5 unchanged sentences
Peoples assesses itself against the Federal Financial Institutions Examination Council’s (“FFIEC”) Cybersecurity Assessment Tool (“CAT”) on a quarterly basis.
+Added: Beginning in 2025, Peoples will assess itself using the Cyber Risk Institute Tool (“CRIT”) on at least an annual basis.
Additional assessment of Peoples’ cybersecurity capabilities is performed by consultants and regulators annually.
1 unchanged sentence
Peoples also has a third-party risk management program pursuant to which Peoples performs annual reviews of third-party vendors as to their cybersecurity and business continuity capabilities to ensure they meet the stated requirements and the risk appetite of Peoples as documented in Peoples’ information security policy.
−Removed: Vendors not meeting Peoples’ risk requirements are notified of
−Removed: necessary improvements and, if the vendors cannot mitigate the identified risks, Peoples looks to identify alternative vendors.
+Added: Vendors not meeting Peoples’ risk requirements are notified of necessary improvements and, if the vendors cannot mitigate the identified risks, Peoples looks to identify alternative vendors.
Documentation of performance of the third-party risk assessments is retained and acknowledged by appropriate Risk and Information Security employees of Peoples.
4 unchanged sentences
At least annually, the Risk Committee reviews and reassesses the adequacy of its charter and recommends any proposed changes to the full Board as necessary to reflect changes in regulatory requirements, authoritative guidance and evolving practices.
−Removed: The Risk Committee provides a report to the entire Board at each meeting of the Board of Directors regarding the overall risk condition of the firm and whether Peoples risk remain within its stated risk appetite.
−Removed: Peoples’ Chief Risk Officer (“CRO”) reports to the Risk Committee and the Chief Operating Officer and has primary responsibility for the design and implementation of the ERM Program.
+Added: On at least a quarterly basis, Peoples’ Chief Risk Officer provides a report to the Risk Committee regarding the overall risk condition of Peoples and whether it is within Peoples’ stated risk appetite.
+Added: Peoples’ Chief Risk Officer (“CRO”) reports to the Risk Committee and the CEO and has primary responsibility for the design and implementation of the ERM Program.
The ERM Program establishes Peoples’ risk appetite, monitors key risk and performance indicators, identifies key risks within the firm, designs and executes specific risk initiatives and monitors risk mitigation efforts and control processes.
4 unchanged sentences
The CISO has primary responsibility for assessing and responding to material risks from cybersecurity threats.
−Removed: The current CISO is an experienced Information Security and Information Technology officer with 21 years of experience in Information Security and Information Technology and a master’s degree in business administration.
−Removed: The CISO is also a Certified Information Systems Security Professional (“CISSP”), which is an industry recognized certification that recognizes cybersecurity professionals with the knowledge, skills and abilities to lead an organization’s information security program.
+Added: The current CISO is an experienced Information Security and Information Technology professional with over 25 years of experience specializing in cyber defense, vulnerability management, security operations, recovery management and as a Windows system engineer.
On a quarterly basis, the CISO updates the Risk Committee on the state of cybersecurity and potential risks to Peoples’ to be considered by the Risk Committee.
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.