25 unchanged sentences
Our third-party risk management program is integrated into our Information Security Program within our ERM Program.
−Removed: The policies, procedures and practices applicable to the cybersecurity components of the third-party risk management program were developed and are maintained consistent with the FFEIC IT Examination Handbook, as well as guidance from our prudential regulators.
+Added: The policies, procedures and practices applicable to the cybersecurity components of the third-party risk management program were developed and are maintained consistent with the FFIEC IT Examination Handbook, as well as guidance from our prudential regulators.
We perform a risk assessment, including cyber threats, associated with use of third-party vendors and exercise appropriate due diligence before entering into a vendor arrangement.
3 unchanged sentences
All third parties with access to our information systems must review and acknowledge our Acceptable Use Policy before access is granted.
−Removed: When a cybersecurity incident occurs, whether detected internally or from third-party cybersecurity incidents, we evaluate the incident for criticality across a range of contributing indicators, including service availability, impact to operations, reputational impact, regulatory and legal considerations, data sensitivity and direct financial impact.
+Added: When a cybersecurity incident occurs, whether detected internally or from third-party cybersecurity incidents, we evaluate the incident for criticality across a range of contributing indicators, including service availability, impact to operations, and brand, regulatory and legal considerations, data sensitivity and direct financial impact.
The potential impact of the incident, individually or in aggregate, is evaluated by the Chief Security Officer, or CSO, continuously across these criteria.
1 unchanged sentence
AND SUBSIDIARIES
−Removed: have escalation procedures to notify members of senior and executive management, the Board (or an applicable subset) and regulators in a timely manner based on the criticality of the cybersecurity incident.
+Added: escalation procedures to notify members of senior and executive management, the Board (or an applicable subset) and regulators in a timely manner based on the criticality of the cybersecurity incident.
S&T also has in place incident response and business continuity plans.
10 unchanged sentences
The Risk Committee oversees risk from cybersecurity threats as a part of its oversight of the ERM Program.
−Removed: The Risk Committee regularly reviews reports from, and has discussions with, S&T’s Chief Risk Officer, or CRO, Chief Operating Officer, or COO, CSO, and Director of Operational Risk Management regarding cybersecurity risks, the threat landscape, updates on incidents and reports on our investments in cybersecurity risk mitigation and governance.
+Added: The Risk Committee regularly reviews reports from, and has discussions with, S&T’s Chief Risk Officer, or CRO, Chief Operating Officer, or COO, Chief Information Officer, or CIO, CSO, and Director of Operational Risk Management regarding cybersecurity risks, the threat landscape, updates on incidents and reports on our investments in cybersecurity risk mitigation and governance.
The Risk Committee chairperson reports activities and recommendations with respect to such matters to the Board as are relevant and deemed appropriate by the Risk Committee.
2 unchanged sentences
Management’s Role
−Removed: At the management level, the ERM Committee, CRO, COO, CSO, Director of Information Technology and Director of Operational Risk Management are responsible for assessing and managing material risks from cybersecurity threats.
+Added: At the management level, the ERM Committee, CRO, COO, CIO, CSO and Director of Operational Risk Management are responsible for assessing and managing material risks from cybersecurity threats.
The ERM Committee reports information to the Risk Committee on a quarterly basis, or more often as needed.
−Removed: Risk Management leadership, which assists the ERM Committee in assessing and managing cybersecurity threats, include our CRO, COO, CSO, Director of Information Technology and Director of Operational Risk Management.
+Added: Risk Management leadership, which assists the ERM Committee in assessing and managing cybersecurity threats, include our CRO, COO, CIO, CSO and Director of Operational Risk Management.
Our CRO who oversees the risk management information security program reports to our CEO, but has direct access to the Risk Committee.
2 unchanged sentences
Our CSO reports to the CRO and has 18 years of information technology and cybersecurity experience, including prior roles as chief information officer, assistant director of information technology, chief information security officer and chief security officer in federal law enforcement and banking organizations.
−Removed: Our Director of Information Technology has 25 years of information technology and cybersecurity experience.
−Removed: Our Director of Operational Risk Management has 11 years of information technology and cybersecurity experience, including serving as a former chief information officer for a financial institution.
+Added: Our CIO has over 25 years of financial services, information technology, cybersecurity and emerging technologies experience.
+Added: Our Director of Operational Risk Management has over 25 years of information technology and cybersecurity experience, including serving as a former chief information officer for a financial institution.
For more information regarding the risks associated with cybersecurity that may impact our business strategy, results of operations or financial condition, see “ Part I, “Item 1A.
4 unchanged sentences
At December 31, 2025, we operate 72 banking branches and three loan production offices, of which 41 are leased facilities.
+Added: S&T BANCORP, INC.
+Added: AND SUBSIDIARIES
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.