5 unchanged sentences
Cybersecurity risk management processes are integrated into this program, given the increasing reliance on technology and potential of cyber threats.
−Removed: The cybersecurity risk management program contains eleven key elements:
+Added: Our cybersecurity risk management program contains eleven key elements:
Information Security Policies, Strategic Planning, Risk Assessment, Audit and Examination, Business Continuity Planning, Incident Response Planning, Third-Party Due Diligence, Cyber Insurance Coverage, Employee Training and Testing, Patch and Vulnerability Management, and the Federal Financial Institutions Examination Council (“FFIEC”) Cyber Assessment Tool (“CAT”).
1 unchanged sentence
This commitment is upheld through the implementation of our comprehensive Information Security Program (“ISP”), designed to ensure the confidentiality, integrity, and availability of critical information technology (“IT”) systems and data.
−Removed: The Information Security Governance Committee (“ISGC”), appointed by the Board, bears the responsibility for cybersecurity risk management and strategy.
+Added: The Information Security Steering Committee (“ISSC”), appointed by the Board, bears the responsibility for cybersecurity risk management and strategy.
It aids the Board in fulfilling its oversight duties related to IT security, aligning with the Bank’s business strategy, and adhering to regulatory requirements.
−Removed: The Virtual Chief Information Security Officer (“vCISO”), who is also appointed by the Board, oversees the ISP and coordinates the ISGC.
−Removed: The ISGC's responsibilities encompass:
+Added: The Virtual Chief Information Security Officer (“vCISO”), who is also appointed by the Board, oversees the ISP and coordinates the ISSC.
+Added: The ISSC's responsibilities encompass:
• Review and approval of the ISP-related documents, including policies, strategies, plans and risk assessments;
2 unchanged sentences
• Providing input on mitigation of current issues and threats;
−Removed: • Reporting, at least quarterly, to the Enterprise Risk Management Committee on ISGC activities and risk impacts on the Risk Appetite Statement.
+Added: • Reporting, at least quarterly, to the Enterprise Risk Management Committee on ISSC activities and risk impacts on the Risk Appetite Statement.
• Reporting, at least annually, to the Board on the status of the ISP, covering compliance, risk management, vendor management, audit and testing results, breaches and incidents, and recommended updates to the ISP.
2 unchanged sentences
In its most recent assessment in 2023, the FFIEC CAT identified that the Company is operating at an acceptable level of cyber maturity.
−Removed: This means the bank is effectively handling the inherent risks it faces in five critical areas:
+Added: This means the Company is effectively handling the inherent risks it faces in five critical areas:
cyber risk management and oversight, collaboration on threat intelligence, implementation of cybersecurity controls, management of external dependencies, and resilience in handling cyber incidents.
To stay ahead of potential cybersecurity challenges, the Company has established a formal process.
−Removed: This process is activated whenever the FFIEC CAT or the ISGC identifies changes in inherent risks.
+Added: This process is activated whenever the FFIEC CAT or the ISSC identifies changes in inherent risks.
In response, the Company proactively updates its cybersecurity objectives, policies, and tactical goals.
11 unchanged sentences
Attackers adapt quickly to changes in defense measures.
−Removed: While we have not identified significant compromises, substantial data losses, or major financial setbacks from cybersecurity attacks so far, our systems, along with those of our clients and service providers, face constant threats.
−Removed: There is no guarantee that our
−Removed: cybersecurity risk management program will completely safeguard the confidentiality, integrity, and availability of our information systems and solutions.
+Added: While we have not
+Added: identified significant compromises, substantial data losses, or major financial setbacks from cybersecurity attacks so far, our systems, along with those of our clients and service providers, face constant threats.
+Added: There is no guarantee that our cybersecurity risk management program will completely safeguard the confidentiality, integrity, and availability of our information systems and solutions.
Cybersecurity risks are anticipated to stay elevated due to the evolving nature of threats and the increased use of online and mobile banking services.
1 unchanged sentence
Risk Factors” in this Form 10-K for a further discussion of risks related to cybersecurity.
−Removed: The Board of Directors is responsible for the development, implementation, and maintenance of the ISP.
−Removed: Specifically, the Board is oversees:
−Removed: • Continuous administration of the ISP;
−Removed: • Perform an annual review and approval of the ISP policies;
−Removed: • Assignment of critical roles, including the vCISO;
−Removed: • Review of reports provided by the ISGC at least annually.
−Removed: Adherence to the ISP is of utmost importance, and any exceptions to policy must be recommended by the ISGC, approved by the Enterprise Risk Management Committee, and reported to the Board at least annually.
−Removed: As previously stated, the ISGC, appointed by the Board, bears the responsibility for cybersecurity risk management and strategy.
−Removed: The vCISO oversees the ISP and coordinate with the ISGC.
−Removed: The ISGC includes key personnel including the vCISO, Chief Operating Officer, Technology Services Director, Information Technology Manager, Internal Audit Manager, Compliance Manager, and Information Security Specialists.The ISGC members bring diverse qualifications, certifications, and extensive experience to the table.
+Added: The Board of Directors oversees cybersecurity risk management as part of its broader risk oversight responsibilities.
+Added: The Board receives at least annual reports from the ISSC on cybersecurity risks, emerging threats, regulatory developments, and the effectiveness of our information security program.
+Added: The Board also reviews and approves the ISP annually to ensure alignment with business strategy and regulatory requirements.
+Added: The ISSC, chaired by the vCISO, is responsible for implementing cybersecurity risk management policies and strategies.
+Added: The vCISO, appointed by the Board, has extensive experience in information security, holding various professional certifications, including a Certified Information Systems Security Professional (“CISSP”).
+Added: The ISSC also includes senior executives from risk, compliance, IT, and internal audit functions, ensuring a multidisciplinary approach to managing cybersecurity threats.
+Added: Adherence to the ISP is of utmost importance, and any exceptions to policy must be recommended by the ISSC, approved by the Enterprise Risk Management Committee, and reported to the Board at least annually.
+Added: The ISSC includes key personnel including the vCISO, Chief Operating Officer, Technology Services Director, Information Technology Manager, Internal Audit Manager, Compliance Manager, and Information Security Specialists.
+Added: The ISSC members bring diverse qualifications, certifications, and extensive experience to the table.
This collective expertise ensures a comprehensive and well-rounded approach to our information security initiatives.
1 unchanged sentence
The responsibilities include cybersecurity risk assessment, defense operations, incident response, vulnerability assessment, threat intelligence, identity access governance, third-party risk management, client, vendor and employee education and awareness, and business continuity and disaster recovery.
−Removed: The ISGC, as a whole, consists of information security professionals with varying degrees of professional education, certifications and experience.
−Removed: This blend of diverse qualifications, certifications, and experience within the ISGC ensures a comprehensive and flexible approach to information security, positioning the Company to address emerging threats and maintain a robust defense against potential risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.