1 unchanged sentence
Cybersecurity
−Removed: We believe that cybersecurity and the protection of data and customer information in our possession, custody or control is of paramount importance to our business.
The Company’s information security program is designed to protect the confidentiality, integrity, and availability of our critical systems and information, including customer information.
−Removed: The program is comprised of policies, procedures, and programs, and is informed by and intended to align with the interagency guidance issued by banking regulators as well as the FFIEC Information Security Booklet and Cybersecurity Assessment Tool (the “Information Security Program”).
+Added: The program is comprised of policies, procedures, and programs, and is informed by and intended to align with the interagency guidance issued by banking regulators as well as the NIST Cybersecurity Framework (the “Information Security Program”).
This does not imply that we meet any particular technical standards, specifications, or requirements, but rather that we use the guidance to help us identify, assess, and manage cybersecurity risks relevant to our business.
Cybersecurity Risk Management and Strategy
−Removed: Our Information Security Program is integrated into our risk management program and is aligned to the Company’s business strategy and Enterprise Risk Management program.
−Removed: It shares common methodologies, reporting channels and governance processes that apply to other areas of enterprise risk, including legal, compliance, strategic, operational, and financial risk.
+Added: We are a digital bank.
+Added: As such, data security is a foundational pillar of our business strategy.
+Added: We’ve therefore integrated our Information Security Program into the Enterprise Risk Management program, meaning it shares common methodologies, reporting channels and governance processes that apply to other areas of enterprise risk, including legal, compliance, strategic, operational, and financial risk.
Key elements of our Information Security Program include:
8 unchanged sentences
• a third-party risk management program for service providers, suppliers, and vendors, that provides for the assessment, monitoring and management of cybersecurity risk presented by the Company’s use of such third parties, as well as contractual protections related to cybersecurity incidents affecting third party vendors and service providers.
−Removed: The Company engages in a continuous risk monitoring process that seeks to identify the likelihood and impact of internal and external threats to our information security systems and data, and assesses the sufficiency of the controls in place to mitigate these threats to acceptable levels on a risk-based basis.
+Added: The Company engages in a continuous risk monitoring process that seeks to identify the likelihood and impact of internal and external threats to our information security systems and data and assesses the sufficiency of the controls in place to mitigate these threats to acceptable levels.
Incidents are reported to and handled under our Incident Response Policy, which designates an incident response team and includes procedures and processes to identify, assess, respond to, mitigate and report on cybersecurity incidents.
−Removed: The risk and evolving nature of cybersecurity threats, and not a previous cybersecurity incident, has led to the Company to devote significant time and resources to the development and implementation of the Information Security Program described above.
−Removed: Despite our efforts, there can be no assurance that our cybersecurity risk management processes and measures will be fully implemented, complied with, or effective in protecting our systems and information.
+Added: In the last three fiscal years, the Company has not experienced any material cybersecurity incidents.
+Added: Despite our efforts, there can be no assurance that our cybersecurity risk management processes and measures described will be fully implemented, complied with, or effective in protecting our systems and information.
We face risks from certain cybersecurity threats that, if realized, are reasonably likely to materially affect our business strategy, result of operations or financial condition.
2 unchanged sentences
Our Board of Directors keeps apprised of and oversees technology risk and cybersecurity of the Company.
−Removed: The Board receives updates from the Company’s Information Security Officer (“ISO”) on a quarterly basis and receives cybersecurity training on at least an annual basis.
−Removed: While the entire Board receives reporting and receives training, the Board has delegated certain specific responsibility for overseeing cybersecurity threats, among other things, to its Risk Committee .
+Added: The Board receives updates from the Company’s Chief Information Officer or Information Security Officer (“ISO”) on a quarterly basis and receives cybersecurity training on at least an annual basis.
+Added: While the entire Board receives reporting and training, the Board has delegated certain specific responsibility for overseeing cybersecurity threats, among other things, to its Risk Committee.
Our ISO and Chief Risk Officer provide the Risk Committee and the Company’s internal Enterprise Risk Management Committee periodic and as needed reports on our cybersecurity risks and cybersecurity incidents, if any.
The Risk Committee and the entire Board review and approve the Company’s information security policies and certain other relevant policies on at least an annual basis.
−Removed: Our ISO, who has over twenty-five years of experience in the system, network, and cybersecurity space, is responsible for overseeing and managing the Information Security Program alongside our Chief Information Officer.
+Added: Our ISO and Chief Information Officer , who share the responsibility of overseeing and managing the Information Security Program, collectively have decades of experience in the system, network, and cybersecurity space.
The Chief Information Officer serves on the Enterprise Risk Management Committee, which is chaired by our Chief Risk Officer.
1 unchanged sentence
The Company and the Bank are headquartered in a 172,630 square foot mixed-use building located at 8701 East 116th Street, Fishers, IN 46038.
−Removed: The Bank’s wholly-owned subsidiary, SPF15, Inc., owns the building and property.
+Added: The Bank’s wholly-owned subsidiary, SPF15, Inc., owns and operates the building and property.
The Company considers its property to be in adequate condition and suitable for its intended purposes.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.