Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
The Company’s information security program is designed to protect the confidentiality, integrity, and availability of our critical systems and information, including customer information. The program is comprised of policies, procedures, and programs, and is informed by and intended to align with the interagency guidance issued by banking regulators as well as the NIST Cybersecurity Framework (the “Information Security Program”). This does not imply that we meet any particular technical standards, specifications, or requirements, but rather that we use the guidance to help us identify, assess, and manage cybersecurity risks relevant to our business.
Cybersecurity Risk Management and Strategy
We are a digital bank. As such, data security is a foundational pillar of our business strategy. We’ve therefore integrated our Information Security Program into the Enterprise Risk Management program, meaning it shares common methodologies, reporting channels and governance processes that apply to other areas of enterprise risk, including legal, compliance, strategic, operational, and financial risk. Key elements of our Information Security Program include:
• risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader enterprise information technology environment are conducted on at least an annual basis;
• internal testing of our security controls and our response to cybersecurity incidents;
• the use of external service providers, to assess, test or otherwise assist with aspects of our security controls;
• training and awareness programs for all employees that include periodic and ongoing assessments to drive adoption and awareness of cybersecurity processes and controls;
• a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
• maintenance and regular testing of a Business Continuity Plan that includes redundant back-up systems for critical functions;
• a physical security program that is tested regularly;
• obtaining and maintaining cyber insurance; and
• a third-party risk management program for service providers, suppliers, and vendors, that provides for the assessment, monitoring and management of cybersecurity risk presented by the Company’s use of such third parties, as well as contractual protections related to cybersecurity incidents affecting third party vendors and service providers.
The Company engages in a continuous risk monitoring process that seeks to identify the likelihood and impact of internal and external threats to our information security systems and data and assesses the sufficiency of the controls in place to mitigate these threats to acceptable levels. Incidents are reported to and handled under our Incident Response Policy, which designates an incident response team and includes procedures and processes to identify, assess, respond to, mitigate and report on cybersecurity incidents.
In the last three fiscal years, the Company has not experienced any material cybersecurity incidents. Despite our efforts, there can be no assurance that our cybersecurity risk management processes and measures described will be fully implemented, complied with, or effective in protecting our systems and information. We face risks from certain cybersecurity threats that, if realized, are reasonably likely to materially affect our business strategy, result of operations or financial condition. Please see Part I, Item 1A Risk Factors for further discussion of the risks associated with an interruption or breach in our information systems or infrastructure.
21
Cybersecurity Governance
Our Board of Directors keeps apprised of and oversees technology risk and cybersecurity of the Company. The Board receives updates from the Company’s Chief Information Officer or Information Security Officer (“ISO”) on a quarterly basis and receives cybersecurity training on at least an annual basis. While the entire Board receives reporting and training, the Board has delegated certain specific responsibility for overseeing cybersecurity threats, among other things, to its Risk Committee. Our ISO and Chief Risk Officer provide the Risk Committee and the Company’s internal Enterprise Risk Management Committee periodic and as needed reports on our cybersecurity risks and cybersecurity incidents, if any.
The Risk Committee and the entire Board review and approve the Company’s information security policies and certain other relevant policies on at least an annual basis. Our ISO and Chief Information Officer , who share the responsibility of overseeing and managing the Information Security Program, collectively have decades of experience in the system, network, and cybersecurity space. The Chief Information Officer serves on the Enterprise Risk Management Committee, which is chaired by our Chief Risk Officer. They are supported by our team of technology professionals, who are responsible for information technology security monitoring and for managing the controls designed to identify, detect, protect against, respond to and recover from cybersecurity threats and cybersecurity incidents.
Item 2. Properties
The Company and the Bank are headquartered in a 172,630 square foot mixed-use building located at 8701 East 116th Street, Fishers, IN 46038. The Bank’s wholly-owned subsidiary, SPF15, Inc., owns and operates the building and property. The Company considers its property to be in adequate condition and suitable for its intended purposes.
Item 3. Legal Proceedings
Neither we nor any of our subsidiaries are party to any material legal proceedings. From time to time, the Bank is a party to legal actions arising from its normal business activities.
Item 4. Mine Safety Disclosures
None.
PART II
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.