6 unchanged sentences
Cybersecurity is a critical component of our risk management program;
−Removed: thus we have implemented a Cyber and Information Security Program to protect the confidentiality, integrity and availability of our information and information technology environment.
+Added: thus, we have implemented a Cyber and Information Security Program to protect the confidentiality, integrity and availability of our information and information technology
Our program aligns with applicable federal and state regulations, industry frameworks such as the Federal Financial Institutions Examination Council ("FFIEC") and best practices from the National Institute of Standards and Technology ("NIST").
8 unchanged sentences
Quarterly employee training is performed on cybersecurity, information security, identify theft prevention and data privacy.
−Removed: The Bank has not experienced any material losses relating to cybersecurity threats or incidents to date.
+Added: The Bank has not experienced any material losses relating to cybersecurity threats or incidents as of September 30, 2025.
+Added: Material cybersecurity incidents are escalated to the Board and evaluated for disclosure in accordance with SEC reporting requirements.
Incident Response
2 unchanged sentences
The Incident Response Policy prescribes points of escalation and mechanisms for collaboration should the need arise to engage outside partnerships such as external counsel, cybersecurity forensic examiners, cyber insurance vendors, government agencies and regulatory bodies.
+Added: The Incident Response Policy also specifies that material incidents are promptly reported to the Board and considered for disclosure under applicable SEC rules.
Third Party Service Provider Monitoring
The Bank maintains a robust Vendor Management Program to appropriately measure, monitor and control risks associated with outsourcing products and services, including cybersecurity risks.
−Removed: Under the program, vendors are assigned a risk rating based
−Removed: on an assessment of the vendor and its access to network, systems and confidential information.
−Removed: The Bank’s Information Security Officer conducts regular periodic reviews of the adequacy of its oversight of controls over third party relationships.
+Added: Under the program, vendors are assigned a risk rating based on an assessment of the vendor and its access to network, systems and confidential information.
+Added: Critical and high-risk vendors are reassessed at least annually, and remediation plans are implemented for identified deficiencies.
+Added: The Bank’s Information Security Officer ("ISO")conducts regular periodic reviews of the adequacy of its oversight of controls over third party relationships.
Cybersecurity Governance
2 unchanged sentences
one of which has completed and received Cybersecurity Oversight Certification from the National Association of Corporate Directors (“NACD”).
−Removed: The Bank’s primary responsibility for managing cyber risk is vested in the Bank’s Information Security Analyst ("ISA") .
−Removed: The ISA reports to the Chief Risk Officer and serves as the primary custodian of the Bank’s Cyber Security and Information Security Program.
+Added: The Board receives cybersecurity updates at least quarterly, including risk metrics, incident reports, and progress on mitigation strategies.
+Added: The Bank’s primary responsibility for managing cyber risk is vested in the Bank’s Information Security Officer ("ISO") .
+Added: The Bank’s ISO, who reports to the Chief Risk Officer, has four years of experience in information security and risk management.
+Added: The ISO is responsible for the day-to-day management of the Cyber and Information Security Program, including oversight of risk assessments, incident response, employee training, and third-party vendor cybersecurity controls.
+Added: The Chief Technology Officer ("CTO") has over 13 years of experience in IT and cybersecurity leadership, including managing enterprise IT operations and technology risk.
+Added: The CTO also holds a Certified Community Bank Information Technology Officer designation from the ICBA, and a CompTIA Security+ certification and has completed the Graduate School of Banking at the University of Wisconsin's Bank Technology Management program.
+Added: Members of the Technology Steering Committee bring substantial experience in IT operations, cybersecurity, and risk management, providing guidance on technology strategy, operational performance, and cybersecurity oversight.
The Technology Steering Committee meets on a regular basis and is tasked with providing oversight and guidance regarding both information technology and cybersecurity related issues of strategic importance to the Bank.
−Removed: The Technology Steering Committee is comprised of numerous members of the management team, Chief Technology Officer ("CTO") and ISA.
+Added: The Technology Steering
+Added: Committee is comprised of numerous members of the management team, the CTO and the ISO.
The Technology Steering committee reports to the Board of Directors through Committee minutes.
The Board Technology Committee assists the Board of Directors in fulfilling its oversight responsibilities with respect to the overall role of technology in executing the business strategy of the institution, including but not limited to major technology investments, technology strategy, operational performance and technology trends that may affect customers.
−Removed: The Board Technology Committee meets regularly and receives reports from the CTO and ISA on cybersecurity and information technology risks.
+Added: The Board Technology Committee meets regularly and receives reports from the CTO and the ISO on cybersecurity and information technology risks.
The Board Technology Committee reports to the Board of Directors through Committee minutes.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.