|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy. The Company relies extensively on various information systems and other electronic resources to operate its business. In addition, nearly all of the Company’s customers, service providers and other business partners on whom the Company depends, including the providers of the Company’s online banking, mobile banking and accounting systems, use these systems and their own electronic information systems. Any of these systems can be compromised, including by employees, customers and other individuals who are authorized to use them, and bad actors using sophisticated and constantly evolving set of software, tools and strategies to do so. The nature of the Company’s business, as a financial services provider, and the Company’s relative size, make the Company and its business partners high-value targets for these bad actors to pursue. See Item 1A. Risk Factors—Operational, Strategic and Reputational Risks of this Form 10-K for additional information.
Accordingly, the Company has devoted significant resources to assessing, identifying and managing risks associated with cybersecurity threats, as noted below:
This information security program is a key part of the Company’s overall risk management system, which is administered by the Director of Information Security. The program includes administrative, technical and physical safeguards to help protect the security and confidentiality of customer records and information. These security and privacy policies and procedures are in effect across all of the Company’s businesses and geographic locations.
From time-to-time, the Company has identified cybersecurity threats and cybersecurity incidents that require the Company to make changes to its processes and to implement additional safeguards. While none of these identified threats or incidents have materially affected the Company, it is possible that threats and incidents the Company identifies in the future could have a material adverse effect on its business strategy, results of operations and financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The Company relies extensively on various information systems and other electronic resources to operate its business. In addition, nearly all of the Company’s customers, service providers and other business partners on whom the Company depends, including the providers of the Company’s online banking, mobile banking and accounting systems, use these systems and their own electronic information systems. Any of these systems can be compromised, including by employees, customers and other individuals who are authorized to use them, and bad actors using sophisticated and constantly evolving set of software, tools and strategies to do so. The nature of the Company’s business, as a financial services provider, and the Company’s relative size, make the Company and its business partners high-value targets for these bad actors to pursue. See Item 1A. Risk Factors—Operational, Strategic and Reputational Risks of this Form 10-K for additional information.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|From time-to-time, the Company has identified cybersecurity threats and cybersecurity incidents that require the Company to make changes to its processes and to implement additional safeguards. While none of these identified threats or incidents have materially affected the Company, it is possible that threats and incidents the Company identifies in the future could have a material adverse effect on its business strategy, results of operations and financial condition.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance. The Company’s management team is responsible for the day-to-day management of cybersecurity risks it faces, including the Company’s Executive Vice President and Chief Operating Officer and Director of Information Security. The Company’s current Director of Information Security has over 29 years of experience. For the past 8 years, the Company’s Director of Information Security has successfully managed teams, implementing and maintaining robust cybersecurity and data protection controls to safeguard the Company’s information assets. The Company’s Director of Information Security reports directly to our Executive Vice President and Chief Operating Officer, who possesses extensive expertise gained through over 30 years in various risk, operations and leadership roles. This combined experience ensures exceptional guidance and oversight of our cybersecurity program.
In addition, the Board, both as a whole and through its Risk Committee (the “Risk Committee”), is responsible for the oversight of risk management, including cybersecurity risks. In that role, the Board and the Risk Committee, with support from the Company’s cybersecurity advisors, are responsible for ensuring that the risk management processes designed and implemented by management are adequate and functioning as designed. To carry out those duties, both the Board and the Risk Committee receive quarterly reports from the Company’s management team regarding cybersecurity risks and the Company’s efforts to prevent, detect, mitigate and remediate any cybersecurity incidents.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|In addition, the Board, both as a whole and through its Risk Committee (the “Risk Committee”), is responsible for the oversight of risk management, including cybersecurity risks. In that role, the Board and the Risk Committee, with support from the Company’s cybersecurity advisors, are responsible for ensuring that the risk management processes designed and implemented by management are adequate and functioning as designed. To carry out those duties, both the Board and the Risk Committee receive quarterly reports from the Company’s management team regarding cybersecurity risks and the Company’s efforts to prevent, detect, mitigate and remediate any cybersecurity incidents.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Company’s management team is responsible for the day-to-day management of cybersecurity risks it faces, including the Company’s Executive Vice President and Chief Operating Officer and Director of Information Security. The Company’s current Director of Information Security has over 29 years of experience. For the past 8 years, the Company’s Director of Information Security has successfully managed teams, implementing and maintaining robust cybersecurity and data protection controls to safeguard the Company’s information assets. The Company’s Director of Information Security reports directly to our Executive Vice President and Chief Operating Officer, who possesses extensive expertise gained through over 30 years in various risk, operations and leadership roles. This combined experience ensures exceptional guidance and oversight of our cybersecurity program.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef