+Added: Under this rule,
+Added: banking organizations that are SEC registrants must generally disclose information about a material cybersecurity incident within four business days of determining it is material with periodic updates as to the status of the incident in subsequent
+Added: filings as necessary.
Under a final rule adopted by federal banking agencies in 2021, banking organizations are required to notify their primary banking regulator within 36 hours of determining that a “computer-security incident” has
−Removed: materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the banking organization’s ability to carry out banking operations or deliver banking products and services to a material portion of its customer base,
−Removed: its businesses and operations that would result in material loss, or its operations that would impact the stability of the United States.
−Removed: The federal banking agencies have also adopted guidelines for establishing information security standards
−Removed: and cybersecurity programs for implementing safeguards under the supervision of the Board of Directors.
−Removed: These guidelines, along with related regulatory materials, increasingly focus on risk management and processes related to information
−Removed: technology and the use of third parties in the provision of financial services.
−Removed: Moreover, recent cyberattacks against banks and other financial institutions that resulted in unauthorized access to confidential customer information have prompted
−Removed: the federal banking regulators to issue more extensive guidance on cybersecurity risk management.
−Removed: Among other things, financial institutions are expected to design multiple layers of security controls to establish lines of defense and ensure that
−Removed: their risk management processes address the risks posed by compromised customer credentials, including security measures to authenticate customers accessing internet-based services.
−Removed: A financial institution also should have a robust business
−Removed: continuity program to recover from a cyberattack and procedures for monitoring the security of third-party service providers that may have access to nonpublic data at the institution.
+Added: materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the banking organization’s ability to carry out banking operations or deliver banking products and services to a material portion of its customer base, its
+Added: businesses and operations that would result in material loss, or its operations that would impact the stability of the United States.
+Added: The federal banking agencies have also adopted guidelines for establishing information security standards and
+Added: cybersecurity programs for implementing safeguards under the supervision of the Board of Directors.
+Added: These guidelines, along with related regulatory materials, increasingly focus on risk management and processes related to information technology and
+Added: the use of third parties in the provision of financial services.
+Added: Moreover, recent cyberattacks against banks and other financial institutions that resulted in unauthorized access to confidential customer information have prompted the federal
+Added: banking regulators to issue more extensive guidance on cybersecurity risk management.
+Added: Among other things, financial institutions are expected to design multiple layers of security controls to establish lines of defense and ensure that their risk
+Added: management processes address the risks posed by compromised customer credentials, including security measures to authenticate customers accessing internet-based services.
+Added: A financial institution also should have a robust business continuity program
+Added: to recover from a cyberattack and procedures for monitoring the security of third-party service providers that may have access to nonpublic data at the institution.
State regulators have also been increasingly active in implementing privacy and cybersecurity standards and regulations.
3 unchanged sentences
continually monitoring developments in the states in which our customers are located.
−Removed: Risks and exposures related to cybersecurity attacks, including litigation and enforcement risks, are expected to be elevated for the foreseeable future due to the rapidly evolving nature and sophistication of
−Removed: these threats, as well as due to the expanding use of Internet banking, mobile banking and other technology-based products and services by us and our customers.
+Added: Risks and exposures related to cybersecurity attacks, including litigation and enforcement risks, are expected to be elevated for the foreseeable future due to the rapidly evolving nature and sophistication of these
+Added: threats, as well as due to the expanding use of Internet banking, mobile banking and other technology-based products and services by us and our customers.
+Added: Implementation of certain new technologies, such as those related to artificial intelligence,
+Added: automation and algorithms, also may have unintended consequences, including fraud or cybersecurity risk, due to their limitations, potential manipulation, or our failure to use them effectively.
“Risk Factors” for a further discussion of risks related to cybersecurity.
3 unchanged sentences
Cybersecurity attacks and other security breaches can have material adverse impacts on our business.
−Removed: While no organization can eliminate cybersecurity risk entirely,
−Removed: we devote significant resources to our security program that we believe is reasonably designed to mitigate our cybersecurity and information technology risk.
−Removed: The Bank devotes significant resources and management focus to ensuring the integrity of
−Removed: our systems through information security and business continuity programs.
−Removed: However, our facilities and systems, and those of third-party service providers, are still vulnerable to external or internal security breaches, acts of vandalism,
−Removed: computer viruses, misplaced or lost data, programming or human errors, or other similar events.
−Removed: The Company seeks to address cybersecurity risks by implementing a governance structure and processes to assess, identify, manage, remediate, and
−Removed: report cybersecurity risks.
+Added: While no organization can eliminate cybersecurity risk entirely, we
+Added: devote significant resources to our security program that we believe is reasonably designed to mitigate our cybersecurity and information technology risk.
+Added: The Bank devotes significant resources and management focus to ensuring the integrity of our
+Added: systems through information security and business continuity programs.
+Added: However, our facilities and systems, and those of third-party service providers, are still vulnerable to external or internal security breaches, acts of vandalism, computer
+Added: viruses, misplaced or lost data, programming or human errors, or other similar events.
+Added: The Company seeks to address cybersecurity risks by implementing a governance structure and processes to assess, identify, manage, remediate, and report
+Added: cybersecurity risks.
Identifying and assessing cybersecurity risks is integrated into our overall risk management program and processes.
−Removed: Cybersecurity risks related to our business, technical operations, data, and privacy, along with cybersecurity risk-related compliance issues, are identified and addressed through a framework consisting of
−Removed: third-party assessments, internal information technology audits, information security assessments, and risk and compliance reviews.
−Removed: We conduct regular privacy and cybersecurity reviews of systems, audit applicable data and information policies,
−Removed: perform penetration and vulnerability testing using third-party tools to test security controls, perform regular training and assessments for the Board of Directors and employees, monitor emerging data privacy and information security laws and
−Removed: regulations, and implement applicable changes to improve our overall security posture.
−Removed: We regularly engage third-party auditors to
−Removed: assess our cybersecurity program and compliance with all applicable “best practices” and regulations.
−Removed: The Company adjusts its information security policies, standards, processes and practices as necessary based on the information provided by
−Removed: these assessments and to remediate material identified vulnerabilities.
−Removed: have in place a robust incident response process that helps ensure our preparedness for a cybersecurity incident including our ability to detect, analyze, contain, remediate, and recover from a security incident as well as conduct post-incident
−Removed: analysis to avoid future incidents.
+Added: Cybersecurity risks related to our business, technical operations, data, and privacy, along with cybersecurity risk-related compliance issues, are identified and addressed through a framework consisting of information security risk assessments, third-party assessments, internal information technology audits, and compliance reviews.
+Added: We conduct regular privacy and cybersecurity reviews of systems, audit applicable data and information policies, perform penetration and vulnerability testing using third-party tools to test security controls, perform regular training and assessments for the Board of Directors and all employees, monitor emerging data privacy and information security laws and regulations, and implement applicable changes to improve our overall security posture.
+Added: We regularly engage third-party auditors to assess our cybersecurity program and compliance with all applicable “best practices” and regulations.
+Added: We adjust our information security policies, standards, processes and practices as necessary based on the information provided by these assessments and remediate identified vulnerabilities.
+Added: We have in place a robust incident response process that helps ensure our preparedness for a cybersecurity incident including our ability to detect, analyze, contain, remediate, and recover from a security incident as well as conduct post-incident analysis to avoid future incidents.
Incident response process activities are overseen by cross-functional leadership in Risk Management, Operations, Information Security, Compliance, and Information Systems.
−Removed: Security events and incidents are
−Removed: evaluated, ranked by severity, and prioritized for response and remediation.
+Added: Security events and incidents are evaluated, ranked by severity, and prioritized for response and remediation.
Incidents are evaluated to determine materiality and operational, business, and overall privacy impacts.
−Removed: We conduct regular exercises and drills to simulate
−Removed: responses to various cybersecurity incidents.
−Removed: The incident response team, including management, coordinates with technical and business stakeholders to further analyze risks and enhance detection, mitigation, and remediation strategies
−Removed: incorporated in the incident response program.
+Added: We conduct regular exercises and drills to simulate responses to various cybersecurity incidents.
+Added: The incident response team, including management, coordinates with technical and business stakeholders to further analyze risks and enhance detection, mitigation, and remediation strategies incorporated in the incident response program.
Our risk management program regularly assesses third-party risks (inclusive of fourth-party risk) by conducting activities to identify and mitigate risks from third parties (e.g., vendors, suppliers, and other business partners).
−Removed: Cybersecurity risks are evaluated when selecting and managing applicable third-parties that handle or process employee, business, or customer data, and a review process that includes due diligence over a third-party’s information security and technology control environment is conducted at onboarding and periodically throughout the lifecycle of the relationship to ensure that systems of third- parties meet certain security baseline requirements.
−Removed: We maintain procedures to respond to, manage and mitigate third-party cybersecurity events and vulnerabilities when identified.
−Removed: Cybersecurity Gover nance
−Removed: the importance of information security, privacy and data protection to our stakeholders, cybersecurity is a critical part of our risk management program and a key focus area for our Board and Executive Management.
−Removed: The Board of Directors oversees management’s processes for identifying and mitigating risks,
−Removed: including cybersecurity risks, to help manage our risk exposure to meet our strategic objectives.
−Removed: Executive Management and our Information Security Officer (“ISO”) regularly brief the Board of Directors on our cybersecurity and
−Removed: information security posture and ensure the Board is apprised of emerging risks and cybersecurity incidents deemed to have a direct or indirect business impact.
−Removed: The Audit & Risk Committee meets on a
−Removed: monthly basis to receive updates from management, including leaders from Information Systems, Information Security, Risk Management, and Compliance, on matters of cybersecurity risks and mitigation initiatives.
−Removed: The leaders from
−Removed: these areas each bring over 20 years of professional experience and certifications in information technology, information security, information systems audit, compliance, and risk management.
−Removed: This group of leaders provides updates on existing and new cybersecurity risks, status
−Removed: updates on how management is addressing or mitigating cyber risks and cybersecurity or privacy incidents, and progress on key cybersecurity initiatives.
+Added: Cybersecurity risks are evaluated when selecting and managing applicable third-parties that handle or process employee, business, or customer data.
+Added: Our review process includes performing due diligence over a third-party’s information security and technology control environment.
+Added: This review is conducted when onboarding third parties and periodically throughout the lifecycle of the relationship to ensure that third-party systems meet our security baseline requirements.
+Added: We maintain procedures to monitor, respond to, manage and mitigate third-party cybersecurity events and vulnerabilities when identified.
+Added: Cybersecurity Governance
+Added: Given the importance of information security, privacy and data protection to our stakeholders, cybersecurity is a critical part of our risk management program and a key focus area for our Board and Executive Management.
+Added: The Board of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help manage our risk exposure to meet our strategic objectives.
+Added: Executive Management and our Information Security Officer (“ISO”) regularly brief the Board of Directors on our cybersecurity and information security posture and ensure the Board is apprised of emerging risks and cybersecurity incidents deemed to have a direct or indirect business impact.
+Added: The Audit & Risk Committee meets on a monthly basis to receive updates from management, including leaders from Information Systems, Information Security, Risk Management, and Compliance, on matters of cybersecurity risks and mitigation initiatives.
+Added: This group of leaders provides updates on existing and new cybersecurity risks, status updates on how management is addressing or mitigating cyber risks and cybersecurity or privacy incidents, and progress on key cybersecurity initiatives.
+Added: The Cybersecurity and Technology Committee meets on a quarterly basis and is composed of three members of the Board of Directors, the Enterprise Risk Officer, the ISO, and the Chief Information
+Added: Officer (“CIO”).
+Added: The Committee is responsible for overseeing the Bank’s overall cybersecurity and technology posture.
+Added: The Committee meets quarterly to review progress on key information security and technology initiatives, monitor program
+Added: performance, and discuss emerging threats and technology-related matters.
The Electronic Data Processing (“EDP”) Steering Committee is a senior management level committee that meets at least quarterly to discuss a variety of information technology and cybersecurity matters, which form the basis for providing status reports to the Board of Directors.
−Removed: The committee is responsible for monitoring all Information Systems-related projects and initiatives, facilitating the
−Removed: remediation of issues that could adversely impact the ability of the Information Systems Department to perform its function, and allocating available resources to the highest priority projects and initiatives.
−Removed: The Chief Administrative Officer
−Removed: chairs the EDP Steering Committee and members of Executive Management, Information Systems, Information Security, Treasury Management, Retail and Wholesale Banking departments are represented in the meetings.
−Removed: In addition to project management
−Removed: guidance, the committee provides oversight of and direction for the Information Security Program, monitors cybersecurity risks, and helps ensure prompt remediation of cybersecurity incidents.
+Added: The committee is responsible for monitoring all Information Systems-related projects and initiatives, facilitating the remediation of issues that could adversely impact the ability of the Information Systems Department to perform its function, and allocating available resources to the highest priority projects and initiatives.
+Added: The Chief Administrative Officer chairs the EDP Steering Committee and members of Executive Management, Information Systems, Information Security, Treasury Management, Retail and Wholesale Banking departments are represented in the meetings.
+Added: In addition to project management guidance, the committee provides oversight of and direction for the Information Security Program, monitors cybersecurity risks, and helps ensure prompt remediation of cybersecurity incidents.
In 2025, we did not identify any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition .
−Removed: however, cybersecurity threats are pervasive.
−Removed: Despite the capabilities, processes and security measures we employ that we believe are
−Removed: designed to detect, reduce, and mitigate the risk of cybersecurity incidents, we may not be aware of all vulnerabilities or might not accurately assess the risks of incidents, and such preventative measures cannot provide absolute security and
−Removed: may not be sufficient in all circumstances or mitigate all potential risks.
+Added: Despite the capabilities, processes, and security measures we employ, we may not be aware of all vulnerabilities or might not accurately assess the risks of incidents, and such preventative measures cannot provide absolute security and may not be sufficient in all circumstances or mitigate all potential risks.
Moreover, cybersecurity threats are continuously evolving, which may cause cybersecurity threats to be more difficult to detect in the future.
−Removed: See “Risk Factors - Risks
−Removed: Related to Cybersecurity and Information Technology” in Part I, Item 1A of this Form 10-K, for additional information about these and other risks related to cybersecurity and information technology.
+Added: See “Risk Factors - Risks Related to Cybersecurity and Information Technology” in Part I, Item 1A of this Form 10-K, for additional information about these and other risks related to cybersecurity and information technology.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.