|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
The Company has developed an information security program to assess, identify, and monitor cybersecurity risks. The Company regularly assesses cybersecurity risks arising from the operating environment and attempts to identify the likelihood and severity of the risk and the possible impact of the risk on the Company, its customers, and employees.
The Company conducts periodic testing of software, hardware, defensive capabilities, and other information security systems utilizing both internal processes and third-party consultants. Testing procedures are supplemented by regular cyber threat exercises and employee training. Threat simulation exercises are used to develop and refine the Company’s incident response plans and employees undergo cybersecurity awareness training on a regular basis.
The Company also addresses cyber risks posed by its relationships with third-party vendors. The Company assesses vendor risk as a part of its vendor management process, which requires a pre-acquisition diligence review, including the review of the vendor’s information security policy for all vendors determined to be a “critical vendor”. The vendor management process also requires a review of all critical vendors annually and all critical vendors are reported to the Board of Directors.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
The Company has developed an information security program to assess, identify, and monitor cybersecurity risks. The Company regularly assesses cybersecurity risks arising from the operating environment and attempts to identify the likelihood and severity of the risk and the possible impact of the risk on the Company, its customers, and employees.
The Company conducts periodic testing of software, hardware, defensive capabilities, and other information security systems utilizing both internal processes and third-party consultants. Testing procedures are supplemented by regular cyber threat exercises and employee training. Threat simulation exercises are used to develop and refine the Company’s incident response plans and employees undergo cybersecurity awareness training on a regular basis.
The Company also addresses cyber risks posed by its relationships with third-party vendors. The Company assesses vendor risk as a part of its vendor management process, which requires a pre-acquisition diligence review, including the review of the vendor’s information security policy for all vendors determined to be a “critical vendor”. The vendor management process also requires a review of all critical vendors annually and all critical vendors are reported to the Board of Directors.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Board IT Steering Committee is responsible for oversight of the Company’s cybersecurity and information security program and regularly reviews and evaluates information security and cybersecurity risks provided by management. The IT Steering Committee meets quarterly to evaluate and review the information presented by management. The Board Members on the IT Steering Committee or Chief Information Officer present a summary of the IT Steering Committee meetings to the Board on a quarterly basis.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board IT Steering Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board IT Steering Committee is responsible for oversight of the Company’s cybersecurity and information security program and regularly reviews and evaluates information security and cybersecurity risks provided by management. The IT Steering Committee meets quarterly to evaluate and review the information presented by management.
|Cybersecurity Risk Role of Management [Text Block]
|The Corporation’s information security program is led by the Chief Information Officer in conjunction with Management and Board of Director IT Steering Committee. The Chief Information Officer has over 25 years of technology and cyber experience at community and regional banks. The Chief Information Officer currently serves as a member of the ISACA Harrisburg chapter for IT professionals and on the IT Steering Committee for the PA Bankers Association.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Chief Information Officer
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Chief Information Officer has over 25 years of technology and cyber experience at community and regional banks.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef