12 unchanged sentences
The S&T Information Security Program utilizes a defense in depth strategy that leverages multiple security measures to protect the bank's assets.
−Removed: We encrypt and leverage data loss prevention technology for sensitive data and use advanced transport
−Removed: S&T BANCORP, INC.
−Removed: AND SUBSIDIARIES
−Removed: layer security encryption for our applications.
+Added: We encrypt and leverage data loss prevention technology for sensitive data and use advanced transport layer security encryption for our applications.
S&T employees are required to undergo annual information security awareness training, which includes information regarding evolving threats such as phishing, malware and social engineering testing.
18 unchanged sentences
The potential impact of the incident, individually or in aggregate, is evaluated by the Chief Security Officer, or CSO, continuously across these criteria.
−Removed: We have escalation procedures to notify members of senior and executive management, the Board (or an applicable subset) and regulators in a timely manner based on the criticality of the cybersecurity incident.
+Added: S&T BANCORP, INC.
+Added: AND SUBSIDIARIES
+Added: have escalation procedures to notify members of senior and executive management, the Board (or an applicable subset) and regulators in a timely manner based on the criticality of the cybersecurity incident.
S&T also has in place incident response and business continuity plans.
10 unchanged sentences
The Risk Committee oversees risk from cybersecurity threats as a part of its oversight of the ERM Program.
−Removed: The Risk Committee regularly reviews reports from, and has discussions with, S&T’s Chief Risk Officer, or CRO, Chief Operating Officer, or COO, CSO, Chief Information and Technology Officer and Director of Operational Risk Management regarding cybersecurity risks, the threat landscape, updates on incidents and reports on our investments in cybersecurity risk mitigation and governance.
+Added: The Risk Committee regularly reviews reports from, and has discussions with, S&T’s Chief Risk Officer, or CRO, Chief Operating Officer, or COO, CSO, and Director of Operational Risk Management regarding cybersecurity risks, the threat landscape, updates on incidents and reports on our investments in cybersecurity risk mitigation and governance.
The Risk Committee chairperson reports activities and recommendations with respect to such matters to the Board as are relevant and deemed appropriate by the Risk Committee.
1 unchanged sentence
A special meeting of the Board will be held, as deemed necessary by the Chairperson of the Board in consultation with the Chair of the Risk Committee.
−Removed: S&T BANCORP, INC.
−Removed: AND SUBSIDIARIES
Management’s Role
−Removed: At the management level, the ERM Committee, CRO, COO, CSO, Chief Information and Technology Officer, Director of Information Technology and Director of Operational Risk Management are responsible for assessing and managing material risks from cybersecurity threats.
+Added: At the management level, the ERM Committee, CRO, COO, CSO, Director of Information Technology and Director of Operational Risk Management are responsible for assessing and managing material risks from cybersecurity threats.
The ERM Committee reports information to the Risk Committee on a quarterly basis, or more often as needed.
−Removed: Risk Management leadership, which assists the ERM Committee in assessing and managing cybersecurity threats, include our CRO, COO, CSO, Chief Information and Technology Officer, Director of Information Technology and Director of Operational Risk Management.
+Added: Risk Management leadership, which assists the ERM Committee in assessing and managing cybersecurity threats, include our CRO, COO, CSO, Director of Information Technology and Director of Operational Risk Management.
Our CRO who oversees the risk management information security program reports to our CEO, but has direct access to the Risk Committee.
2 unchanged sentences
Our CSO reports to the CRO and has 18 years of information technology and cybersecurity experience, including prior roles as chief information officer, assistant director of information technology, chief information security officer and chief security officer in federal law enforcement and banking organizations.
−Removed: Our Chief Information and Technology Officer has nine years of information technology and cybersecurity experience.
Our Director of Information Technology has 25 years of information technology and cybersecurity experience.
5 unchanged sentences
We operate in Pennsylvania and Ohio.
−Removed: At December 31, 2023, we operate 73 banking branches and four loan production offices, of which 43 are leased facilities.
+Added: At December 31, 2024, we operate 71 banking branches and three loan production offices, of which 41 are leased facilities.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.