25 unchanged sentences
The Company also periodically engages third parties for assessments of specific products, services, or applications.
−Removed: The Company leverages various software and service providers as part of its Cybersecurity Program, including a managed security service provider and a service provider that helps monitor third-party suppliers.
+Added: The Company leverages various software and service providers as part of its Cybersecurity Program that assist with various services, including monitoring third-party suppliers.
The Company also receives periodic threat intelligence reports from vendors, peers, and industry information sharing and analysis centers.
13 unchanged sentences
Management’s Role in Cybersecurity Risk Management
−Removed: The Chief Information Security Officer (“CISO”) of the Bank and a standing management Information Security Committee monitor, measure, and report key indicators, risk assessments, and security measures to the management Corporate Risk Committee.
−Removed: The CISO, in conjunction with the Corporate Risk Committee, makes quarterly reports to, the Risk Committee of the Board of Directors.
+Added: Management convenes a standing Information Security Committee to monitor, measure, and report key indicators, risk assessments, and security measures to the management Corporate Risk Committee.
+Added: Information Security leadership, in conjunction with the Corporate Risk Committee, make quarterly reports to the Risk Committee of the Board of Directors.
Such quarterly reporting may include, but is not limited to, key metrics and risk indicators, penetration test results, risk assessment results, status of ongoing initiatives, incident and notable event reports, compliance with regulatory standards, and operational issues.
1 unchanged sentence
Risk Management Personnel
−Removed: Primary responsibility for assessing, monitoring, and managing our Cybersecurity Program rests with the CISO , Mr.
−Removed: Richard Friedberg.
−Removed: With over 25 years of experience in the field of cybersecurity, his background includes extensive experience across the financial sector, technology sector, and U.S.
−Removed: Friedberg is also an adjunct faculty member at Carnegie Mellon University, teaching risk and cyber practices.
−Removed: Friedberg holds a Bachelor of Science from Carnegie Mellon University, a Master of Business Administration from George Washington University, and maintains certification as a Certified Information Systems Security Professional and Certified Information Security Manager.
+Added: Primary responsibility for assessing, monitoring, and managing our Cybersecurity Program rests with the Interim Information Security Officer , supported by two Interim Deputy Chief Information Security Officers and the broader Information Security function.
+Added: The Chief Information and Digital Officer, Renato Derraik, also serves as Interim Information Security Officer.
+Added: Derraik has served as the Bank’s Chief Information and Digital Officer since June 2021 and has over 25 years of experience leading technology, digital, and operating model transformations, including leadership roles overseeing digital innovation and transformation at a large financial services company, and advising global organizations on technology and digital transformations.
+Added: This experience supports his oversight of cybersecurity risk management, including integrating cybersecurity risk considerations into technology strategy, operations, governance, and risk reporting.
+Added: The Interim Information Security Officer is supported by Scott McMichael and George Werbacher, who serve as the Interim Deputy Chief Information Security Officers.
+Added: McMichael leads cybersecurity risk management and governance, including enterprise cyber risk oversight, training and awareness, portfolio oversight, regulatory alignment, and third-party information security risk management.
+Added: He brings over 20 years of experience in financial services governance, security, and risk leadership, including senior leadership roles at Capital One Financial Corporation and Navy Federal Credit Union.
+Added: McMichael holds a Juris Doctor from the University of Richmond School of Law.
+Added: Werbacher leads key security controls and operations, including detection and response, incident management, vulnerability management, and cloud and network security.
+Added: He brings over a decade of cybersecurity leadership experience across financial services and technology, including senior security roles at Capital One Financial Corporation, Truist Financial Corporation, and Blackbaud Inc.
+Added: Werbacher holds a Master of Science in Information Security and Policy Management from Carnegie Mellon University.
+Added: McMichael and Mr.
+Added: Werbacher are both graduates of the Carnegie Mellon Executive Education CISO program.
Monitoring Cybersecurity Incidents
−Removed: The CISO is continually informed of and monitors cybersecurity risks and incidents through real-time updates, including a partnership with a managed security service provider.
+Added: Information Security leadership are continually informed of and monitor cybersecurity risks and incidents through real-time updates, including a partnership with a managed security service provider.
Periodic Information Security Committee meetings cover key metrics and risk indicators, penetration test results, risk assessment results, status of ongoing initiatives, incident and notable event reports, compliance with regulatory standards, and operational issues.
−Removed: In the event of a cybersecurity incident, we have an established incident response plan that requires prompt notification of the CISO or the CISO’s designee, who in turn engages with the corporate Incident Response Team (IRT) to respond to the incident.
−Removed: The CISO is also responsible for informing the Information Security Committee of cybersecurity incidents, which in turn reviews the impact of incidents and monitors the Company’s mitigation and remediation efforts.
+Added: In the event of a cybersecurity incident, we have an established incident response plan that requires prompt notification to Information Security leadership, who in turn engages with the corporate Incident Response Team (IRT) to respond to the incident.
+Added: Information Security leadership are also responsible for informing the Information Security Committee of cybersecurity incidents, which in turn reviews the impact of incidents and monitors the Company’s mitigation and remediation efforts.
Depending on the nature of the incident, this process also provides for escalating notice to the Risk Committee of the Board of Directors.
1 unchanged sentence
Reporting to Board of Directors
−Removed: The CISO, in his capacity, periodically informs the Information Security Committee, Corporate Risk Committee and Board’s Risk Committee of cybersecurity risks and incidents.
+Added: Information Security leadership periodically inform the Information Security Committee, Corporate Risk Committee and Board’s Risk Committee of cybersecurity risks and incidents.
This enables the highest levels of management to be kept abreast of the Company’s cybersecurity posture and potential risks facing the Company.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.