2 unchanged sentences
Risk Management and Strategy
−Removed: The Company continuously monitors its information systems to proactively assess, identify, and manage risks from vulnerabilities and assess cybersecurity threats.
+Added: The Company recognizes that the security of our banking operations is critical to protecting our customers and maintaining our reputation.
+Added: The cybersecurity landscape is constantly evolving and the advent of artificial intelligence has increased the risks.
+Added: The Company maintains a cybersecurity risk management program designed to identify, assess, manage, and mitigate material risks from cybersecurity threats.
The Company’s process for identifying and assessing material risks from cybersecurity threats operates alongside the Company’s broader overall risk assessment process.
The Company’s Computer Security Incident Response Team immediately investigates system alerts that may indicate the presence of a cybersecurity threat or incident and escalates information regarding the threat or incident as necessary to address it in a timely manner.
−Removed: The Company also maintains a computer security incident response plan with formalized workflows and playbooks .
−Removed: The computer security incident response plan, among other things, provides for inter-departmental coordination and management of cybersecurity threats or incidents to quickly assess the impact, mitigate risks to information systems, and work to resolve vulnerabilities.
−Removed: We periodically conduct simulation exercises involving employees at various levels of the organization.
+Added: The Company maintains a written incident response plan with defined escalation procedures and cross functional coordination designed to assess impact, contain threats, and remediate vulnerabilities.
+Added: The incident response plan, among other things, provides for inter-departmental coordination and management of cybersecurity threats or incidents to quickly assess the impact, mitigate risks to information systems, and work to resolve vulnerabilities.
+Added: We conduct periodic tabletop exercises and simulations to test preparedness and response capabilities.
We also periodically engage external partners to conduct annual audits of our systems, test our systems infrastructure, and suggest improvements.
10 unchanged sentences
We consider customer education regarding the use of electronic convenience products to be especially important due to the Bank’s increased exposure to loss related to these products if procedures are not followed.
−Removed: To our knowledge, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected the Company, including its business strategy, results of operations or financial condition.
−Removed: With regard to the possible impact of future cybersecurity threats or incidents, see Part I.
−Removed: Item 1A, Risk Factors — Operational, Strategic and Business Risks.
−Removed: Management of cybersecurity risk is the responsibility of the full Board of Directors, with additional assistance from the Audit Committee.
+Added: Cybersecurity threats have not materially affected the Company's business strategy, results of operations, or financial condition.
+Added: For additional information regarding cybersecurity risks, see Part I, Item 1A, Risk Factors.
+Added: The Board of Directors oversees cybersecurity risk, with assistance from the Audit Committee.
The Board of Directors also devotes significant time and attention to the oversight of cybersecurity and information security risk and receives an operational risk update that includes a review of cybersecurity and information security risk.
2 unchanged sentences
At the management level, the Chief Information Officer and Information Security Officer receive regular reports from the Company’s systems department, both historical and real-time, about the Company’s cybersecurity status.
−Removed: The Company has established written policies and procedures to ensure that significant cybersecurity incidents are immediately investigated, addressed through the coordination of various internal departments, and publicly reported (to the extent required by applicable law).
−Removed: management determines a material cybersecurity incident has occurred, the Company’s policies require management to promptly inform the Audit Committee with follow-up information to the full Board of Directors.
−Removed: Under the direction of the Chief Information Officer, the Information Security Officer is responsible for cybersecurity and business continuity, which includes security architecture, security operations, incident response, IT risk and compliance, and security awareness and training.
−Removed: The Information Security Officer has over 40 years of security & risk management experience among other disciplines.
−Removed: The Cybersecurity Program Manager who reports directly to and supports the Information Security Officer in various aspects of cybersecurity and business continuity in the Company is a Certified Information Systems Security Professional (CISSP) and a Certified Information Systems Auditor (CISA), The other members of the Company’s information security organization also have extensive cybersecurity, business, and technology experience and hold certifications in their area of expertise.
+Added: The Company maintains processes designed to identify, escalate, and report cybersecurity incidents in accordance with applicable law and regulation.
+Added: If management determines a material cybersecurity incident has occurred, the Company’s policies require management to promptly inform the Audit Committee with follow-up information to the full Board of Directors.
+Added: The Information Security Officer leads the Company's cybersecurity program, including security operations, incident response, risk and compliance, and security awareness.
+Added: The cybersecurity team includes professionals with relevant industry experience and certifications.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.