|
Cybersecurity Risk Management and Strategy
|12 Months Ended
Dec. 31, 2024
|Cybersecurity risk management Strategy and Governance [Abstract]
|Cybersecurity Risk Management Processes For Assessing Identifying And Managing Threats [Text Block]
|
The
framework, alongside
legal and reputational risks, among others.
The Corporation has established three management
●
monitors
including cybersecurity risks.
●
Information and
risks, mitigating
that may result in operational, compliance and reputational
●
management activities
procedures that
efficiency
matters, as well as operational losses stemming
The ITCRC and ORCO meet at least quarterly
The Board
Corporation’s overall risk framework, and assists the Board in the monitoring, review and approval of the policies that measure, limit
and manage the Corporation’s risks, including cybersecurity
an
incidents
Information Security Officer
Division”)
implementation
approving the Corporation’s risk management program
the Corporation’s
and (iv) reviewing reports regarding selected topics
The Board in turn also receives briefings on cybersecurity matters and risks, including an annual presentation from the Chief
Security Officer and the CISO on the Information Security Program.
In
members of the
principles and regulations that are relevant to our institution
To identify, assess and manage risks from cybersecurity threats, the Corporation has established a three lines of defense
framework. The first line of defense is composed of business line management that identifies and manages the risks associated with
business activities, including cybersecurity risk. The second line of defense is made up of members of the Corporation’s Corporate
Risk Management Group and the Corporate Security Group (the “CSG”) who, among other things, measure and report on the
Corporation’s risk activities. In such line of defense, the FORM Division, within the Corporate Risk Management Group, is
responsible for (i) establishing baseline metrics that measure, monitor, limit and manage the framework that identifies and manages
multiple and cross-enterprise risks, including cybersecurity risks; and (ii) articulating the RAS and supporting metrics, including
those related to operational risk, business continuity, disaster recovery and third-party management oversight processes.
Meanwhile, Popular’s Cyber Security Division (the “CSD”), which is headed by the CISO and reports to the CSG, is responsible for
the development of strategies, policies and programs to assess and mitigate cybersecurity risks. Members of the CSD (including the
CISO) and FORM Division report on and escalate cybersecurity, IT and privacy risks to management committees, such as the
ITCRC, ORCO and ERM Committee, and, if appropriate, to the RMC and the Board of Directors, as required under relevant policies
and procedures. Lastly, the third line of defense consists of the Corporate Auditing Division, which independently provides
assurance regarding the effectiveness of the risk framework and reports directly to the Audit Committee of the Board.
Popular monitors various vectors of threats and utilizes open-source intelligence forums and communities such as the Financial
Services Information Sharing and Analysis Center and the Cybersecurity and Infrastructure Security Agency, among others, to
receive threat intelligence feeds which are reviewed by the CSD. As cybersecurity threats are identified, they are evaluated to
assess the level of exposure and the potential risk to Popular. The ITCRC and the ERM Committee discuss and track the threats
identified in internal assessments and scans or in third-party reports. Depending on the evolution and materiality of the threat, these
are escalated to the RMC as appropriate.
The CSD
and
strategy and
personnel, and is based on standards and controls set by the National Institute of Standards and Technology
NIST’s Framework for
“CAT”), a tool based on NIST standards and controls developed by the Federal Financial Institutions
in order to measure the
into
assessment framework, following the announcement by the FFIEC of the sunset
through public-private collaboration and is a list of assessment questions curated based
cyber standards, such as the International Standards
The CSD
managing cyber
cybersecurity
incidents, as well as to comply with potentially
The Corporation also undertakes the below listed
and manage its material risks from cybersecurity
●
measures;
●
threats impact
technology or processes;
●
●
and use requirements;
●
●
awareness and responsiveness to such possible
●
●
●
necessary.
Popular engages third parties to assist in certain cybersecurity matters.
In particular, Popular uses the expertise of third parties to
perform specialized assessments to test its systems, such as periodic penetration testing, that provide insights into the effectiveness
of its controls. Popular also engages third parties to provide computer forensics and investigations services as needed to assess
and address actual or potential cybersecurity incidents. In addition, Popular hires third parties to provide the first level security
monitoring of Popular’s external and internal networks.
Popular’s Outsourced
party service
performs due diligence on
systems or data on a
on such third party.
Furthermore, Popular requires third parties that have
a training on cybersecurity at least annually.
Under the heading “We and our third-party providers have been, and expect in the future to continue to be, subject to cyber-attacks,
which could cause
companies to
and information
adverse
incorporated by
we describe whether and how risks from identified cybersecurity threats, including as a result of
any previous cybersecurity incidents, could have materially affected or are reasonably likely to materially affect us, including our
business strategy, results of operations, or financial condition.
The CSG
including over 12 years of
Information
Certified Public Accountant that also holds a Juris Doctor degree and FINRA administered
holds the title
as Senior
various risk
dealer business.
The
cybersecurity governance
boards of directors on cyber risks and cybersecurity standards.
He holds the title of CISO and Cybersecurity Division
The Corporate Risk
years of work experience.
Prior to
Head of Commercial and Construction Mortgage and
a BS with a major in Computer Engineering
The FORM Division Manager has over 29 years of work experience.
Manager
Director,
Internal
Information Systems, and a Master of Science in Information
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
To identify, assess and manage risks from cybersecurity threats, the Corporation has established a three lines of defense
framework. The first line of defense is composed of business line management that identifies and manages the risks associated with
business activities, including cybersecurity risk. The second line of defense is made up of members of the Corporation’s Corporate
Risk Management Group and the Corporate Security Group (the “CSG”) who, among other things, measure and report on the
Corporation’s risk activities. In such line of defense, the FORM Division, within the Corporate Risk Management Group, is
responsible for (i) establishing baseline metrics that measure, monitor, limit and manage the framework that identifies and manages
multiple and cross-enterprise risks, including cybersecurity risks; and (ii) articulating the RAS and supporting metrics, including
those related to operational risk, business continuity, disaster recovery and third-party management oversight processes.
Meanwhile, Popular’s Cyber Security Division (the “CSD”), which is headed by the CISO and reports to the CSG, is responsible for
the development of strategies, policies and programs to assess and mitigate cybersecurity risks. Members of the CSD (including the
CISO) and FORM Division report on and escalate cybersecurity, IT and privacy risks to management committees, such as the
ITCRC, ORCO and ERM Committee, and, if appropriate, to the RMC and the Board of Directors, as required under relevant policies
and procedures. Lastly, the third line of defense consists of the Corporate Auditing Division, which independently provides
assurance regarding the effectiveness of the risk framework and reports directly to the Audit Committee of the Board.
The Corporation also undertakes the below listed
and manage its material risks from cybersecurity
●
measures;
●
threats impact
technology or processes;
●
●
and use requirements;
●
●
awareness and responsiveness to such possible
●
●
●
necessary.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight And Identification Processes [Flag]
|true
|Cybersecurity Risk Process For Informing Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|
The Board
Corporation’s overall risk framework, and assists the Board in the monitoring, review and approval of the policies that measure, limit
and manage the Corporation’s risks, including cybersecurity
an
incidents
Information Security Officer
Division”)
implementation
approving the Corporation’s risk management program
the Corporation’s
and (iv) reviewing reports regarding selected topics
The Board in turn also receives briefings on cybersecurity matters and risks, including an annual presentation from the Chief
Security Officer and the CISO on the Information Security Program.
|Cybersecurity Risk Materially Affected Or Reasonably Likely To Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board Of Directors Oversight [Text Block]
|
In
members of the
principles and regulations that are relevant to our institution
|Cybersecurity Risk Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|
The Corporation has established three management
●
monitors
including cybersecurity risks.
●
Information and
risks, mitigating
that may result in operational, compliance and reputational
●
management activities
procedures that
efficiency
matters, as well as operational losses stemming
|Cybersecurity Risk Role Of Management [Text Block]
|
The Board
Corporation’s overall risk framework, and assists the Board in the monitoring, review and approval of the policies that measure, limit
and manage the Corporation’s risks, including cybersecurity
an
incidents
Information Security Officer
Division”)
implementation
approving the Corporation’s risk management program
the Corporation’s
and (iv) reviewing reports regarding selected topics
|Cybersecurity Risk Management Positions Or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions Or Committees Responsible [Text Block]
|
Popular monitors various vectors of threats and utilizes open-source intelligence forums and communities such as the Financial
Services Information Sharing and Analysis Center and the Cybersecurity and Infrastructure Security Agency, among others, to
receive threat intelligence feeds which are reviewed by the CSD. As cybersecurity threats are identified, they are evaluated to
assess the level of exposure and the potential risk to Popular. The ITCRC and the ERM Committee discuss and track the threats
identified in internal assessments and scans or in third-party reports. Depending on the evolution and materiality of the threat, these
are escalated to the RMC as appropriate.
|Cybersecurity Risk Process For Informing Management Or Committees Responsible [Text Block]
|
The ITCRC and ORCO meet at least quarterly
|Cybersecurity Risk Management Expertise Of Management Responsible [Text Block]
|
The CSG
including over 12 years of
Information
The
cybersecurity governance
boards of directors on cyber risks and cybersecurity standards.
The Corporate Risk
years of work experience.
The FORM Division Manager has over 29 years of work experience.
|Cybersecurity Risk Management Positions Or Committees Responsible Report To Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef