7 unchanged sentences
In addition to our information security team, we also employ a senior vice president of IT governance and risk who has over 18 years of IT governance, risk, and compliance experience and is responsible for the development, monitoring, and reporting of IT-related key risk indicators (“KRIs”), including KRIs related to cyber risks.
−Removed: Both our CISO and our senior vice president of IT governance and risk report to our chief information officer (“CIO”), who has more than 25 years of technology leadership experience, including leadership experience at global financial institutions, and is responsible, among other things, for oversight of our information technology environment, strategy, and security risks.
+Added: Both our CISO and our senior vice president of IT governance and risk report to our chief information officer (“CIO”), who has more than 25 years of technology leadership experience, including multiple years serving as chief information officer for regulated financial institutions and other industry verticals, and is responsible, among other things, for oversight of our information technology environment, strategy, and security risks.
As part of our information security program, we undertake efforts to monitor new and emerging risks and evaluate the effectiveness and maturity of our cyber defenses through various means, including internal audits, targeted testing (including penetration testing), incident response exercises, maturity assessments, and industry benchmarking.
22 unchanged sentences
The Company’s board of directors, or the board of directors of Simmons Bank (as applicable), also approves information security-related policies, including the Acceptable Use Policy, Information Security Policy, IT Ransomware Policy, and Business Continuity Management Policy.
−Removed: With respect to internal management, the CISO and CIO meet regularly to discuss the activities and operations of the information security team, and the CIO holds regular meetings with our chief executive officer to discuss cyber related matters, information technology issues, and cybersecurity threats.
+Added: With respect to internal management, the CISO and CIO meet regularly to discuss the activities and operations of the information security team, and the CIO holds periodic meetings with other members of our executive team to discuss cyber related matters, information technology issues, and cybersecurity threats.
To enhance awareness, monitoring, and oversight of cybersecurity risks, management also uses the following internal committees (in addition to the enterprise risk management committee discussed above):
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.