2 unchanged sentences
Risk Management and Strategy
−Removed: NewtekOne maintains an enterprise-wide risk-management (“ERM”) framework to identify, measure, mitigate, monitor and report material risks to NewtekOne.
−Removed: Our ERM process includes participation by our senior management and employees across NewtekOne and its consolidated subsidiaries and is overseen by our Board.
+Added: NewtekOne maintains a Risk Management framework to identify, measure, mitigate, monitor and report material risks to the Risk Committee of our Board.
+Added: Our Risk Management process includes participation by our senior management and employees across NewtekOne and its consolidated subsidiaries and is overseen by our Chief Risk Officer who reports to the Risk Committee and our CEO.
+Added: The Risk Committee sets the risk appetite across NewtekOne while the executive leadership team and our associates identify and monitor current and emerging risks and manage those risks within our risk appetite.
Cybersecurity has been identified among the material risks in our business and the following approach has been developed to address cybersecurity.
−Removed: We have developed an enterprise-wide cybersecurity risk management system and strategy to safeguard our assets and operations, including the protection of the confidentiality of nonpublic, sensitive personal and business information and the integrity and security of our information systems, as follows:
+Added: We and NTS, and NTS’s successor, IPM, which manages our IT infrastructure and cybersecurity under the direction of our CTO, have developed an enterprise-wide cybersecurity risk management system and strategy to safeguard our assets and operations, including the protection of the confidentiality of nonpublic, sensitive personal and business information and the integrity and security of our information systems , as follows:
Assessment, Identification, and Management of Material Risks:
16 unchanged sentences
Engagement of Assessors, Consultants, and Auditors:
+Added: Internal Expertise:
+Added: Our CTO is responsible for overseeing the Company’s IT infrastructure and cybersecurity and reports to our executive management team and the Technology Steering Committee of our Board.
External Expertise:
We recognize the value of external expertise in assessing and enhancing our cybersecurity posture.
−Removed: To complement the internal capabilities of our Chief Information Security Officer (“CISO”), Chief Technology Officer (“CTO”) and their team of professionals, we engage assessors, consultants, auditors, and other third-party experts with specialized knowledge in cybersecurity.
+Added: Historically, the Company’s subsidiary NTS and its team of professionals, including NTS’ Chief Information Security Officer (“CISO”), who currently serves as our CISO, and CTO, and their team of professionals, have managed the Company’s IT infrastructure, including our dedicated server hosting, managed cybersecurity, backup and disaster recovery, and other related services.
+Added: As of the January 2, 2025, close of our divestiture of NTS to IPM, we and IPM entered into a Master Services Agreement pursuant to which IPM provides us with the same services NTS provided to the Company prior to the divestiture.
+Added: Our CTO is responsible for overseeing IPM’s provision of the managed technology services, including cybersecurity, to NewtekOne.
+Added: In addition, we engage assessors, consultants, auditors, and other third-party experts with specialized knowledge in cybersecurity.
These external stakeholders conduct independent assessments, penetration testing, vulnerability scans, and audits to evaluate the effectiveness of our cybersecurity controls and identify areas for improvement.
3 unchanged sentences
Oversight of Third-Party Service Providers:
−Removed: Vendor Risk Management:
−Removed: We recognize that third-party service providers may introduce additional cybersecurity risks to our organization.
−Removed: As such, we have established a vendor risk management program to assess and monitor the cybersecurity posture of our third-party vendors and partners.
−Removed: Due Diligence:
−Removed: Prior to engaging with third-party service providers, we conduct due diligence assessments to evaluate their cybersecurity controls, practices, and compliance with industry standards and regulations.
−Removed: This due diligence process includes assessing the vendor's security policies, procedures, incident response capabilities, and contractual obligations related to cybersecurity.
−Removed: Ongoing Monitoring:
−Removed: We continuously monitor the cybersecurity performance of our third-party vendors throughout the duration of our engagement.
−Removed: This includes regular assessments, audits, and compliance reviews to ensure that vendors adhere to agreed-upon cybersecurity standards and contractual obligations.
−Removed: Remediation and Escalation:
−Removed: In the event that cybersecurity risks or deficiencies are identified within our third-party vendor ecosystem, we work collaboratively with the vendor to address and remediate these issues in a timely manner.
−Removed: Depending on the severity of the risk, we may escalate concerns to senior management or terminate the vendor relationship if necessary.
+Added: Our management is actively engaged in overseeing our third-party service providers.
+Added: Our Enterprise Third Party Risk Management (TPRM) Policy establishes requirements and practices used to oversee and manage the activities of third parties with whom we have a relationship, under which we identify, measure, monitor, and manage third-party risk (including information cybersecurity risks) in alignment with our strategic objectives and in compliance with applicable law.
+Added: Any identified threats, vulnerabilities, or cybersecurity incidents are addressed as appropriate through our CTO, CISO and IPM.
Our Board oversees material risks facing the Company.
−Removed: For some categories of risk, the Board has empowered a committee to provide more focused oversight.
−Removed: In the case of cybersecurity and technology risk, the Board’s Risk Committee has that responsibility.
−Removed: The Risk Committee is informed of risks from cybersecurity threats through regular reports from the Company’s management, including our CISO and CTO.
−Removed: Our CISO and CTO, who are employees of our subsidiary NTS, oversee our cybersecurity risk management program.
+Added: For some categories of risk, the Board has empowered committees to provide more focused oversight.
+Added: In the case of cybersecurity and technology risk, in 2024 the Board formed the Technology Steering Committee which has that responsibility.
+Added: The Technology Steering Committee is informed of risks from cybersecurity threats through regular reports from the Company’s management, including our CTO.
+Added: Our CTO and the CISO, who is employed by IPM, oversee our cybersecurity risk management program.
The CISO is chiefly responsible for developing, maintaining, and enforcing cybersecurity and cyber risk-related policies;
ensuring the Company and its subsidiaries satisfy requirements of relevant regulations, industry standards, and third-party risk assessment requirements;
−Removed: keeping abreast of developing security threats, and helping both the Board and the Risk Committee understand potential security problems that might arise from the changing threat landscape;
+Added: keeping abreast of developing security threats, and helping both the Board and the Technology Steering Committee understand potential security problems that might arise from the changing threat landscape;
and overseeing and implementing regular security awareness training of all employees on cybersecurity, and supporting effective communication with users to limit security vulnerabilities.
−Removed: The CISO regularly reports to the Risk Committee, as well as the risk committee of the board of directors of Newtek Bank, on the state of our cybersecurity risk management program and provides updates on cybersecurity matters.
−Removed: The Risk Committee also receives regular reports on how management identifies, assesses, and manages cybersecurity and broader technology risks.
−Removed: The Risk Committee reviews these reports and discusses them with management.
−Removed: The Risk Committee reports to the full Board on key aspects of management’s presentations on cybersecurity and broader technology risks.
−Removed: All members of the Board have access to written cybersecurity reports that are provided to the Risk Committee.
−Removed: While our Board and Risk Committee oversee risk, our senior leadership is responsible for identifying, assessing, and managing our exposure to risks from cybersecurity threats.
−Removed: Accountability of our cybersecurity program is housed within our subsidiary NTS, which is led by our CTO.
+Added: The CISO regularly reports to our CTO who reports to the Technology Steering Committee on a quarterly and more frequently as needed, on the state of our cybersecurity risk management program and provides updates on cybersecurity matters.
+Added: The Technology Steering Committee also receives regular reports on how management identifies, assesses, and manages cybersecurity and broader technology risks.
+Added: The Technology Steering Committee reviews these reports and discusses them with management.
+Added: The Technology Steering Committee reports to the full Board on key aspects of management’s presentations on cybersecurity and broader technology risks.
+Added: All members of the Board have access to written cybersecurity reports that are provided to the Technology Steering Committee.
+Added: While our Board and Technology Steering Committee oversee cybersecurity and technology risk, our senior leadership is responsible for identifying, assessing, and managing our exposure to risks from cybersecurity threats.
+Added: Accountability of our cybersecurity program is housed within IPM, with oversight by our CTO.
Reporting to our CTO is the CISO, the individual who provides day-to-day oversight of our cybersecurity program.
2 unchanged sentences
The CISO’s team consists of individuals that have knowledge, skills and expertise to respond to a cybersecurity incident.
−Removed: Our CISO coordinates with the Company’s and our subsidiaries’ executive officers relating to potentially material cybersecurity incidents and regularly discusses with the Risk Committee the effectiveness of the Company’s technology security, capabilities for disaster recovery, data protection, cyber threat detection and cyber incident response and management of technology-related compliance risks.
+Added: Our CISO coordinates with the CTO, who coordinates with the Company’s and our subsidiaries’ executive officers relating to potentially material cybersecurity incidents and regularly discusses with the Technology Steering Committee the effectiveness of the Company’s technology security, capabilities for disaster recovery, data protection, cyber threat detection and cyber incident response and management of technology-related compliance risks.
Our CISO is a Certified Information System Security Professional (CISSP) with decades of experience with technology in security, architecture, infrastructure and support in the financial, education, healthcare and verticals.
He is a results driven leader who has managed multimillion dollar projects and solutions to successful completion.
−Removed: Our CTO has over 25 years of experience in enterprise technology services with expertise in managed services, private cloud, service operations, and security.
+Added: Our CTO has over 25 years of experience in enterprise technology solutions, with expertise in managed services, private cloud, service operations, and security.
He is committed to driving reliability of services while prioritizing robust security measures.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.