44 unchanged sentences
Material Cybersecurity Threat Risks
−Removed: The Company has not experienced any material losses
−Removed: relating to cybersecurity threats or incidents for the year ended June 30, 2024.
−Removed: We are not aware of any risks from cybersecurity threats,
−Removed: including as a result of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect
−Removed: the Company, including our business strategy, results of operations or financial condition.
−Removed: Although we have a robust cybersecurity program
−Removed: that is designed to assess, identify, and manage material risks from cybersecurity threats, we cannot provide absolute surety that we
−Removed: have properly identified or mitigated all vulnerabilities or risks of incidents.
−Removed: The Company, and the third parties that the Company engages,
−Removed: are subject to constant and evolving threats of attack and cybersecurity incidents may be more difficult to detect for periods of time.
−Removed: A cybersecurity incident could harm our business strategy, results of operations, financial condition, reputation, and/or subject us to
−Removed: regulatory actions or litigation which may result in fines, judgments or indictments.
+Added: The Company has not experienced any material
+Added: losses relating to cybersecurity threats or incidents for the year ended June 30, 2025.
+Added: We are not aware of any risks from cybersecurity
+Added: threats, including as a result of any previous cybersecurity incidents that have materially affected or are reasonably likely to materially
+Added: affect the Company, including our business strategy, results of operations or financial condition.
+Added: Although we have a robust cybersecurity
+Added: program that is designed to assess, identify, and manage material risks from cybersecurity threats, we cannot provide absolute surety
+Added: that we have properly identified or mitigated all vulnerabilities or risks of incidents.
+Added: The Company, and the third parties that the
+Added: Company engages, are subject to constant and evolving threats of attack and cybersecurity incidents may be more difficult to detect for
+Added: periods of time.
+Added: A cybersecurity incident could harm our business strategy, results of operations, financial condition, reputation, and/or
+Added: subject us to regulatory actions or litigation which may result in fines, judgments or indictments.
Cybersecurity Governance
2 unchanged sentences
The Board has oversight responsibilities to ensure effective
−Removed: governance in managing these risks because it recognizes the significance of these threats to our operational integrity, shareholder and
−Removed: customer confidence and reputation.
+Added: governance in managing these risks because it recognizes the significance of these threats to our operational integrity, shareholder
+Added: and customer confidence and reputation.
Board of Directors Oversight
12 unchanged sentences
a broad range of topics, including:
−Removed: ● Current cybersecurity landscape and emerging
−Removed: ● Status of ongoing cybersecurity initiatives and
−Removed: ● Incident reports and issues identified from any
−Removed: cybersecurity events;
−Removed: ● Compliance with regulatory requirements and industry
−Removed: In addition to our regularly scheduled Board meetings,
−Removed: the ISO regularly communicates with senior staff regarding emerging or potential cybersecurity risks.
−Removed: They discuss any significant developments
−Removed: in the cybersecurity domain, which when reported to the Board, ensures the Board’s oversight is proactive and responsive.
−Removed: actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives.
−Removed: This involvement
−Removed: ensures that cybersecurity considerations are integrated into the broader strategic objectives of the Company.
−Removed: The Board closely reviews
−Removed: these reports of the Bank’s cybersecurity posture and the effectiveness of its risk management strategies prior to approval.
−Removed: review helps in identifying areas for improvement and ensuring the alignment of cybersecurity efforts with the overall risk management
+Added: Current cybersecurity landscape
+Added: and emerging threats;
+Added: Status of ongoing cybersecurity
+Added: initiatives and strategies;
+Added: Incident reports and issues
+Added: identified from any cybersecurity events;
+Added: Compliance with regulatory
+Added: requirements and industry standards.
+Added: In addition to our regularly scheduled Board
+Added: meetings, the ISO regularly communicates with senior staff regarding emerging or potential cybersecurity risks.
+Added: They discuss any significant
+Added: developments in the cybersecurity domain, which when reported to the Board, ensures the Board’s oversight is proactive and responsive.
+Added: The Board actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives.
+Added: This involvement ensures that cybersecurity considerations are integrated into the broader strategic objectives of the Company.
+Added: closely reviews these reports of the Bank’s cybersecurity posture and the effectiveness of its risk management strategies prior
+Added: This review helps in identifying areas for improvement and ensuring the alignment of cybersecurity efforts with the overall
+Added: risk management framework.
Cyber Risk Management Personnel
The ISO directly reports to the CEO.
−Removed: The ISO regularly
−Removed: meets with the CEO to update and discuss any cybersecurity risks and incidents affecting the Company.
−Removed: This ensures that the highest levels
−Removed: of management are kept abreast of the cybersecurity posture and potential risks facing the Company.
−Removed: Furthermore, all significant cybersecurity
−Removed: matters and strategic risk management decisions are promptly escalated to the Board of Directors, ensuring that they have an up-to-date,
−Removed: comprehensive understanding of and can provide guidance on critical cybersecurity issues.
+Added: regularly meets with the CEO to update and discuss any cybersecurity risks and incidents affecting the Company.
+Added: This ensures that the
+Added: highest levels of management are kept abreast of the cybersecurity posture and potential risks facing the Company.
+Added: Furthermore, all significant
+Added: cybersecurity matters and strategic risk management decisions are promptly escalated to the Board of Directors, ensuring that they have
+Added: an up-to-date, comprehensive understanding of and can provide guidance on critical cybersecurity issues.
Primary responsibility for assessing and providing
1 unchanged sentence
The ISO’s experience includes prior leadership roles within
−Removed: the Company, where they developed an expert level of understanding of the intersection between financial regulations and cloud-based technologies.
−Removed: The ISO and other information systems staff possess in-depth knowledge and experience which are instrumental in developing and executing
−Removed: our cybersecurity strategies.
+Added: the Company, where they developed an expert level of understanding of the intersection between financial regulations and cloud-based
+Added: technologies.
+Added: The ISO and other information systems staff possess in-depth knowledge and experience which are instrumental in developing
+Added: and executing our cybersecurity strategies.
The ISO and the Tech Steering Committee oversee our governance programs, work with our technology-focused
1 unchanged sentence
Monitoring Cybersecurity Incidents
−Removed: The ISO and other information security staff utilizes
−Removed: vendor relationships and various other internet based daily updates for the latest developments in cybersecurity, including potential
−Removed: threats and innovative risk management techniques.
−Removed: This knowledge is crucial for the effective prevention, detection, mitigation, and
−Removed: remediation of cybersecurity incidents.
+Added: The ISO and other information security staff
+Added: utilizes vendor relationships and various other internet based daily updates for the latest developments in cybersecurity, including
+Added: potential threats and innovative risk management techniques.
+Added: This knowledge is crucial for the effective prevention, detection, mitigation,
+Added: and remediation of cybersecurity incidents.
The ISO provides structure for clear processes to ensure the regular monitoring of our information
This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities.
−Removed: the event of a cybersecurity incident, we believe we are equipped with a well-defined Incident Response Plan that is adequately resourced.
+Added: In the event of a cybersecurity incident, we believe we are equipped with a well-defined Incident Response Plan that is adequately resourced.
This plan includes immediate actions to mitigate the impact and long-term strategies for remediation and prevent future incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.