19 unchanged sentences
In accordance with the incident response plans, cross-functional management teams assess and assign a threat level to each cybersecurity incident.
−Removed: A cybersecurity incident (or incidents, if aggregated together) assigned a critical threat level is escalated to a committee consisting of the Company’s executive and certain other officers (for such purpose, the “Critical Threat Committee”) for review.
+Added: A cybersecurity incident (or incidents, if aggregated together) assigned a critical threat level is escalated to the Board’s Risk Committee as described below in more detail.
The Company has not experienced any cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected the Company, including its business strategy, results of operations, or financial condition.
1 unchanged sentence
Risk Factors – Unauthorized disclosure of sensitive or confidential client or customer information, whether through a cyber-attack, other breach of our computer systems or otherwise, could harm our business.
−Removed: In exercising oversight over the Company’s information technology risks, including its cyber and information security program, our Board of Directors has established a Technology Committee that is led by the Company’s Chief Digital and Information Officer (“CDIO”) and is comprised of directors with technology industry backgrounds, all of the Company’s executive officers, the Company’s Information Security Officer (“ISO”) and the Company’s Chief Risk Officer.
−Removed: The Technology Committee
−Removed: receives materials on a quarterly basis to address the identification and status of information technology cybersecurity risks.
+Added: In exercising oversight over the Company’s information technology risks, including its cyber and information security program, the Company’s Enterprise Risk Management Committee (the “ERM Committee”) has established a Technology Committee that is led by the Company’s Chief Digital and Information Officer (“CDIO”) and is comprised of the Company’s executive officers, the Company’s Information Security Officer (“ISO”) and the Company’s Chief Risk Officer.
+Added: The Technology Committee receives materials on a quarterly basis to address the identification and status of information technology cybersecurity risks.
Each year, the full Board of Directors also receives a comprehensive update on the Company’s cyber and information security program.
2 unchanged sentences
Our CDIO assumed his current role in January 2026.
−Removed: Prior to that, he served as the Company’s Senior Vice President of Technology and Operations, where he lead the Company’s core processing and operations functions, and the development of technology-driven products and services.
−Removed: Our CDIO has over 20 years of technology and operations experience in the banking industry.
+Added: Prior to that, he served as the Senior Vice President and Chief Enterprise Architect for a bank with over $30 billion in assets.
+Added: In his over 25 years of technology experience in regulated industries, including banking, our CDIO has held leadership positions responsible for developing digital banking solutions, launching and integrating business enablement tools, artificial intelligence integration, and oversight of the technology framework.
Our ISO oversees a team of employees dedicated to the prevention, detection, mitigation, and remediation of cybersecurity incidents.
−Removed: He joined the Company in September 2022 with more than 20 years of technology and information security experience in banking and as a consultant, and he holds a Certified Information Security Manager certification.
−Removed: The team of employees includes information security professionals with a range of varying cybersecurity education and experience, many of whom have substantial experience assessing and managing cybersecurity initiatives and hold various cybersecurity certifications.
−Removed: The Company’s Critical Threat Committee is responsible for evaluating the materiality of a cybersecurity incident based on criteria that has been reviewed with the Board of Directors, and for determining whether there are disclosure obligations under applicable securities laws.
−Removed: In the event that the Critical Threat Committee determines that a critical cybersecurity incident (or incidents, if aggregated together) is deemed to be material, the Critical Threat Committee will brief the Board of Directors and oversee the disclosure process.
−Removed: For all critical cybersecurity incidents that are not deemed to be material, the Critical Threat Committee will notify the Company’s Chairman and Chief Executive Officer to determine whether the Board of Directors will be notified of the critical incident during the next regularly-scheduled cybersecurity update to the Audit Committee, or sooner as circumstances warrant.
+Added: He joined the Company in November 2025 with more than 25 years of technology and information security experience, specifically in the banking sector.
+Added: His most recent roles included Information Security Officer and Director of Information Technology, along with various cybersecurity consulting engagements.
+Added: In addition, the Company utilizes a specialized managed security provider to consult, monitor, alert and remediate issues related to cybersecurity.
+Added: This oversight includes endpoint protection, firewall alerting, vulnerability detection and oversight over the Company’s system information and event management (SIEM) platform.
+Added: The Company’s Incident Response Team (a sub-committee of the Technology Committee) has been established to evaluate the materiality of cybersecurity incidents based upon criteria that have been reviewed with the ERM Committee and the Board’s Risk Committee, and is responsible for determining whether there are disclosure obligations under applicable securities laws.
+Added: In the event that the Incident Response Team determines that a critical cybersecurity incident (or incidents, if aggregated together) is deemed to be material, the Incident Response Team will brief the Risk Committee and oversee the disclosure process.
+Added: For all critical cybersecurity incidents that are not deemed to be material, the Incident Response Team will report such incidents to the Technology Committee, which will further report such critical incidents to the ERM Committee and the Risk Committee, as part of the next regularly-scheduled cybersecurity updates, or sooner as circumstances warrant.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.