1 unchanged sentence
Not applicable.
+Added: SOUND FINANCIAL BANCORP, INC.
+Added: AND SUBSIDIARY
Cybersecurity
3 unchanged sentences
Our cybersecurity risk management program contains eleven key elements:
−Removed: Information Security Policies, Strategic Planning, Risk Assessment, Audit and Examination, Business Continuity Planning, Incident Response Planning, Third-Party Due Diligence, Cyber Insurance Coverage, Employee Training and Testing, Patch and Vulnerability Management, and the Federal Financial Institutions Examination Council (“FFIEC”) Cyber Assessment Tool (“CAT”).
+Added: Information Security Policies, Strategic Planning, Risk Assessment, Audit and Examination, Business Continuity Planning, Incident Response Planning, Third-Party Due Diligence, Cyber Insurance Coverage, Employee Training and Testing, Patch and Vulnerability Management, and the National Institute of Standards and Technology (“NIST”) framework.
The Company is committed to protecting the information of clients, employees, and stakeholders from both conventional and cyber threats.
10 unchanged sentences
• Reporting, at least annually, to the Board on the status of the ISP, covering compliance, risk management, vendor management, audit and testing results, breaches and incidents, and recommended updates to the ISP.
−Removed: The Company’s approach to managing cybersecurity risks is shaped by insights from the FFIEC CAT, a tool designed for assessing and improving cybersecurity practices.
+Added: The Company’s approach to managing cybersecurity risks is shaped by insights from the NIST Cyber Security Framework (“CSF”) 2.0, a tool designed for assessing and improving cybersecurity practices.
This tool undergoes a thorough examination by an independent third-party on an annual basis to ensure an unbiased and comprehensive evaluation.
−Removed: In its most recent assessment in 2023, the FFIEC CAT identified that the Company is operating at an acceptable level of cyber maturity.
+Added: In its most recent assessment in 2025, the NIST CSF 2.0 identified that the Company is operating at an acceptable level of cyber maturity.
This means the Company is effectively handling the inherent risks it faces in five critical areas:
1 unchanged sentence
To stay ahead of potential cybersecurity challenges, the Company has established a formal process.
−Removed: This process is activated whenever the FFIEC CAT or the ISSC identifies changes in inherent risks.
+Added: This process is activated whenever the NIST CSF 2.0 or the ISSC identifies changes in inherent risks.
In response, the Company proactively updates its cybersecurity objectives, policies, and tactical goals.
5 unchanged sentences
Further, to enhance cybersecurity awareness, reduce vulnerability, and foster consideration of cybersecurity threats, our employees and the Board of Directors attend annual trainings.
−Removed: Specific role-based trainings are mandatory for certain employees, tailored to their duties.
+Added: Specific role-based training is mandatory for certain employees, tailored to their duties.
In the ordinary course of business, we rely heavily on electronic communications and information systems to conduct our operations and to store sensitive data.
4 unchanged sentences
While we have not
+Added: SOUND FINANCIAL BANCORP, INC.
+Added: AND SUBSIDIARY
identified significant compromises, substantial data losses, or major financial setbacks from cybersecurity attacks so far, our systems, along with those of our clients and service providers, face constant threats.
16 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.