XML 40 R27.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cybersecurity threats are assessed, identified, and managed within our Enterprise Risk Management Framework. We use a multi-layered approach to effectively manage risk. This approach includes, but is not limited to: (1) employees who are responsible for and manage risk; (2) employees and systems that oversee, monitor, and report risk; and (3) independent assurance, evaluation, and oversight of risk management activities.
Our security strategy is a layered approach. We utilize multiple layers of defense, both internally and externally, to ensure the integrity of our systems and data. We engage reputable security partners (assessors, consultants, auditors, and other third parties) for real time analysis and protection of our network infrastructure. This includes the use of preventative and detective tools to monitor, block, and alert us to suspicious activity. We utilize industry and regulator recognized assessment tools, such as the FFIEC Cybersecurity Assessment Tool and the Ransomware Self-Assessment Tool, to identify potential cybersecurity threats as well as the impact they could have on the Bank. Dashboards are used to track and monitor cybersecurity activity and trends.
We have established programs in place to proactively mitigate and respond to cybersecurity risk. The Vendor Management Program provides management with a framework to evaluate new vendors and ensure ongoing monitoring of third parties, including the evaluation of cybersecurity risk. The Incident Response Plan provides a framework for management to respond to and minimize the impact of an incident involving our information technology systems, or that of one of our third-party providers. The Business Continuity Plan provides information to prepare for and manage a business disruption.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Cybersecurity threats are assessed, identified, and managed within our Enterprise Risk Management Framework. We use a multi-layered approach to effectively manage risk. This approach includes, but is not limited to: (1) employees who are responsible for and manage risk; (2) employees and systems that oversee, monitor, and report risk; and (3) independent assurance, evaluation, and oversight of risk management activities.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board Risk Committee assists the Board in fulfilling its responsibilities related to the oversight of the Bank’s     Enterprise Risk Management Framework. The Board Risk Committee oversees executive management’s design, implementation, and maintenance of an effective risk management program to ensure compliance with laws and regulations, and operation within the parameters established in the Bank’s risk appetite statement. This includes a review of the cybersecurity dashboard which summarizes key risk indicators and identifies emerging risks.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Information Technology Risk Management Committee is chaired by the Chief Technology Officer and comprised         of IT management and other key stakeholders from across the Bank. They are responsible for identifying, measuring, monitoring, and controlling risk generated within IT, including cybersecurity risk. This committee reviews and updates risk assessments as necessary and monitors activity through risk reports and dashboards. A cybersecurity dashboard, which includes a summary of key risk metrics, is reviewed and monitored by the IT Risk Management. The Chief Technology Officer and Information Security Officer provide quarterly reports to the Board Risk Committee.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Information Technology Risk Management Committee is chaired by the Chief Technology Officer and comprised         of IT management and other key stakeholders from across the Bank. They are responsible for identifying, measuring, monitoring, and controlling risk generated within IT, including cybersecurity risk. This committee reviews and updates risk assessments as necessary and monitors activity through risk reports and dashboards. A cybersecurity dashboard, which includes a summary of key risk metrics, is reviewed and monitored by the IT Risk Management. The Chief Technology Officer and Information Security Officer provide quarterly reports to the Board Risk Committee.
The Board Risk Committee assists the Board in fulfilling its responsibilities related to the oversight of the Bank’s     Enterprise Risk Management Framework. The Board Risk Committee oversees executive management’s design, implementation, and maintenance of an effective risk management program to ensure compliance with laws and regulations, and operation within the parameters established in the Bank’s risk appetite statement. This includes a review of the cybersecurity dashboard which summarizes key risk indicators and identifies emerging risks.
The Board Risk Committee provides a verbal risk report and meeting minutes to the Board periodically. In addition, the full Board reviews the Risk Management processes and results, and the Board’s Audit Committee tracks any corrective actions identified in the Internal Audit process. Cybersecurity incidents are escalated to the Board in a timely manner using the processes defined within the Bank’s Incident Response Plan.
Cybersecurity Risk Role of Management [Text Block]
The Information Technology Risk Management Committee is chaired by the Chief Technology Officer and comprised         of IT management and other key stakeholders from across the Bank. They are responsible for identifying, measuring, monitoring, and controlling risk generated within IT, including cybersecurity risk. This committee reviews and updates risk assessments as necessary and monitors activity through risk reports and dashboards. A cybersecurity dashboard, which includes a summary of key risk metrics, is reviewed and monitored by the IT Risk Management. The Chief Technology Officer and Information Security Officer provide quarterly reports to the Board Risk Committee.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
We employ Information Technology staff to analyze and protect our network infrastructure. Members of our IT staff have relevant training and education in computer networks and systems, information security and intelligence, and hold industry certifications related to network security, enterprise IT governance, and risk and information systems control. In addition, our employees network with peer banks, participate in industry groups, and attend ongoing training to stay abreast of cybersecurity threats and best practices.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Members of our IT staff have relevant training and education in computer networks and systems, information security and intelligence, and hold industry certifications related to network security, enterprise IT governance, and risk and information systems control.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
Within the Enterprise Risk Management Framework, we have established committees, both at the management and board level, to oversee risk, and ensure cybersecurity risk is escalated appropriately to the Board.
The Information Technology Risk Management Committee is chaired by the Chief Technology Officer and comprised         of IT management and other key stakeholders from across the Bank. They are responsible for identifying, measuring, monitoring, and controlling risk generated within IT, including cybersecurity risk. This committee reviews and updates risk assessments as necessary and monitors activity through risk reports and dashboards. A cybersecurity dashboard, which includes a summary of key risk metrics, is reviewed and monitored by the IT Risk Management. The Chief Technology Officer and Information Security Officer provide quarterly reports to the Board Risk Committee.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true