5 unchanged sentences
to cybersecurity incidents are expected to remain high for the foreseeable future due to the rapidly evolving nature
−Removed: and sophistication of cybersecurity threats and geopolitical events, as well as due to the expanding use of Internet and mobile banking and other technology-based products and services utilized by us and our clients, including products and services that utilize the cloud and artificial intelligence (AI), among other emerging technologies.
+Added: and increasing sophistication of cybersecurity threats and geopolitical events, as well as the fact that threat actors frequently target technologies and systems commonly used by us and our clients.
+Added: In addition, our use of emerging technology-based products and services, including cloud computing and artificial intelligence may introduce new and evolving cybersecurity risks and may create additional avenues for exploitation by threat actors.
To date, Key has not experienced material disruption to our operations, or material harm to our client base, from cyberattacks.
14 unchanged sentences
including, but not limited to, access controls, vulnerability scans, network monitoring, internal and external
−Removed: penetration testing, monitoring of vendor vulnerability notices and patch releases, scanning of systems and emails
−Removed: for malware and other vulnerabilities, firewalls and intrusion detection and prevention systems, and dedicated
−Removed: security personnel.
+Added: penetration testing, monitoring of vendor vulnerability notices and patch releases, firewalls and intrusion detection and prevention systems, and dedicated security personnel.
As described in more detail in “Risk Management — Overview” in Item 7 of this report and in “Cybersecurity
Governance” below, Key employs the “Three Lines of Defense” in its risk governance framework.
−Removed: identifying, and managing cybersecurity risk across the organization in support of the IS Program is a cross-functional effort that requires collaboration and direction from all lines of defense – the lines of business and support functions (First Line of Defense), Risk Management (Second Line of Defense), and the Risk Review Group (RRG), Key’s internal audit function (Third Line of Defense):
+Added: identifying, and managing cybersecurity risk across the organization in support of the IS Program is a cross-functional effort that requires collaboration and direction from all lines of defense – the lines of business and support functions (First Line of Defense), Risk Management (Second Line of Defense), and Key’s Internal Audit (IA) function (Third Line of Defense):
• First Line of Defense – Lines of Business and Support Functions.
3 unchanged sentences
Risk Management oversees risk and monitors the First Line of Defense controls.
−Removed: Operational Risk Management performs review and challenge of controls, monitors the operational risk profile, and ensures Key operates within its operational risk appetite.
+Added: Operational Risk Management performs review and challenge of controls, monitors the operational and technology risk profiles, and ensures Key operates within its operational and technology risk appetite.
Compliance Risk Management provides an independent, enterprise-wide function that focuses on compliance with laws, rules, regulations, and guidance applicable to Key.
Privacy Compliance, which sits within Compliance Risk Management, provides advisory support, governance, and oversight of privacy-related statutes, regulations, and risks related to Key’s customers, employees, and other individuals from who Key collects personally identifiable information.
−Removed: • Third Line of Defense – Risk Review Group (RRG).
−Removed: The RRG reviews and evaluates the scope and breadth of security activities throughout Key and the effectiveness of the IS Program.
−Removed: RRG conducts independent internal
−Removed: audits on Key’s LOBs, operations, information systems, and technologies.
+Added: • Third Line of Defense – Internal Audit (IA).
+Added: IA reviews and evaluates the scope and breadth of security activities throughout Key and the effectiveness of the IS Program.
+Added: IA conducts independent internal audits on Key’s
+Added: LOBs, operations, information systems, and technologies.
These internal audits provide an independent perspective on Key’s processes and risks.
Technology risks are evaluated in areas including cybersecurity and information security, data control, acquisition and development, delivery and support, business continuity, and information technology governance.
−Removed: RRG shares the results of its audits with the LOB management, Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and banking regulators.
+Added: IA shares the results of its audits with the LOB management, Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and banking regulators.
As part of its cybersecurity risk management strategy, Key regularly reviews its security and privacy controls in the context of industry standard practices, frameworks, evolving laws, and changing client expectations.
−Removed: Key engages external providers periodically to perform a maturity assessment of the IS Program against industry cybersecurity frameworks.
−Removed: Key also engages external advisors periodically to perform security posture assessments of our environment to proactively identify weakness within our security policy and/or configurations.
+Added: Annually, we benchmark ourselves against industry-leading frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework and the Cyber Risk Institute Profile.
+Added: We also engage external providers periodically to perform a maturity assessment of the IS Program against industry cybersecurity frameworks and to perform security posture assessments of our environment to proactively identify weakness within our security policy and/or configurations.
Summary level results from these assessments are shared to internal stakeholders through Key’s Risk Governance committee structure.
−Removed: Key is also subject to cybersecurity and privacy regulatory exams, as required by law for financial institutions.
+Added: Key is also subject to cybersecurity and privacy regulatory exams, as required by law for financial institutions operating in the U.S.
Key has implemented cybersecurity, privacy, and fraud education and awareness programs across the
16 unchanged sentences
oversight capacity to ensure that Key’s risks, including risk from cybersecurity threats, are managed in a manner that is effective and balanced and adds value for our shareholders.
−Removed: The Board’s Risk Committee exercises primary oversight over enterprise-wide risk at Key, including operational risk, which includes cybersecurity risk, and provides oversight of management’s activities related to cybersecurity risk.
−Removed: The Board’s Audit Committee monitors and exercises oversight over cybersecurity risk as part of its joint oversight of operational risk with the Risk Committee.
−Removed: The Board’s Technology Committee provides additional oversight of management’s activities related to Key’s technology strategic investment plan, cybersecurity investments, and major technology vendor relationships and is expected to escalate to the Risk Committee on certain risk management issues.
+Added: The Board’s Risk Committee exercises primary oversight over enterprise-wide risk at Key, including technology risk, which includes (but is not limited to) cybersecurity, business resiliency, and other technology-related risks, and provides oversight of management’s activities related to the same.
+Added: The Board’s Technology Committee, in consultation with the Risk Committee, provides additional oversight of the technology-related risks listed above, and is expected to escalate to the Risk Committee on certain risk management issues.
+Added: The Technology Committee also oversees major technology investments supporting Key’s strategic objectives in areas such as cybersecurity, fraud and data, project management, technology strategy, technology innovation, and emerging technology trends.
+Added: The Board’s Audit Committee also shares in oversight of cybersecurity risk.
Key’s CISO oversees the IS Program and its related policies and is responsible for determining whether relevant security risk information is properly integrated into strategic and business decisions, overseeing the appropriate identification and ownership of security risks, monitoring critical risks, and maintaining the appropriate oversight and governance of information security through associated programs and/or standards.
2 unchanged sentences
The CISO is responsible for reporting on information security matters, including cybersecurity risk, to the Board.
−Removed: The CISO provides updates to the Audit Committee on cybersecurity matters at each regularly scheduled Committee meeting (six times in 2024).
−Removed: The CISO’s update to the Committee generally address the cybersecurity threat landscape, information security trends, strategic initiatives related to information security, and cybersecurity program reviews.
−Removed: The CISO also updates the Risk Committee on cybersecurity matters and on Key’s compliance with the Gramm-Leach-Bliley Act on an annual basis and presents the Information Security Policy for approval.
−Removed: The CISO, along with Key’s Deputy CISO, also report annually to the Technology Committee to obtain approval on Key’s Cyber Strategy and Investment Plan.
−Removed: The CISO provides updates to the Board as needs arise and from time to time.
−Removed: Key’s Deputy CISO leads the Corporate Information Security function, including the Cyber Defense Center, Identity
−Removed: & Access Management Operations, Information Security Governance and Data Protection, and Security Architecture, Engineering and Platform Operations.
+Added: The CISO provides regular updates on cybersecurity matters to the Audit Committee (six times in 2025).
+Added: These updates typically address the cybersecurity threat landscape, information security trends, strategic initiatives related to information security, and cybersecurity program reviews.
+Added: The CISO also provides regular updates to the Risk Committee on cybersecurity matters as well as Key’s compliance with the Gramm-Leach-Bliley Act (at least
+Added: annually) and presents the Information Security Policy for Risk Committee approval.
+Added: In addition, the CISO, together with Key’s Deputy CISO, reports annually to the Technology Committee to seek approval of Key’s Cyber Strategy and Investment Plan.
+Added: The CISO provides additional updates to the Board and its committees as circumstances warrant.
+Added: Key’s Deputy CISO leads the Corporate Information Security function, including Cyber Defense, Identity
+Added: & Access Management, Information Security Governance and Data Protection, and Security Architecture, Engineering and Platform Operations.
The Deputy CISO has over 18 years of cybersecurity and technology risk management experience across financial services and retail, previously served as the Head of Information Security Governance within KeyCorp’s Corporate Information Security group, as well as the Head of Cybersecurity and Technology Risk Oversight within KeyCorp’s Risk Management group.
−Removed: He holds a bachelor’s degree in Finance and Management Information Systems and an MBA.
+Added: The Deputy CISO holds a bachelor’s degree in Finance and Management Information Systems and an MBA.
The CISO reports to Key’s Chief Information Officer who oversees all of Key’s shared services for technology,
1 unchanged sentence
Our Chief Information Officer, who has served in the role since 2012, has extensive experience overseeing technology and operations delivery for critical enterprise functions and has held various leadership roles during her over 30-year career in the financial services industry.
−Removed: At the management level, our Enterprise Risk Management (ERM) Committee, chaired by the Chief Executive
−Removed: Officer and comprising other senior level executives, including the Chief Information Officer, reports to the Board’s
−Removed: Risk Committee and is responsible for managing risk, including cybersecurity risk.
−Removed: The ERM Committee serves as a
−Removed: senior level forum for review and discussion of material operational risk issues, including cybersecurity risk, and
−Removed: receives regular updates from the CISO regarding cybersecurity risk.
−Removed: The ERM Committee directly oversees the
−Removed: Operational Risk Committee, which provides governance, direction, oversight, and high-level management of
−Removed: operational risk, including cybersecurity risk, and includes senior management representation from the LOB and
−Removed: support areas.
−Removed: The CISO is a voting member of the Operational Risk Committee.
−Removed: The Operational Risk Committee also includes subcommittees which, among other things, address security issues
−Removed: and concerns, pursue security-related program enhancements, address fraud trends, provide input on fraud
−Removed: strategy, weigh the impacts of fraud risk on customers, business clients, and the LOB, and cascades awareness of
−Removed: fraud risks across Key.
+Added: At the management level, our ERM Committee, chaired by the Chief Risk Officer and comprising other senior level executives, including the Chief Information Officer, reports to the Board’s Risk Committee and supports the management of all risks by providing governance, direction, oversight and high-level management of risk.
+Added: The ERM Committee serves as a senior level forum for review and discussion of material risk issues, including cybersecurity risk.
+Added: The Operational Risk Committee also reports to the Board’s Risk Committee and provides governance, direction, and oversight of operational risks, including technology risks, and includes senior management representation from the LOB and support areas.
+Added: The Chief Information Officer is a voting member of the Operational Risk Committee.
+Added: The Operational Risk Committee also includes subcommittees, including the Security & Technology Committee (the “SecTec Committee”).
+Added: The SecTec Committee is responsible for ensuring a cohesive and coordinated approach to security and technology risk management and provides an enterprise-wide perspective of security and technology risk management.
Key also has a Privacy Team led by a Chief Privacy Officer (CPO) who has over ten years of experience in legal,
2 unchanged sentences
an undergraduate degree in finance, a master’s degree in business administration, and a juris doctorate.
−Removed: licensed to practice law in the state of Ohio and has obtained the CIPP/US certification through the International
+Added: The CPO is licensed to practice law in the state of Ohio and has obtained the CIPP/US certification through the International
Association of Privacy Professionals.
−Removed: The CPO and Privacy team have the authority to escalate privacy risks to the
−Removed: The Privacy and Information Security teams work together to implement controls around how personally
−Removed: identifiable information is managed and protected and to comply with applicable laws and regulations.
+Added: The CPO and Privacy team have the authority to escalate privacy risks to the Board.
+Added: The Privacy and Information Security teams work together to implement controls around how personally identifiable information is managed and protected and to comply with applicable laws and regulations.
Cybersecurity Incidents
13 unchanged sentences
Incidents are also reported internally to key stakeholders through Key’s risk governance committee structure.
−Removed: As discussed above in “Cybersecurity Risk Management,” the RRG shares the results of its independent internal
−Removed: audits of security activities at Key and the effectiveness of the IS Program with the line of business management,
−Removed: Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and banking
−Removed: Any identified gaps are risk rated, issued a due date for remediation, and tracked through completion of
−Removed: Remediation is then verified by the RRG.
+Added: As discussed above in “Cybersecurity Risk Management,” Internal Audit shares the results of its independent internal audits of security activities at Key and the effectiveness of the IS Program with the line of business management, Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and
+Added: banking regulators.
+Added: Any identified gaps are risk rated, issued a due date for remediation, and tracked through completion of remediation.
+Added: Remediation is then verified by IA.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.