15 unchanged sentences
The Company conducts a variety of information security assessments throughout the year, both internally and through third-party specialists.
+Added: These assessments include regular penetration testing and periodic third-party audits to validate the effectiveness of our controls.
In designing our Information Security Program, we refer to established industry frameworks - in particular, the Federal Financial Institutions Examination Council (FFIEC) and guidance and best practices from the National Institute of Standards and Technology (NIST).
12 unchanged sentences
We have developed a formal cybersecurity incident response plan that summarizes the steps the Company will take to respond to a cybersecurity incident.
−Removed: The plan includes an Information Security Incident Response Team (ISIRT), which is responsible for
−Removed: addressing and coordinating all aspects of the Company's response to cybersecurity events.
−Removed: The ISIRT is supported by operating procedures and guidelines designed to outline the expectations and processes to be followed when responding to incidents of unauthorized access to confidential information maintained by the Company or its service providers.
+Added: The plan includes an Information Security Incident Response Team (ISIRT), which is responsible for addressing and coordinating all aspects of the Company's response to cybersecurity events.
+Added: The ISIRT is supported by operating procedures and guidelines designed to outline the expectations and processes to be followed when responding to incidents of
+Added: unauthorized access to confidential information maintained by the Company or its service providers.
The ISIRT may consult legal counsel and other external experts in connection with their respective activities.
2 unchanged sentences
Associated risk metrics are monitored quarterly by Management and reported to the Audit Committee of the Board and the Board of Directors.
−Removed: Management measures and reports inherent risk, mitigating controls, residual risk and emerging risk for various key risk categories, inclusive of cybersecurity and information security risks.
+Added: Management measures and reports inherent risk, mitigating controls, residual risk and emerging risk for various key risk categories, inclusive of cybersecurity and information security risks, on at least a quarterly basis.
The Company's governance and oversight of cybersecurity risks are facilitated through our Information Security Program, which establishes administrative, technical, and physical safeguards designed to protect the confidential information and records of all the Bank's clients in accordance with FDIC regulations.
2 unchanged sentences
We maintain relevant expertise within the Bank's management team to manage cybersecurity risks.
−Removed: In particular, the Board has appointed a Chief Information Security Officer.
−Removed: Together with the Risk and Audit Manager, they provide direction and oversight for information and cyber-security related activities across the Company—including existing and emerging initiatives, service provider arrangements, incident response, business continuity management, staff training, monitoring of key controls and adjusting the information security program in response to changes in operations and internal/external threats and vulnerabilities.
−Removed: Our Information Security Management team, among other things, is responsible for conducting risk assessments, designing the Information Security Program to manage identified risks based on information sensitivity and the Company’s operational complexity, overseeing service provider arrangements, establishing risk-based response programs for incidents of unauthorized access, providing staff training, conducting testing of key controls, systems, and procedures, and adjusting the program in response to changes in people, processes, technology, sensitive information, threats, and the business environment (e.g., mergers, acquisitions, alliances, joint ventures, or outsourcing arrangements).
+Added: In particular, the Board has appointed a Chief Information Security Officer (CISO).
+Added: Together with the Director of Risk Management, they provide direction and oversight for information and cyber-security related activities across the Company—including existing and emerging initiatives, service provider arrangements, incident response, business continuity management, staff training, monitoring of key controls and adjusting the information security program in response to changes in operations and internal/external threats and vulnerabilities.
+Added: In this role, the CISO leverages 24 years of information technology experience and has maintained various applicable cybersecurity and IT audit certifications.
+Added: Our Information Security Management team , among other things, is responsible for conducting risk assessments , designing the Information Security Program to manage identified risks based on information sensitivity and the Company’s operational complexity, overseeing service provider arrangements, and managing risks associated with third-party service providers by conducting due diligence prior to engagement and ongoing monitoring of vendors’ security practices, including their ability to prevent, detect, and respond to cybersecurity threats.
+Added: They also establish risk-based response programs for incidents of unauthorized access, providing staff training, conducting testing of key controls, systems, and procedures, and adjusting the program in response to changes in people, processes, technology, sensitive information, threats, and the business environment (e.g., mergers, acquisitions, alliances, joint ventures, or outsourcing arrangements).
The Board of Directors plays a crucial role, annually reviewing and approving our Information Security Program.
1 unchanged sentence
Additionally, the Board of Directors' Technology Committee considers information technology and cybersecurity expertise when assessing potential director candidates, to help ensure the Board of Directors has the capability to appropriately oversee management's activities in these areas.
+Added: The Board receives regular updates from the CISO and Director of Risk Management regarding cybersecurity threats and program enhancements.
+Added: In evaluating its oversight capabilities, the Board considers relevant cybersecurity expertise among its members and provides ongoing training where appropriate.
+Added: As of the date of this report, the Company has not experienced any cybersecurity incidents that have had a material impact on its business strategy, financial condition, or results of operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.