6 unchanged sentences
Our objective for managing cybersecurity risk is to avoid or minimize the impacts of external threat events or other efforts to penetrate, disrupt or misuse our systems or information.
−Removed: The structure of our information security program is designed around the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, Federal Financial Institution Examination Council (“FFIEC”) Cybersecurity Assessment Tool, regulatory guidance, and other industry standards.
+Added: The structure of our information security program is designed around the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, regulatory guidance, and other industry standards.
In addition, we leverage certain industry and government associations, third-party benchmarking, audits, and threat intelligence feeds to facilitate and promote program effectiveness.
13 unchanged sentences
The Incident Response Plan facilitates coordination across multiple parts of our organization and is evaluated at least annually.
+Added: The plan also defines escalation pathways to senior management, including the Chief Risk Officer, General Counsel, and Chief Financial Officer, to support determinations regarding materiality and any related public disclosures or regulatory notifications.
Notwithstanding our defensive measures and processes, the threat posed by cyber-attacks is severe.
33 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.