4 unchanged sentences
The Company’s process for monitoring and mitigating cybersecurity risk is designed in conjunction with its overall Enterprise Risk Management Policy.
−Removed: The Company’s Information Security Program follows ISO 27002, an international standard for information security controls, as well as references to the Federal Financial Institutions Examination Council Information Examination Handbook, and other regulatory guidance and industry standards.
−Removed: The Company has several processes in place to oversee and identify these risks, such as the Information Technology Risk Governance Committee (“ITRGC”), which is responsible for oversight of information technology (“IT”) and information security (“IS”) risk.
−Removed: This committee oversees the establishment and revision of IT and IS key risk and key performance indicators and ongoing monitoring of these metrics.
−Removed: The Company’s Chief Information Security Officer (“CISO”) is responsible for cybersecurity initiatives at the Company, including identifying and managing security risks, and escalating elevated risks with the Chief Risk Officer (“CRO”) where applicable.
+Added: The Company’s Information Security Program follows ISO 27002, an international standard for information security controls, as well as references to the Federal Financial Institutions Examination Council Information Examination Handbook, and other regulatory guidance and industry standards such as those of the Center for Internet Security (CIS).
+Added: The Company has several processes in place to oversee and identify these risks, such as the Information Technology Risk Governance Committee (“ITRGC”), which is responsible for oversight of information technology (“IT”) risk and the Information Security Committee, which oversees information security (“IS”) risk.
+Added: These committees oversee the establishment and revision of IT and IS key risk and key performance indicators and ongoing monitoring of these metrics.
+Added: As part of the independent second line of defense and reporting to the Chief Risk Officer (“CRO”), the Company’s Chief Information Security Officer (“CISO”) is responsible for cybersecurity initiatives at the Company, including identifying and managing security risks, and escalating elevated risks to the CRO where applicable.
Together, the CISO and the CRO report on emerging and existing threats and mitigation strategies to the Board, which has oversight of cybersecurity risk, on a semi-annual basis, or more frequently, if needed.
+Added: The CRO has over 30 years of experience in overseeing risk management functions.
The CISO has over 30 years of information security experience, with experienced team members that come from a wide range of industries and possess substantial knowledge and expertise in how to manage information security and cybersecurity risks.
Additionally, the team of employees supporting the CISO maintain education and certification requirements necessary to fulfill their responsibilities.
−Removed: The Company has deployed a layered security approach to identify, measure, monitor and control information technology risks.
+Added: As part of its cyber and information security defense, the Company has deployed a layered security approach to identify, measure, monitor and control information technology risks.
+Added: The Company regularly tests the implementation of these controls.
The Company also maintains a documented Incident Management Standard and Technology and Cyber Incident Response Plan.
These documents address the detection, mitigation, and remediation of cybersecurity incidents, and include appropriate timely incident escalations to be followed during an incident, up to and including executive leadership, management committees and depending on incident severity, the Board, or a Board committee.
−Removed: The volume, severity, and root case of security incidents are reported on at monthly management committees.
+Added: The volume, severity, and root cause of security incidents are reported at monthly management committees.
The Company will regularly engage independent third parties to assist in its cybersecurity preparedness, including but not limited to vulnerability scan assessments, secure code scan reviews, and cybersecurity incident response simulations.
2 unchanged sentences
TPRM documents the Company’s view of applicable third-party vendors assessing the vendor’s technological capability to provide products and/or services in a viable and risk adverse manner.
−Removed: In an effort to mitigate risks related to cybersecurity threats, the Company has also designed and implemented required training for all employees, including training on the Company’s security and privacy policies, which are mandatory as part of the onboarding process, with refresher trainings required annually thereafter.
−Removed: Additionally, the Company conducts regular phishing simulation tests throughout the year to keep employees alert, spread awareness and ensure that employees have the knowledge and resources necessary to report suspicious activity.
+Added: As part of its efforts to mitigate risks related to cybersecurity threats, the Company has proactively implemented required tailored training for all employees, including training on the Company’s security and privacy policies, which are mandatory as part of the onboarding process, with refresher trainings required annually thereafter.
+Added: Additionally, the Company conducts regular phishing simulation tests throughout the year to keep employees alert, spread awareness and ensure that employees have the knowledge and resources necessary to identify and report suspicious activity.
While the Company has seen attempts to gain access to its systems, and expects such attacks to continue, or possibly intensify in the future, the Company has not experienced any material losses relating to cyber-attacks or other information security breaches as of December 31, 2025 .
As a protective measure, the Company maintains insurance coverage for cybersecurity incidents experienced by the Company, or by one or more of the Company’s third-party providers, however such insurance coverage may not be sufficient to cover all losses incurred.
−Removed: As of the date of this Report, no risks from cybersecurity
−Removed: threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
+Added: As of the date of this Report, no risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition.
For further discussion surrounding risks from cybersecurity threats, refer to the section captioned “Risks Related to Information Security and Technology” within Part I.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.