UNRESOLVED STAFF COMMENTS
−Removed: Table of Content s
CYBERSECURITY
1 unchanged sentence
The Company maintains an information security program (the “Program”) to identify, assess, and manage material risks to its business, operations, and assets related to cybersecurity threats.
−Removed: The Company leverages recognized security frameworks and guidelines, such as the National Institute of Standards and Technology Framework Cybersecurity Framework and Federal Financial Institution Examination Counsel ("FFIEC") guidelines, to organize, assess, and improve our Program.
+Added: The Company leverages recognized security frameworks and guidelines, such as the National Institute of Standards and Technology Framework Cybersecurity Framework and Federal Financial Institution Examination Counsel ("FFIEC") guidelines, to organize, assess, and improve the Program.
Key components of the Program include, among other things:
18 unchanged sentences
For more information on our cybersecurity related risks, see Item 1A Risk Factors.
−Removed: The Company’s information security officer ("ISO") leads the Company’s overall cybersecurity function and currently reports to our Chief Operations Officer.
−Removed: The Company's current ISO has formal education in information technology and extensive work experience gained from over 10+ years in various technology leadership roles.
−Removed: Our executive leadership team is actively engaged in the oversight and strategic direction of our Program and meets with the ISO to review and discuss the Company’s Program, including emerging cybersecurity risks, threats, and industry trends.
+Added: The Company’s information security officer ("ISO") leads the Company’s overall cybersecurity function and reports to our Chief Risk Officer ("CRO").
+Added: The Company's CRO has 30 years of experience in banking and risk management and has experience in various technology oversight roles.
+Added: Our ISO works with stakeholders across the Company, including with our technology group, to maintain the cybersecurity program.
+Added: Our executive leadership team is actively engaged in the oversight and strategic direction of our Program and meets with the CRO to review and discuss the Company’s Program, including emerging cybersecurity risks, threats, and industry trends.
Our Board of Directors (the “Board”) considers cybersecurity risk as part of its risk management oversight function and has delegated to the Audit Committee oversight of cybersecurity risks.
−Removed: The Audit Committee receives updates from the ISO and other Company management on cybersecurity matters at least annually.
+Added: The Audit Committee receives updates from the CRO and other Company management on cybersecurity matters at least annually.
The Audit Committee reports findings and recommendations, as appropriate, to the full Board of Directors for consideration.
1 unchanged sentence
In addition, any cybersecurity incident assessed as being, or potentially becoming, material is escalated for further assessment and then reported to designated members of our senior management and, if necessary, the Audit Committee.
−Removed: Table of Content s
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.