|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Abstract]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Ohio Valley recognizes the critical importance of assessing, identifying, and managing material risks from cybersecurity threats and safeguarding the security of its banking operations and data, including protecting its customers’ information. As a result, the Company has devoted significant financial and personnel resources to assessing, identifying, and managing cybersecurity risks and threats, including:
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The Board, through the Information Technology Steering Committee, works with senior management and other employee committees to oversee the development, implementation, maintenance, and administration of the Information Security Program, which is aligned and integrated into Ohio Valley’s overall risk management system and processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|Ohio Valley’s systems and those of its customers and third-party service providers are under constant threat, and it is possible that Ohio Valley could experience a significant event in the future. Risks and exposures related to cybersecurity attacks are expected to remain high for the foreseeable future due to the rapidly evolving nature and sophistication of these threats, as well as due to the expanding use of Internet banking, mobile banking, and other technology-based products and services by us and our customers.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The Board, through the Information Technology Steering Committee, works with senior management and other employee committees to oversee the development, implementation, maintenance, and administration of the Information Security Program, which is aligned and integrated into Ohio Valley’s overall risk management system and processes. The Information Technology Steering Committee itself is comprised of diverse directors and officers of the Bank with vast knowledge and years of banking experience. The Information Security Officer of the committee has 26 years of banking experience including 25 IT related years as well as continuing education including a BA in Management Information Systems and Network+ and A+ certifications. The purpose of the Information Security Program is to:
The Company has also implemented an Incident Response Plan which is reviewed and updated at least annually in response to an ever-changing threat landscape. The purpose of the Incident Response Plan is to provide long-term strategies for the remediation and prevention of, and resiliency to, cybersecurity threats and incidents. Our Incident Response Plan is executed through the incident response team comprised of both cybersecurity experts and select members of management, including one or more Information Security Officers, who are responsible for monitoring potential threats and identifying events that may warrant Board notification and/or public disclosure. Additionally, our Information Security Officers are responsible for responding to security events by ordering emergency actions to protect the Company and its customers; managing negative effects on the confidentiality, integrity, and availability of information; and minimizing the disruption and degradation of critical services.
Notwithstanding the strength of Ohio Valley’s defensive measures, the threat from cyber-attacks is severe, attacks are sophisticated and increasing in volume, and attackers respond rapidly to changes in defensive measures. While to date, Ohio Valley has not detected a significant compromise, significant data loss, or any material financial losses related to cybersecurity attacks, Ohio Valley’s systems and those of its customers and third-party service providers are under constant threat, and it is possible that Ohio Valley could experience a significant event in the future. Risks and exposures related to cybersecurity attacks are expected to remain high for the foreseeable future due to the rapidly evolving nature and sophistication of these threats, as well as due to the expanding use of Internet banking, mobile banking, and other technology-based products and services by us and our customers.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board, through the Information Technology Steering Committee, works with senior management and other employee committees to oversee the development, implementation, maintenance, and administration of the Information Security Program, which is aligned and integrated into Ohio Valley’s overall risk management system and processes.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board, through the Information Technology Steering Committee, works with senior management and other employee committees to oversee the development, implementation, maintenance, and administration of the Information Security Program, which is aligned and integrated into Ohio Valley’s overall risk management system and processes.
|Cybersecurity Risk Role of Management [Text Block]
|
The Company has also implemented an Incident Response Plan which is reviewed and updated at least annually in response to an ever-changing threat landscape. The purpose of the Incident Response Plan is to provide long-term strategies for the remediation and prevention of, and resiliency to, cybersecurity threats and incidents. Our Incident Response Plan is executed through the incident response team comprised of both cybersecurity experts and select members of management, including one or more Information Security Officers, who are responsible for monitoring potential threats and identifying events that may warrant Board notification and/or public disclosure. Additionally, our Information Security Officers are responsible for responding to security events by ordering emergency actions to protect the Company and its customers; managing negative effects on the confidentiality, integrity, and availability of information; and minimizing the disruption and degradation of critical services.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our Incident Response Plan is executed through the incident response team comprised of both cybersecurity experts and select members of management, including one or more Information Security Officers, who are responsible for monitoring potential threats and identifying events that may warrant Board notification and/or public disclosure.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Information Security Officer of the committee has 26 years of banking experience including 25 IT related years as well as continuing education including a BA in Management Information Systems and Network+ and A+ certifications.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The purpose of the Incident Response Plan is to provide long-term strategies for the remediation and prevention of, and resiliency to, cybersecurity threats and incidents. Our Incident Response Plan is executed through the incident response team comprised of both cybersecurity experts and select members of management, including one or more Information Security Officers, who are responsible for monitoring potential threats and identifying events that may warrant Board notification and/or public disclosure. Additionally, our Information Security Officers are responsible for responding to security events by ordering emergency actions to protect the Company and its customers; managing negative effects on the confidentiality, integrity, and availability of information; and minimizing the disruption and degradation of critical services.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef