|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Management and Strategy. Senior management takes the guidance provided by the Board of Directors and transforms this guidance into operational priorities which are implemented and maintained by the staff members and third-party service providers. In addition, the senior management team ensures that budgeted resources are allocated in a timely manner to support the various security initiatives.
The Director of Compliance and Internal Audit and third-party service providers utilize the direction and resources provided by the senior management team to develop procedures, standards and guidelines to achieve the strategic goals defined by the Board of Directors. Operational and security health is reported monthly to the Board of Directors. Recommendations for improvements are shared between operational staff and the senior management team as part of a continuous improvement program for information security and cybersecurity.
Operational staff members actively maintain, review, update and exercise plans and procedures designed to enhance our overall business resiliency. All staff members are trained annually on current information and cybersecurity trends, techniques and their responsibilities to keep our information confidential, accurate and available.
We also utilize the services of-party providers to conduct an IT audit, external and internal vulnerability testing, external and internal penetration testing, and social engineering testing on at least an annual basis. The results of these independent audits and tests are sent to the Board of Directors for review. Finally, Mutual Savings and Loan Association complies with its regulatory requirements by having federal safety and security examinations performed on a schedule dictated by the regulatory agencies. The of these examinations are reviewed and approved by the Board of Directors. Additionally, all findings from these examinations are recorded and prioritized for remediation.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Senior management takes the guidance provided by the Board of Directors and transforms this guidance into operational priorities which are implemented and maintained by the staff members and third-party service providers. In addition, the senior management team ensures that budgeted resources are allocated in a timely manner to support the various security initiatives
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance. Our efforts for increased information and cybersecurity readiness are driven from the top of the organization. The Board of Directors reviews and approves an Information Technology and Information Security Risk Appetite Statement which guides the actions of the management team, staff members and supporting third-party service providers. In addition, the Board is active in the review and approval of all policies concerning information technology and information security. The Board further reviews reports provided by the management team regarding the status of Mutual Savings and Loan Association’s compliance with the Gramm-Leach-Bliley Act, risk management program, vendor management program, and the results of tests and exercises conducted for business continuity, disaster recovery, cybersecurity incident response and pandemic response. Lastly, the Board of Directors reviews and approves the budget for information and cybersecurity, ensuring that we have sufficient resources to properly address all current and foreseeable information and cybersecurity threats.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board of Directors reviews and approves an Information Technology and Information Security Risk Appetite Statement which guides the actions of the management team, staff members and supporting third-party service providers. In addition, the Board is active in the review and approval of all policies concerning information technology and information security.
|Cybersecurity Risk Role of Management [Text Block]
|The Director of Compliance and Internal Audit and third-party service providers utilize the direction and resources provided by the senior management team to develop procedures, standards and guidelines to achieve the strategic goals defined by the Board of Directors. Operational and security health is reported monthly to the Board of Directors. Recommendations for improvements are shared between operational staff and the senior management team as part of a continuous improvement program for information security and cybersecurity.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Operational staff members actively maintain, review, update and exercise plans and procedures designed to enhance our overall business resiliency. All staff members are trained annually on current information and cybersecurity trends, techniques and their responsibilities to keep our information confidential, accurate and available.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef