4 unchanged sentences
The Company adheres to cybersecurity industry best practices such as the National Institute of Standards and Technology cybersecurity framework and Federal Financial Institutions Examinations Council ("FFIEC") guidance.
−Removed: The Company conducted a NIST cybersecurity framework version 1 to version 2 gap analysis and is in the process of updating controls to adhere to the newest version.
+Added: The Company completed its transition from NIST cybersecurity framework version 1.1 to version 2.0 and updated its controls to align with the current version.
Company management has integrated its processes for assessing, identifying, and managing material risks from cybersecurity threats into the Company’s overall risk management program, including regularly conducting risk assessments and gap analyses in order to identify and prioritize cybersecurity threats and vulnerabilities across our entire digital estate which is comprised of our IT infrastructure as well cloud-based applications and storage.
5 unchanged sentences
We also maintain business continuity, crisis management, and disaster recovery plans to ensure the continued operation of critical business functions in the event of a major disruption, including a cyberattack, which are tested regularly through tabletop exercises, simulations, parallel testing, and functional testing.
−Removed: The Company adheres to a continuous improvement philosophy in regard to cybersecurity and leverages external experts, consultants, auditors, and assessors on a regular basis to complement the internal staff in identifying and remediating any gaps in the Company’s cybersecurity program.
+Added: The Company adheres to a continuous improvement philosophy regarding cybersecurity and leverages external experts, consultants, auditors, and assessors on a regular basis to complement the internal staff in identifying and remediating any gaps in the Company’s cybersecurity program.
The Company has a well-defined and mature vendor management program that includes controls to address third -party cybersecurity risks throughout the vendor management lifecycle.
2 unchanged sentences
The Information Security Officer ("ISO") is responsible for assessing and managing material risks from cybersecurity threats, with a dedicated staff of internal and external information security professionals.
−Removed: The ISO is a Systems Security Certified Practitioner and Certified Information Systems Security Professional with over 12 years of education, training and experience managing technology and cybersecurity risks, including eight years of experience in the banking industry specifically.
+Added: The ISO is a Systems Security Certified Practitioner and Certified Information Systems Security Professional with over 13 years of education, training and experience managing technology and cybersecurity risks, including nine years of experience in the banking industry specifically.
The ISO regularly updates executive and senior management, including the Bank's Enterprise Risk Management Committee, as well as the Board Audit Committee on cybersecurity risks and mitigation strategies.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.