3 unchanged sentences
The Company maintains an information security program (the Program) to identify, assess, and manage material risks to its business, operations, and assets related to cybersecurity threats.
−Removed: The Company leverages recognized security frameworks and guidelines, such as the National Institute of Standards and Technology Framework Cybersecurity Framework and Federal Financial Institution Examination Counsel ("FFIEC") guidelines, to organize, assess, and improve the Program.
+Added: The Company leverages recognized security frameworks and guidelines, such as the National Institute of Standards and Technology Cybersecurity Framework and Federal Financial Institution Examination Counsel (FFIEC) guidelines, to organize, assess, and improve the Program.
Key components of the Program include, among other things:
18 unchanged sentences
For more information on our cybersecurity related risks, see Item 1A Risk Factors.
−Removed: The Company’s information security officer ("ISO") leads the Company’s overall cybersecurity function and reports to our Chief Risk Officer ("CRO").
−Removed: The Company's CRO has 30 years of experience in banking and risk management and has experience in various technology oversight roles.
+Added: The Company’s information security officer (ISO) leads the Company’s overall cybersecurity function and reports to our Executive Director Risk, Human Capital, and Operations, who has 23 years of experience in banking and risk management.
Our ISO works with stakeholders across the Company, including with our technology group, to maintain the cybersecurity program.
−Removed: Our executive leadership team is actively engaged in the oversight and strategic direction of our Program and meets with the CRO to review and discuss the Company’s Program, including emerging cybersecurity risks, threats, and industry trends.
−Removed: Our Board of Directors (the “Board”) considers cybersecurity risk as part of its risk management oversight function and has delegated to the Audit Committee oversight of cybersecurity risks.
−Removed: The Audit Committee receives updates from the CRO and other Company management on cybersecurity matters at least annually.
+Added: Our executive leadership team is actively engaged in the oversight and strategic direction of our Program and meets with the Executive Director Risk, Human Capital, and Operations to review and discuss the Company’s Program, including emerging cybersecurity risks, threats, and industry trends.
+Added: Our Board of Directors considers cybersecurity risk as part of its risk management oversight function and has delegated to the Audit Committee oversight of cybersecurity risks.
+Added: The Audit Committee receives updates from the Executive Director Risk, Human Capital, and Operations and other Company management on cybersecurity matters at least annually.
The Audit Committee reports findings and recommendations, as appropriate, to the full Board of Directors for consideration.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.