XML 54 R38.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Like every major financial services institution, Wintrust faces significant and persistent cybersecurity risks. Whether in the form of data theft, ransomware, phishing, denial of service, or third-party vendor incidents, threat actors continue to become more sophisticated and escalate their efforts against financial institutions. At Wintrust, the Board of Directors and executive management are committed to devoting the necessary resources into monitoring, detecting, preventing and mitigating
cybersecurity risk. As a regulated financial institution, we are required to comply with various regulations applicable to cybersecurity, as well as guidance issued by our regulators, and our cybersecurity program closely tracks to those requirements. Additionally, Wintrust leverages global cybersecurity standards as general guides, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.

Cybersecurity oversight begins with the Information Technology & Information Security Committee (“IT/IS Committee”) of the Wintrust Board of Directors. The Wintrust Chief Security Officer (“CSO”) and designated officers under his supervision oversee the cybersecurity program. The CSO has a dual reporting structure, reporting to both the IT/IS Committee and the Vice Chairman/Chief Operating Officer of Wintrust. The CSO and his designated officers have extensive industry experience and manage a team of skilled professionals with cybersecurity expertise. This team governs our cybersecurity program that follows NIST cybersecurity framework components of Govern, Identify, Protect, Detect, Respond and Recover. Our cybersecurity program employs a wide range of technological, administrative, and physical security measures designed to address the confidentiality, integrity, and availability of the information and data of both Wintrust and our customers. We have established policies, processes and procedures to monitor, report and respond to suspected or actual security events. A critical function of the cybersecurity program is the Security Operations Center, which is constantly monitoring Wintrust systems to detect threats. If any credible threats are detected, the Security Operations Center notifies the CSO and the appropriate response plan is initiated. The CSO will advise executive management and other relevant stakeholders as necessary. We coordinate with our third parties and vendor partners through assessments and due diligence reviews before sharing or allowing the hosting or processing of data. We also work with our outside partners to investigate security events that may have impacted our business or data, and to leverage lessons learned during those investigations. In addition, we contractually require our third-party service providers that possess or process any Wintrust or customer information to adhere to certain security requirements, controls and responsibilities based on the risk profile of the relationship.
Wintrust also recognizes that individual employees are frequent targets of threat actors. We regularly engage with employees on the importance of protecting the information and data of Wintrust, our customers and employees through monthly newsletters, poster campaigns and other formal communications. If specific threats are identified, management may communicate those threats directly to employees for heightened awareness. Our cybersecurity program requires employees to review information security policies annually, complete multiple cybersecurity training courses throughout the year, and participate in monthly mock phishing campaigns. We also communicate with our customers about their role in enhancing cybersecurity and protecting their identities and data.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Like every major financial services institution, Wintrust faces significant and persistent cybersecurity risks. Whether in the form of data theft, ransomware, phishing, denial of service, or third-party vendor incidents, threat actors continue to become more sophisticated and escalate their efforts against financial institutions. At Wintrust, the Board of Directors and executive management are committed to devoting the necessary resources into monitoring, detecting, preventing and mitigating
cybersecurity risk. As a regulated financial institution, we are required to comply with various regulations applicable to cybersecurity, as well as guidance issued by our regulators, and our cybersecurity program closely tracks to those requirements. Additionally, Wintrust leverages global cybersecurity standards as general guides, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.
Cybersecurity oversight begins with the Information Technology & Information Security Committee (“IT/IS Committee”) of the Wintrust Board of Directors.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Cybersecurity oversight begins with the Information Technology & Information Security Committee (“IT/IS Committee”) of the Wintrust Board of Directors.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Cybersecurity oversight begins with the Information Technology & Information Security Committee (“IT/IS Committee”) of the Wintrust Board of Directors.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The CSO reports at regular intervals to the Wintrust Enterprise Risk Management Committee, the IT/IS Committee, and the Audit Committee of the Wintrust Board of Directors, as well as the full Wintrust Board of Directors, as necessary. The Audit Committee performs an annual review of our cybersecurity program, which includes a discussion of management’s actions to identify and detect threats and incident plans in the event of a response or recovery situation. The Audit Committee receives an annual review that includes enhancements to the cybersecurity program and management’s progress on its cybersecurity strategic roadmap
Cybersecurity Risk Role of Management [Text Block] Besides our dedicated cybersecurity team, Wintrust’s risk management and internal audit teams provide additional review of its approach to cybersecurity. Our governance program maintains policies and standards, which are verified through risk-based assessments, reviews and testing. The CSO reports at regular intervals to the Wintrust Enterprise Risk Management Committee, the IT/IS Committee, and the Audit Committee of the Wintrust Board of Directors, as well as the full Wintrust Board of Directors, as necessary. The Audit Committee performs an annual review of our cybersecurity program, which includes a discussion of management’s actions to identify and detect threats and incident plans in the event of a response or recovery situation. The Audit Committee receives an annual review that includes enhancements to the cybersecurity program and management’s progress on its cybersecurity strategic roadmap. In addition, the Board of Directors receives quarterly cybersecurity reports, which include a review of key risk indicators, test results and related remediation, and an overview of recent threats and how the Company is managing those threats.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Wintrust Chief Security Officer (“CSO”) and designated officers under his supervision oversee the cybersecurity program. The CSO has a dual reporting structure, reporting to both the IT/IS Committee and the Vice Chairman/Chief Operating Officer of Wintrust.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The CSO and his designated officers have extensive industry experience and manage a team of skilled professionals with cybersecurity expertise.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] A critical function of the cybersecurity program is the Security Operations Center, which is constantly monitoring Wintrust systems to detect threats. If any credible threats are detected, the Security Operations Center notifies the CSO and the appropriate response plan is initiated. The CSO will advise executive management and other relevant stakeholders as necessary. We coordinate with our third parties and vendor partners through assessments and due diligence reviews before sharing or allowing the hosting or processing of data.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true