|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
We rely extensively on various information systems and other electronic resources to operate our business. In addition, nearly all of our customers, service providers and other business partners on whom we depend, including the providers of our online banking, mobile banking and accounting systems, use their own electronic information systems. Any of these systems can be compromised, including by employees, customers and other individuals who are authorized to use them, and bad actors using sophisticated and a constantly evolving set of software, tools and strategies to do so. The nature of our business, as a financial-services provider, and our relative size, make us and our business partners high-value targets for these bad actors to pursue. See “Risks Related to Information Security and Business Interruption” section of the Risk Factors included in Item 1A of this 2024 Form 10-K for additional information.
Accordingly, we have devoted significant resources to assessing, identifying and managing risks associated with cybersecurity threats, including:
The Information Security Program is a key part of our overall risk management system, which is administered by our Information Technology Steering Committee. The program includes administrative, technical and physical safeguards to help protect the security and confidentiality of customer records and information.
From time-to-time, we have identified cybersecurity threats that require us to make changes to our processes and to implement additional safeguards. While we have not experienced cybersecurity incidents that have materially affected our business, operations, or financial condition to date, we recognize that evolving cyber threats present a continuing risk. A successful cybersecurity breach, particularly one affecting our critical systems or third-party service providers, could result in operational disruptions, financial losses, reputational damage, legal or regulatory consequences, and loss of customer confidence. For example, unauthorized access to our systems could lead to data theft, fraud, or extended downtime impacting our ability to provide financial services. If such an event were to occur, it could have a material adverse effect on our results of operations and financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We rely extensively on various information systems and other electronic resources to operate our business. In addition, nearly all of our customers, service providers and other business partners on whom we depend, including the providers of our online banking, mobile banking and accounting systems, use their own electronic information systems. Any of these systems can be compromised, including by employees, customers and other individuals who are authorized to use them, and bad actors using sophisticated and a constantly evolving set of software, tools and strategies to do so. The nature of our business, as a financial-services provider, and our relative size, make us and our business partners high-value targets for these bad actors to pursue. See “Risks Related to Information Security and Business Interruption” section of the Risk Factors included in Item 1A of this 2024 Form 10-K for additional information.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|From time-to-time, we have identified cybersecurity threats that require us to make changes to our processes and to implement additional safeguards. While we have not experienced cybersecurity incidents that have materially affected our business, operations, or financial condition to date, we recognize that evolving cyber threats present a continuing risk. A successful cybersecurity breach, particularly one affecting our critical systems or third-party service providers, could result in operational disruptions, financial losses, reputational damage, legal or regulatory consequences, and loss of customer confidence. For example, unauthorized access to our systems could lead to data theft, fraud, or extended downtime impacting our ability to provide financial services. If such an event were to occur, it could have a material adverse effect on our results of operations and financial condition.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The Company’s management team is responsible for the day-to-day management of cybersecurity risks we face and oversees the Information Technology Steering Committee. The Information Technology Steering Committee manages the oversight of the information security assessment, development of policies, standards and procedures, testing, training and security report processes for the Company. The Information Technology Steering Committee is comprised of officers with the appropriate expertise and authority to oversee the Information Security Program.
In addition, the Company’s Board is responsible for the oversight of risk management, including cybersecurity risks. In that role, the Company’s Board, with support from the Company’s management and third party cybersecurity advisors, are responsible for ensuring that the risk management processes designed and implemented by management are adequate and functioning as designed. The Board reviews and approves an information security program, vendor management policy (including third-party service providers), acceptable use policy, incident response policy and business continuity planning policy on an annual basis. All the aforementioned policies are developed and implemented by management of the Company. To carry out their duties, the Board receives updates from the Information Technology Steering Committee regarding cybersecurity risks and the Company’s efforts to prevent, detect, mitigate and remediate any cybersecurity.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Company’s management team is responsible for the day-to-day management of cybersecurity risks we face and oversees the Information Technology Steering Committee. The Information Technology Steering Committee manages the oversight of the information security assessment, development of policies, standards and procedures, testing, training and security report processes for the Company. The Information Technology Steering Committee is comprised of officers with the appropriate expertise and authority to oversee the Information Security Program.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|In addition, the Company’s Board is responsible for the oversight of risk management, including cybersecurity risks. In that role, the Company’s Board, with support from the Company’s management and third party cybersecurity advisors, are responsible for ensuring that the risk management processes designed and implemented by management are adequate and functioning as designed. The Board reviews and approves an information security program, vendor management policy (including third-party service providers), acceptable use policy, incident response policy and business continuity planning policy on an annual basis. All the aforementioned policies are developed and implemented by management of the Company. To carry out their duties, the Board receives updates from the Information Technology Steering Committee regarding cybersecurity risks and the Company’s efforts to prevent, detect, mitigate and remediate any cybersecurity.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef