XML 42 R30.htm IDEA: XBRL DOCUMENT v3.25.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We believe that our cybersecurity program provides effective protection of client information and of our operating systems from known and reasonably expected risks, while also promoting the timely detection of, and defense against, cyberattacks and other unauthorized access to our information technology (“IT”) systems. In order to accomplish these goals, we maintain up-to-date information security and monitoring controls, which we believe mitigates cybersecurity risks and threats while optimizing the utility of our systems. At the same time, cyberattacks are increasingly common, sophisticated and destructive, and several large, highly sophisticated financial institutions have been successfully targeted in recent years, leading to significant losses of client data, denials and loss of online banking and other data services, and other critical functions that have become essential to modern banking. These events also have carried significant reputational risk for the successfully targeted institutions. In order to mitigate these risks, our Information Security Officer ("ISO") is responsible for our cybersecurity programs and for the detection of and response to any identified threats and incidents. That individual also reports regularly to our Board of Directors, oversees certain policies and procedures that are intended to guard against, detect, and respond to potential breaches of our IT systems.

Managing Material Risks & Integrated Overall Risk Management

We have strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture of cybersecurity risk management. Our procedures and security program are the guiding policies over our cybersecurity risk management. Additionally, our IT team uses the best currently available tools to help protect against cybercriminals. We leverage the latest encryption practices and cyber technologies on our systems, devices, and third-party connections and further review vendor encryption to ensure proper information security safeguards are maintained. Our employees are responsible for complying with our cybersecurity standards and complete training to understand the behaviors and technical requirements necessary to keep information secure.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We have strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture of cybersecurity risk management. Our procedures and security program are the guiding policies over our cybersecurity risk management. Additionally, our IT team uses the best currently available tools to help protect against cybercriminals. We leverage the latest encryption practices and cyber technologies on our systems, devices, and third-party connections and further review vendor encryption to ensure proper information security safeguards are maintained. Our employees are responsible for complying with our cybersecurity standards and complete training to understand the behaviors and technical requirements necessary to keep information secure.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board recognizes the importance of managing risks associated with cybersecurity threats. The Board has established robust oversight procedures to promote effective governance in managing cybersecurity risks because of the significance of these threats to our operational integrity and shareholder confidence.

Board of Directors Oversight

The Board Risk and Compliance Committee ("BRCC") is central to the Board’s oversight of cybersecurity risks. The BRCC currently oversees various risk areas such as regulatory compliance, CRA, BSA/AMLA, enterprise risk management, cybersecurity, technology, and third-party risk management. The committee ensures that the Board maintains appropriate expertise to assure the appropriate management of cybersecurity risk. The BRCC reports periodically to the Board on the effectiveness of cybersecurity risk management processes and cybersecurity risk trends. The Board also receives specific reports from senior management with oversight responsibility for cybersecurity risks within the Company. These reports include risk assessments of cybersecurity and related risks, as well as the company’s vulnerability to those risks. The BRCC reviews an annual evaluation of the company’s cybersecurity posture and the effectiveness of its risk management strategies, identifying areas for improvement and ensuring the cybersecurity efforts are integrated with the overall risk management framework.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] he Company’s Management Risk and Compliance Committee also reports directly to the BRCC regarding our risk management initiatives. The BRCC also receives quarterly reports from the Executive IT Committee and IT department in order to say informed on all aspects of cybersecurity risk affecting the Company.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The ISO reports to the BRCC on the status and impact of any information security related developments and strategic initiatives, and depending on the severity of the situation, directly to the Board of Directors. In addition to regular meetings, the BRCC, the ISO, Chief Risk Officer, Chief Information Officer, and Chief Executive Officer maintain an ongoing dialogue regarding emerging or potential cybersecurity risks that we face, particularly as a financial institution.
Cybersecurity Risk Role of Management [Text Block]
The ISO plays a pivotal role in informing the BRCC on cybersecurity risks. Jointly with the Chief Risk Officer, the ISO reports quarterly to the BRCC on a range of topics, including:

Current cybersecurity landscape and risks;
Status of ongoing cybersecurity incidents, threats and strategies;
Internal and external test result and remediation efforts;
Enforcement of ongoing awareness training on information security;
Cybersecurity incident reporting and post-incident reviews; and
Compliance with regulatory requirements and evolving industry trends.

The ISO reports to the BRCC on the status and impact of any information security related developments and strategic initiatives, and depending on the severity of the situation, directly to the Board of Directors. In addition to regular meetings, the BRCC, the ISO, Chief Risk Officer, Chief Information Officer, and Chief Executive Officer maintain an ongoing dialogue regarding emerging or potential cybersecurity risks that we face, particularly as a financial institution. The Company’s Management Risk and Compliance Committee also reports directly to the BRCC regarding our risk management initiatives. The BRCC also receives quarterly reports from the Executive IT Committee and IT department in order to say informed on all aspects of cybersecurity risk affecting the Company.

Risk Management Personnel
Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with the ISO, who has extensive cybersecurity program management experience working in various information security roles, including teaching as an information security instructor at a University. The ISO holds various information security qualifications, such as a doctoral degree in information technology and cyber security and holds the Certified Information Systems Security Professional ("CISSP") certification. The ISO and Chief Risk Officer are responsible for managing the disclosure and communications related to cybersecurity incidents. Our Chief Risk Officer chairs the Management Compliance and Risk Committee independently and has more than 20 years of experience in compliance and risk management.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with the ISO, who has extensive cybersecurity program management experience working in various information security roles, including teaching as an information security instructor at a University. The ISO holds various information security qualifications, such as a doctoral degree in information technology and cyber security and holds the Certified Information Systems Security Professional ("CISSP") certification. The ISO and Chief Risk Officer are responsible for managing the disclosure and communications related to cybersecurity incidents. Our Chief Risk Officer chairs the Management Compliance and Risk Committee independently and has more than 20 years of experience in compliance and risk management.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Risk Officer chairs the Management Compliance and Risk Committee independently and has more than 20 years of experience in compliance and risk management.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The ISO, in his capacity as such, regularly reports to management and the BRCC on all aspects related to cybersecurity risks and incidents. This ensures that the highest levels of management are kept informed of our cybersecurity and the potential risks we face. In the event of certain cybersecurity matters which present increasing concern, our policies require escalating these cybersecurity and risk management decisions to the full Board.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true