18 unchanged sentences
Any change in employment responsibilities that requires access changes is implemented using the same access approval procedures.
−Removed: Finally, all remote access into the Company’s networks must be approved by the Chief Information Security Officer (which we refer to as the “CISO”).
+Added: Finally, all remote access into the Company’s networks must be approved by the Chief Information Security Officer (whom we refer to as the “CISO”).
• Vulnerability and patch management:
1 unchanged sentence
Software patches are deployed based on criticality of vulnerability.
−Removed: Further, we track our performance in implementing patches, and if implementation timing falls below performance expectations, management will take steps to identify and remediate the root causes of implementation delays.
+Added: Further, we track our performance in implementing patches, and if implementation timing falls below performance expectations, management takes steps to identify and remediate the root causes of implementation delays.
• Risk assessments:
7 unchanged sentences
Information security is an integral component of our employee training program.
−Removed: Training includes efforts to maintain security awareness among employees at all times by means of company-wide communications of cybersecurity risks or incidents affecting third parties, internal testing and similar efforts.
+Added: Training includes efforts to maintain security awareness among employees at all times by means of required company-wide communications of cybersecurity risks or incidents affecting third parties, internal testing and similar efforts.
The information security program applies to all of the Company’s business lines and employees as well as to vendors and other third parties with access to the Company’s information systems or its confidential and proprietary information.
−Removed: Whenever we consider a new product or service to offer to our clients, or a new means of offering or providing an existing product or service, or a new back-office process or procedure, the implications to the Company’s information security are required to be considered.
+Added: Whenever we consider a new product or service to offer to our clients, a new means of offering or providing an existing product or service, or
+Added: a new back-office process or procedure (each of which may involve the incorporation of AI technologies), the implications to the Company’s information security are required to be considered.
+Added: The discussion below under the “Governance and Oversight” heading provides more details about how our efforts to address cybersecurity risks are incorporated into the Company’s overall enterprise risk management program.
Our CISO, a Certified Information Systems Security Professional, leads the Company’s information security team, which has over 50 years’ combined experience in providing solutions to manage information security, compliance, privacy and technology management.
4 unchanged sentences
These controls include appropriate access controls based on least privilege, multifactor authentication for remote and privilege access, and encryption to protect data.
−Removed: The information security program is designed to comply with applicable laws and regulations and is driven by industry standards for financial institutions, including the Federal Financial Institutions Examination Council (“FFIEC”) Cybersecurity Assessment Tool, as well as by the guidance promulgated by the National Institute of Standards and Technology (“NIST”).
+Added: The information security program is designed to comply with applicable laws and regulations and is driven by industry standards for financial institutions, including guidance promulgated by the National Institute of Standards and Technology (“NIST”).
We work closely with government and industry associations to stay abreast of developments and share best practices with respect to cybersecurity.
2 unchanged sentences
in certain circumstances a new or emerging cybersecurity threat may require modifications to how we conduct business.
−Removed: The Company’s information security team utilizes the Financial Services Sector Coordinating Council for Critical Infrastructure Protection and Homeland Security version of the FFIEC Cybersecurity Assessment Tool to perform an annual assessment of our information security program.
+Added: The Company’s information security team utilizes the NIST Cybersecurity Framework to perform an annual maturity assessment of our information security program.
The assessment provides a repeatable and measurable process for institutions to measure their cybersecurity preparedness over time.
−Removed: The assessment incorporates cybersecurity-related principles from the FFIEC Information Technology Examination Handbook and regulatory guidance, and concepts from other industry standards, including the NIST Cybersecurity Framework.
−Removed: The assessment consists of two parts:
−Removed: Inherent Risk Profile and Cybersecurity Maturity.
−Removed: The Cybersecurity Maturity aspect of the assessment is designed to help management measure the institution’s level of risk and corresponding controls.
−Removed: The levels range from baseline to innovative.
−Removed: Cybersecurity Maturity includes tests to determine whether an institution’s behaviors, practices and processes can support cybersecurity preparedness within the following five domains:
−Removed: • Cyber risk management and oversight
−Removed: • Threat intelligence and collaboration
−Removed: • Cybersecurity controls
−Removed: • External dependency management
−Removed: • Cyber incident management and resilience
+Added: The assessment incorporates cybersecurity-related principles , including the Federal Financial Institutions Examination Council’s Information Technology Examination Handbook and regulatory guidance, and concepts from other industry standards.
We also retain third parties to test the effectiveness of our cybersecurity efforts.
−Removed: Annually, we obtain independent third party audits of the information security program, including program maturity and overall control effectiveness.
+Added: Annually, we obtain independent third party assessments of the information security program, including program maturity and overall control effectiveness.
In addition, multiple times over the course of each year we engage third party security firms to conduct both external and internal penetration tests.
2 unchanged sentences
we also consider other recommendations to enhance our cybersecurity that these security firms may offer, implementing those that management concludes are appropriate within the context of the Company’s information security program and processes.
−Removed: In addition to audits and testing by third party security firms, our information security program and infrastructure is subject to continuous supervision by the FDIC and the DBCF, including an annual in-depth examination by subject-matter experts from the FDIC and DBCF.
−Removed: The laws and regulations that these regulators administer impose very high expectations on the Company
−Removed: with respect to its information security policies, procedures, processes and controls.
+Added: In addition to assessments and testing by third party security firms, our information security program and infrastructure is subject to continuous supervision by the Federal Reserve and the DBCF, including an annual in-depth examination by subject-matter experts from the Federal Reserve and DBCF.
+Added: The laws and regulations that these regulators administer impose very high expectations on the Company with respect to its information security policies, procedures, processes and controls.
In particular, the Interagency Guidelines Establishing Information Security Standards (the “Guidelines”) require us to implement a comprehensive written information security program that includes administrative, technical and physical safeguards designed to (1) ensure the security and confidentiality of customer information;
7 unchanged sentences
Diligence of Vendors and Other Third Parties .
−Removed: As noted above, the Company’s information security program applies to our vendors and other third parties (referred to collectively as “vendors”) with access to our information systems and networks and/or confidential and proprietary information.
−Removed: Before we grant access to the Company’s systems or a vendor otherwise obtains access to the Company’s confidential and proprietary information, our information security team assesses the vendor’s information security program.
+Added: As noted above, the Company’s information security program applies to our vendors and other third parties (referred to collectively as “vendors”) with access to our information systems and networks and/
+Added: or confidential and proprietary information.
+Added: Before we grant access to the Company’s systems or a vendor otherwise obtains access to the Company’s confidential and proprietary information, our information security team assesses the vendor’s information security program (including its diligence with respect to the information security of vendors to such vendor).
We review the vendor’s information security policy (to the extent the third party is willing to provide a copy of such policy), information security audits, service organization reports and similar information as well as examination reports of the vendor if available from the banking regulators or other governmental entities;
−Removed: the team will also investigate the background, reputation and history of prior cybersecurity incidents of such vendor or other third party.
−Removed: If the information security team is not satisfied that the vendor’s information security infrastructure is adequate to reasonably protect the Company’s systems and confidential and proprietary information from unauthorized access, and there are no suitable solution to address the information security team’s concerns, then we will not engage such vendor.
+Added: the team also investigates the background, reputation and history of prior cybersecurity incidents of such vendor or other third party.
+Added: If the information security team is not satisfied that the vendor’s information security infrastructure is adequate to reasonably protect the Company’s systems and confidential and proprietary information from unauthorized access, and there are no suitable solutions to address the information security team’s concerns, then we will not engage such vendor.
The vendors we retain are also categorized by the level of risk that the vendor presents to us, of which information security risk is a component.
−Removed: The information security team annually reviews those vendors in the “high risk” category and periodically reviews other vendors.
−Removed: This review includes obtaining updated information security audits and service organization reports, where available, and otherwise analyzing whether the vendor’s cybersecurity risk profile has materially changed.
+Added: The information security team works with our risk management services team to complete annual reviews of those vendors in the “Critical” or “Significant” categories and periodically reviews other vendors.
+Added: This review includes obtaining updated information security audits and service organization reports, where available, mapping end user controls considerations to the Company’s existing internal control framework, and otherwise analyzing whether the vendor’s cybersecurity risk profile has materially changed.
The information security team’s review process does not, and cannot, guarantee that a Company vendor will not suffer a cybersecurity incident that impacts us.
4 unchanged sentences
The incident response team includes representatives from the information technology, operations, risk management, legal (including securities law counsel), privacy and finance departments, among others.
−Removed: In addition to meeting quarterly, the incident response team (or a subset of the team) gathers whenever there is a threatened or actual breach of the Company’s information security (whether involving an external actor or an internal party) to determine the nature and extent of the threatened or actual breach and, if appropriate, the steps to take in response thereto to protect the Company’s information security and mitigate any harm that has already occurred.
+Added: In addition to meeting quarterly, the incident response team (or a subset of the team) gathers whenever there is a potential or actual breach of the Company’s information security (whether involving an external actor or an internal party) to determine the nature and extent of the situation and, if appropriate, the steps to take in response thereto to protect the Company’s information security and mitigate any harm that has already occurred.
The team is also responsible for ensuring the Company complies with legal and regulatory requirements (including notifying affected customers and regulators and making any filings required by the securities laws).
6 unchanged sentences
For example, over the course of 2025, employees received at least one email per quarter designed to test employees’ ability to identify and avoid potential “phishing” emails, and those employees that fail this phishing test are assigned additional training.
−Removed: In addition, annually the Company’s incident
−Removed: response team engages in a cyber attack tabletop exercise designed by the Financial Services Information Sharing and Analysis Center that helps to train the incident response team in overcoming a simulated attack against Renasant’s payment systems and processes.
+Added: In addition, annually the Company’s incident response team engages in a cyber attack tabletop exercise designed by the Financial Services Information Sharing and Analysis Center that helps to train the incident response team in overcoming a simulated attack against Renasant’s payment systems and processes.
Governance and Oversight
4 unchanged sentences
The efforts of our information security team to address cybersecurity risk are reviewed by the Company’s Risk Department, which oversees our enterprise risk management program.
−Removed: The department focuses on the quality of the Company’s risk management process in order to manage risks within acceptable tolerance levels.
+Added: The department focuses on the quality of the Company’s risk
+Added: management process in order to manage risks within acceptable tolerance levels.
As it pertains to cybersecurity risk, the Risk Department challenges the processes that the information security team has implemented to identify, assess, control and mitigate cybersecurity risk.
7 unchanged sentences
The Internal Audit Department reports the results of its review, including the steps management intends to take to address any findings, to the Audit Committee of the Board of Directors.
−Removed: Finally, as a means to ensure that our senior executive management has an integrated understanding of the cybersecurity and other risks facing the company at any particular time, the Company has organized a Management Enterprise Risk Management Committee (the “management ERM committee”).
−Removed: Our Chief Risk Officer leads this committee, whose membership includes the Company’s President and the leaders of our major business lines and back-office functions.
−Removed: Among other things, the management ERM committee reviews the Company’s cybersecurity and other risk metrics and the direction in which each risk is trending (increasing risk or decreasing risk), both in isolation and in the context of other existing and emerging risks facing the company, and the status of risk mitigants therefor.
−Removed: We believe that this committee helps management better focus its efforts to minimize cybersecurity risk and that it assists in more focused reporting of cybersecurity risks to the Board of Directors.
+Added: Finally, as a means to ensure that our senior executive management has an integrated understanding of the cybersecurity and other risks facing the Company at any particular time, we have organized a management Enterprise Risk and Compliance Committee (the “ERCC”).
+Added: Our Chief Risk Officer leads this committee, whose membership includes our Chief Executive Officer and the leaders of our major business lines and back-office functions.
+Added: Among other things, the ERCC reviews the Company’s cybersecurity and other risk metrics and the direction in which each risk is trending (increasing risk or decreasing risk), both in isolation and in the context of other existing and emerging risks facing the company, and the status of related risk mitigation.
+Added: We believe that this committee helps management better focus its efforts on minimizing cybersecurity risk and that it assists in more focused reporting of cybersecurity risks to the Board of Directors.
Board Oversight .
6 unchanged sentences
These metric reports give the ERM Committee a broad view of the aggregate cybersecurity risk that the Company faces at any particular time, insight into any particular areas of risk as well as an opportunity for the ERM Committee to discuss with management the steps taken or to be taken to address risks that are out of tolerance or trending in that direction.
−Removed: In addition to this report, the CISO’s report to the
−Removed: Technology Committee described above is included the materials for ERM Committee meetings.
+Added: In addition to this report, the CISO’s report to the Technology Committee described above is included in the materials for ERM Committee meetings.
The chair of the Technology Committee is a member of the ERM Committee, enabling the chair to convey to the ERM Committee details of the discussions with respect to the CISO’s report as well as other matters related to our technological infrastructure and the impact thereof on matters within the ERM Committee’s focus.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.