18 unchanged sentences
Any change in employment responsibilities that requires access changes is implemented using the same access approval procedures.
−Removed: Finally, all remote access into the Company’s networks must include approval by the Chief Information Security Officer (which we refer to as the “CISO”).
+Added: Finally, all remote access into the Company’s networks must be approved by the Chief Information Security Officer (which we refer to as the “CISO”).
• Vulnerability and patch management:
13 unchanged sentences
The information security program applies to all of the Company’s business lines and employees as well as to vendors and other third parties with access to the Company’s information systems or its confidential and proprietary information.
−Removed: Whenever we consider a new product or service to offer to its clients, or a new means of offering or providing an existing product or service, or a new back-office process or procedure, the implications to the Company’s information security are required to be considered.
+Added: Whenever we consider a new product or service to offer to our clients, or a new means of offering or providing an existing product or service, or a new back-office process or procedure, the implications to the Company’s information security are required to be considered.
Our CISO, a Certified Information Systems Security Professional, leads the Company’s information security team, which has over 50 years’ combined experience in providing solutions to manage information security, compliance, privacy and technology management.
−Removed: The Board of Directors’ Technology Committee and its Enterprise Risk Management Committee oversee our information security team, receiving regular updates related to the material features of the information security program, our success and failures in maintaining information security and emerging threats and management’s proposed response thereto.
+Added: The Board of Directors’ Technology Committee and its Enterprise Risk Management Committee (the “ERM Committee”) oversee our information security team, receiving regular updates related to the material features of the information security program, our success and failures in maintaining information security and emerging threats and management’s proposed response thereto.
Strategy and Testing .
27 unchanged sentences
In addition to audits and testing by third party security firms, our information security program and infrastructure is subject to continuous supervision by the FDIC and the DBCF, including an annual in-depth examination by subject-matter experts from the FDIC and DBCF.
−Removed: The laws and regulations that these regulators administer impose very high expectations on the Company with respect to its information security policies, procedures, processes and controls.
−Removed: In particular, the Interagency Guidelines
−Removed: Establishing Information Security Standards (the “Guidelines”) require us to implement a comprehensive written information security program that includes administrative, technical and physical safeguards designed to (1) ensure the security and confidentiality of customer information;
+Added: The laws and regulations that these regulators administer impose very high expectations on the Company
+Added: with respect to its information security policies, procedures, processes and controls.
+Added: In particular, the Interagency Guidelines Establishing Information Security Standards (the “Guidelines”) require us to implement a comprehensive written information security program that includes administrative, technical and physical safeguards designed to (1) ensure the security and confidentiality of customer information;
(2) protect against any anticipated threats or hazards to the security or integrity of such information;
29 unchanged sentences
For example, over the course of 2024, employees received at least one email per quarter designed to test employees’ ability to identify and avoid potential “phishing” emails, and those employees that fail this phishing test are assigned additional training.
−Removed: In addition, annually the Company’s incident response team engages in a cyber attack tabletop exercise designed by the Financial Services Information Sharing and Analysis
−Removed: Center that helps to train the incident response team in overcoming a simulated attack against Renasant’s payment systems and processes.
+Added: In addition, annually the Company’s incident
+Added: response team engages in a cyber attack tabletop exercise designed by the Financial Services Information Sharing and Analysis Center that helps to train the incident response team in overcoming a simulated attack against Renasant’s payment systems and processes.
Governance and Oversight
2 unchanged sentences
The first line of defense against cybersecurity risk is the company’s information security team, led by the CISO.
−Removed: This team is primarily responsible for promptly identifying cybersecurity risks associated with our existing and anticipated operations and, once identified, assessing as to the level that each cybersecurity risk poses to us, and then controlling or mitigating to the extent reasonably possible (in the context the Company’s operations and resources, and competitive factors affecting how banks and other financial services companies conduct operations, among other things).
+Added: This team is primarily responsible for promptly identifying cybersecurity risks associated with our existing and anticipated operations and, once identified, assessing the level that each cybersecurity risk poses to us, and then controlling or mitigating to the extent reasonably possible (in the context of the Company’s operations and resources, and competitive factors affecting how banks and other financial services companies conduct operations, among other things).
The efforts of our information security team to address cybersecurity risk are reviewed by the Company’s Risk Department, which oversees our enterprise risk management program.
14 unchanged sentences
Board Oversight .
−Removed: The Company’s Board of Directors primarily oversees the risks related to our technological infrastructure, information security, cybersecurity, business continuity and disaster recovery programs through its Technology Committee and its Enterprise Risk Management Committee (the “ERM Committee”).
+Added: The Company’s Board of Directors primarily oversees the risks related to our technological infrastructure, information security, cybersecurity, business continuity and disaster recovery programs through its Technology Committee and the ERM Committee.
These committees meet quarterly, and their activities are reported to the full Board of Directors.
2 unchanged sentences
The ERM Committee incorporates the assessment, monitoring and mitigation of cybersecurity risk into its monitoring of the Company’s broader enterprise risk management function.
−Removed: At each meeting of the ERM Committee, the Chief Risk Officer reports on the status within established tolerances of each risk metric as well as the assessment of the direction such metric is trending.
+Added: The Company tracks numerous risk metrics relating to cybersecurity, and at each meeting of the ERM Committee, the Chief Risk Officer reports on the status within established tolerances of each risk metric as well as the assessment of the metric’s trend of increasing or decreasing risk.
These metric reports give the ERM Committee a broad view of the aggregate cybersecurity risk that the Company faces at any particular time, insight into any particular areas of risk as well as an opportunity for the ERM Committee to discuss with management the steps taken or to be taken to address risks that are out of tolerance or trending in that direction.
−Removed: In addition to this report, the CISO’s report to the Technology Committee is included the materials for ERM meetings.
−Removed: The chair of the
−Removed: Technology Committee is a member of the ERM Committee, enabling the chair to convey to the ERM Committee details of the discussions with respect to the CISO’s report as well as other matters related to our technological infrastructure and the impact thereof on matters within the ERM Committee’s focus.
−Removed: Finally, at each ERM Committee meeting our Chief Technology Officer addresses various information technology topics with the ERM Committee.
+Added: In addition to this report, the CISO’s report to the
+Added: Technology Committee described above is included the materials for ERM Committee meetings.
+Added: The chair of the Technology Committee is a member of the ERM Committee, enabling the chair to convey to the ERM Committee details of the discussions with respect to the CISO’s report as well as other matters related to our technological infrastructure and the impact thereof on matters within the ERM Committee’s focus.
+Added: Finally, the CISO attends ERM Committee meetings, providing additional detail, and answering committee members’ questions, about the CISO’s report.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.