Unresolved Staff Comments
−Removed: Not applicable.
Cybersecurity
3 unchanged sentences
Accordingly, we have developed and implemented processes for assessing, identifying and managing material risks from cybersecurity threats designed to comply with federal law and regulations and protect against cybersecurity threats to our business.
−Removed: Our program is supported by management and the Company’s Board of Directors (the “Board of Directors”).
+Added: Our program is supported by management and the Board.
The Company maintains an active cyber insurance policy to enhance protections against material data intrusions or loss of privacy.
1 unchanged sentence
Business – Supervision and Regulation – “Financial Privacy and Cybersecurity Requirements,” incorporated by reference into this Item 1C.
−Removed: The Company’s Information Security Program (the “Program”) is comprised of five pillars:
+Added: The Company’s IS Program is comprised of five pillars:
the Information Security Policy, the Enterprise Information Security Risk Assessment, the Incident Response Plan, a formalized Security Awareness Campaign, and an enterprise monitoring and reporting program.
−Removed: The Information Security Policy contains numerous distinct administrative and technical controls that govern data security for the organization and is based on the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.
−Removed: The policy is reviewed and approved by the Board of Directors annually.
+Added: • The Information Security Policy contains numerous distinct administrative and technical controls that govern data security for the organization and is based on the NIST Cybersecurity Framework.
+Added: The policy is reviewed and approved by the Board annually.
• The Enterprise Information Security Risk Assessment quantifies risk criteria utilizing the same impact measures, including financial, strategic, operational, and reputational, set forth by the Enterprise Risk Committee.
−Removed: The risk assessment is reviewed and approved by the B oard of Directors annually.
−Removed: The Enterprise Risk Committee includes members of management from various departments and members of the Board of Directors and oversees the overall risk management of the Company.
−Removed: The Enterprise Risk Committee meets as often as appropriate to perform its responsibilities, but no less than once per calendar quarter and reports findings and provides recommendations to the Board of Directors on a routine basis.
−Removed: The Incident Response Plan (“IRP”) includes procedures for responding to actual or potential cybersecurity incidents, including providing timely notice to customers and our bank regulatory agencies when appropriate.
+Added: The risk assessment is reviewed and approved by the B oard annually.
+Added: The Enterprise Risk Committee includes members of management from various departments and members of the Board and oversees the overall risk management of the Company.
+Added: The Enterprise Risk Committee meets as often as appropriate to perform its responsibilities, but no less than once per calendar quarter and reports findings and provides recommendations to the Board on a routine basis.
+Added: • The IRP includes procedures for responding to actual or potential cybersecurity incidents, including providing timely notice to customers and our bank regulatory agencies when appropriate.
The IRP is based on the NIST Cybersecurity Framework.
3 unchanged sentences
• The Company maintains an enterprise monitoring and reporting program, which identifies key risk indicators for tracking and identifying trends.
−Removed: The key risk indicators are presented to the Company’s Information Technology Committee (“IT Committee”) and th e Board of Directors on a monthly basis.
−Removed: The Program is monitored each year through various internal and external audits, as well as OCC regulatory exams.
+Added: The key risk indicators are presented to the Company’s IT Committee and th e Board on a monthly basis.
+Added: The IS Program is monitored each year through various internal and external audits, as well as OCC regulatory exams.
Vulnerability and penetration testing are also conducted at least annually by an independent third party to supplement the vulnerability and patching program routinely performed by internal staff.
7 unchanged sentences
This effort includes the review of service organization controls reports, business continuity and disaster recovery efforts, insurance certificates, and other compliance related concerns when applicable.
−Removed: During the last three years we h ave not experienced any cybersecurity incidents that have materially affected our Company, including our business, strategy, results of operations or financial condition.
+Added: We have not experienced any cybersecurity incidents that have materially affected our Company, including our business, strategy, results of operations or financial condition.
For a discussion of how risks from cybersecurity threats may be reasonably likely to materially affect us, refer to Item 1A.
Risk Factors – Risks Related to our Business – “We rely on information technology and telecommunications systems, many of which are provided by third-party vendors” and – “Cyberattacks or other security breaches could adversely affect our operations, net income or reputation,” incorporated by reference into this Item 1C.
−Removed: The Board of Directors is responsible for oversight of risks from cybersecurity threats.
−Removed: Oversight of cybersecurity risk management is performed primarily by the Board of Directors and the IT Committee.
−Removed: The IT Committee consists of members of the Board of Directors and key members of management.
−Removed: The IT Committee’s primary purpose is to assist the Board of Directors in its oversight of technology and innovation strategies, plans and operations related to cybersecurity, data privacy, and third-party technology risk management.
−Removed: The Chief Information Security Officer (“CISO”) provides monthly information security reports on cybersecurity programs, policies and controls, key risk indicators and trends including responses to any cybersecurity events, and efforts to improve security.
−Removed: Annually, the CISO provides security training to the Board of Directors.
−Removed: The CISO also provides the Board of Directors with an annual Information Security Program Summary Report in compliance with federal banking guidelines.
−Removed: The program is managed by the CISO who reports to the Chief Operations Officer and is reviewed by regulators as well as internal auditors.
−Removed: The Chief Information Officer (“CIO”) and information technology staff support the CISO in cybersecurity operations as necessary to mitigate risks to the Company's technology infrastructure.
−Removed: The CISO holds two cybersecurity industry leading certifications (CISSP, CCSP) and has more than 20 years of technology experience.
+Added: The Board is responsible for oversight of risks from cybersecurity threats.
+Added: Oversight of cybersecurity risk management is performed primarily by the Board and the IT Committee.
+Added: The IT Committee’s primary purpose is to assist the Board in its oversight of technology and innovation strategies, plans and operations related to cybersecurity, data privacy, and third-party technology risk management.
+Added: Of the IT Committee members who are not Board members, only our CIO and CISO are responsible for assessing and managing cybersecurity risks, and the other committee members are responsible for oversight.
+Added: The CISO provides monthly information security reports to the Board and IT Committee on cybersecurity programs, policies and controls, key risk indicators and trends including responses to any cybersecurity events, and efforts to improve security.
+Added: Annually, the CISO provides security training to the Board.
+Added: The CISO also provides the Board with an annual Information Security Program Summary Report in compliance with federal banking guidelines.
+Added: The IS Program is managed by the CISO who reports to the Chief Operations Officer and is reviewed by regulators as well as internal auditors.
+Added: An information security analyst reports to the CISO and performs security and assurance functions daily.
+Added: The CIO and information technology staff support the CISO in cybersecurity operations as necessary to mitigate risks to the Company's technology infrastructure.
+Added: The CISO holds two cybersecurity industry leading certifications (Certified Information Systems Security Professional and Certified Cloud Security Professional) and has more than 20 years of technology experience.
+Added: The CIO has been in the information technology field for over 30 years and at various points held the following certifications:
+Added: Cisco Certified Internetwork Expert, Cisco Certified Network Professional, Cisco Certified Voice Professional, Cisco Certified Design Professional, and Microsoft Certified Systems Engineer.
+Added: The information security analyst has over five years of experience and holds ISC2’s “Certified in Cybersecurity” certification.
Information technology staff are generally subject to professional education, experience, and certification requirements, and receive education and mentoring from the CISO and CIO.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.