−Removed: Unresolved Staff Comments
−Removed: Not applicable.
+Added: Staff Comments
Cybersecurity
3 unchanged sentences
Risk Assessment, and Internal Vulnerability Reports and current Cyber Events briefings.
−Removed: The Board of Directors also makes budgeting, procedure,
−Removed: and policy decisions designed and intended to improve the Company’s residual risk.
−Removed: The Technology
−Removed: and Security Committee consists of the Company’s senior management, the IT Management, and business unit management.
−Removed: function of the Technology and Security Committee is to perform Strategic Planning, discuss hardware and software replacement, new projects,
−Removed: current cybersecurity threats, and ongoing cybersecurity issues and threats.
−Removed: The IT Director provides an IT status report to the Board
−Removed: of Directors on a Monthly basis.
−Removed: has adopted an Incident Response Plan (the “Plan”) to monitor, detect, mitigate and remediate cybersecurity incidents.
−Removed: Plan requires that business unit management have a working knowledge of the Company’s Information Security Program and Incident
+Added: The Board of Directors also makes budgeting,
+Added: procedure, and policy decisions designed and intended to improve the Company’s residual risk.
+Added: Technology and Security Committee consists of the Company’s senior management, the IT Management, and business unit management.
+Added: The primary function of the Technology and Security Committee is to perform Strategic Planning, discuss hardware and software replacement,
+Added: new projects, current cybersecurity threats, and ongoing cybersecurity issues and threats.
+Added: The IT Director provides an IT status report
+Added: to the Board of Directors on a monthly basis.
+Added: Company has adopted an Incident Response Plan (the “Plan”) to monitor, detect, mitigate and remediate cybersecurity incidents.
+Added: The Plan requires that business unit management have a working knowledge of the Company’s Information Security Program and Incident
Response Policies.
5 unchanged sentences
The documentation of the suspected or actual incident includes the following:
−Removed: the nature and scope of the incident;
−Removed: the information systems affected;
−Removed: the types of customer information potentially affected.
+Added: Identify the nature and scope of the incident;
+Added: Identify the information systems affected;
+Added: Identify the types of customer information potentially affected.
the Incident Response Team has determined that unauthorized access, manipulation of data or theft of any item identified under GLBA Inventory
4 unchanged sentences
Security Officer, the Compliance Officer and Information Technology Management must be contacted immediately.
−Removed: If Management declares an
−Removed: incident or if there is a confirmed theft or loss of customer information, appropriate regulatory authorities, law enforcement, and legal
−Removed: counsel are notified.
+Added: If Management declares
+Added: an incident or if there is a confirmed theft or loss of customer information, appropriate regulatory authorities, law enforcement, and
+Added: legal counsel are notified.
the fiscal year ended September 30, 2025, the risks from cybersecurity threats, including as a result of any previous cybersecurity incidents,
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.