14 unchanged sentences
Periodic testing of the plan ensures readiness and identifies refinements.
−Removed: Reputable third-party assessors are engaged to conduct various assessments on a regular basis.
+Added: • Reputable third-party assessors are engage d to conduct various assessments on a regular basis.
Supporting the Company’s information security program is a third-party risk management program that manages the life cycle of external service providers and ensures that vendors meet the Company’s cybersecurity requirements.
3 unchanged sentences
Cybersecurity risks have the potential to materially affect the Company’s business, financial condition and results of operation.
−Removed: The Company strengthened its cybersecurity framework in response to cyber attacks in 2016 and 2017 and does not believe that risks from cyber security threats or attacks have materially affected the Company since 2017.
−Removed: However, the sophistication of emerging cyber threats and the utilization of new attack methods continues to evolve.
+Added: The Company has strengthened its cybersecurity framework in recent years but the sophistication of emerging cyber threats and the utilization of new attack methods continues to evolve.
The Company’s cybersecurity risk management and strategy may not protect against all cyber incidents.
4 unchanged sentences
Management’s Role
−Removed: The Company’s ISO, supported by skilled internal personnel, is responsible for identifying, assessing and managing cybersecurity risks and designing, implementing and maintaining the Company’s information security program.
−Removed: The ISO has many years of experience and holds multiple certifications appropriate to the role.
−Removed: The ISO reports to the Senior Vice President/Sr.
−Removed: Operations, Risk & Technology Officer and the Board of Directors.
+Added: The Company’s ISO has many years of experience appropriate to the role and is supported by skilled internal personnel.
+Added: The ISO is responsible for identifying, assessing and managing cybersecurity risks and designing, implementing and maintaining the Company’s information security program.
+Added: The ISO reports to the Chief Risk Officer and the Board of Directors.
Management’s enterprise risk management committee receives regular updates from the ISO on cybersecurity related risks, including trends and emerging threats .
+Added: NBB owns and has a branch bank in NBI’s headquarters located at 101 Hubbard Street, Blacksburg, Virginia.
+Added: NBB’s main office is at 100 South Main Street, Blacksburg, Virginia.
+Added: NBB owns an additional nineteen branch offices and a private office location for support functions, as well as a property nearing completion that will become its Roanoke branch location.
+Added: NBB leases six branch locations and one loan production office.
+Added: As of December 31, 2024, there were no mortgages or liens against any properties.
+Added: We believe that existing facilities are adequate for current needs and to meet anticipated growth.
+Added: A list of all branch and ATM locations is available on our website at www.nbbank.com .
+Added: Information contained on our website is not part of this report.
+Added: For additional information, please see Note 6 and Note 19 of Notes to Consolidated Financial Statements.
+Added: Legal Proceedings
+Added: NBI, NBB, and NBFS are not currently involved in any material pending legal proceedings.
+Added: There are no legal proceedings against the Company related to cybersecurity.
+Added: Mine Safety Disclosures
+Added: Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.