13 unchanged sentences
This includes monitoring of guidance issued by regulatory authorities, participating in professional forums, conducting both internal and external audits, collaborating with third-party services, reviewing policies, and adhering to best practice frameworks including Federal Financial Institutions Examination Council ("FFIEC") guidance and information security requirements established in the Gramm-Leach Bliley Act, along with other relevant state laws and agency regulations.
+Added: For instance, as part of our risk management framework, we regularly assess phishing threats targeting employees, conduct simulated attack exercises, and
+Added: implement enhanced endpoint detection solutions.
Furthermore, we emphasize the importance of maintaining a collaborative relationship with third-party service providers/vendors.
6 unchanged sentences
This collaborative effort is designed to foster complete visibility into the nature and scope of security risks and events, enabling a unified and effective response.
+Added: In addition to incident response, the Company implements robust data protection measures, including encryption protocols, multi-factor authentication, and data loss prevention controls, to safeguard sensitive information.
+Added: To ensure we can keep our operations running smoothly, we maintain and regularly test our business continuity and disaster recovery plans.
+Added: These measures help minimize disruption and ensure a swift recovery in the event of a cybersecurity incident.
Our SIRP is dynamic and adaptable, evolving in tandem with the ever-changing cybersecurity landscape.
By regularly updating and refining our response strategies, we remain prepared to confront emerging threats.
+Added: The Company also maintains a cyber insurance policy as part of its overall risk management strategy to mitigate financial losses in the event of a cybersecurity incident.
As of the reporting period, the Company has not experienced any material cybersecurity events or incidents.
Although third-party service providers have encountered cybersecurity events or incidents, these occurrences have not resulted in a material impact on our systems, computing environments, or data.
+Added: In determining materiality, the Company evaluates factors such as potential financial loss, operational disruptions, regulatory implications, and reputational harm.
+Added: The Company remains committed to enhancing its cybersecurity defenses through ongoing risk assessments, investment in technology, and adherence to industry best practices.
Our Board, supported by the ITBC and the ITSC, actively oversees our processes for management of cybersecurity risks and threats.
5 unchanged sentences
Our Chief Compliance Officer has been with the organization for over 37 years, with over 15 years of experience in compliance.
−Removed: These professionals bring diverse qualifications, certifications, and experience, ensuring a
−Removed: comprehensive approach to our information security initiatives.
−Removed: These qualifications and certifications include Certified Information Security Manager (CISM), Certified Banking Security Manager (CBSM), and Certified Information Security Professional (CISSP).
+Added: These professionals bring diverse qualifications, certifications, and experience, ensuring a comprehensive approach to our information security initiatives.
+Added: These qualifications and certifications include Certified Information Security Manager (CISM) and Certified Banking Security Manager (CBSM).
Our governance structure ensures a comprehensive approach to managing cybersecurity risks and threats, aligning with the Board-approved ISP.
5 unchanged sentences
The ISO is responsible for reporting, at least annually, to the Board of Directors on the status of the ISP, including overall compliance, risk management, vendor management, audit and testing results, breaches and incidents, and recommended updates to the ISP .
+Added: The Board also receives quarterly cybersecurity briefings that include updates on emerging threats, results of cybersecurity risk assessments, and the effectiveness of current controls.
+Added: These discussions inform strategic decision-making and resource allocation for cybersecurity investments.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.