Northwest Bancshares, Inc. 10-K Cybersecurity GRC - 2024-02-23

Page last updated on July 16, 2024

Northwest Bancshares, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-02-23 17:27:09 EST.

Filings

10-K filed on 2024-02-23

Northwest Bancshares, Inc. filed a 10-K at 2024-02-23 17:27:09 EST
Accession Number: 0001471265-24-000009

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY Risk Management and Strategy Our risk management program is designed to identify, assess, and mitigate risks across various aspects of our company, including credit, market, treasury, operational, compliance, model and data, and reputational. Cybersecurity is a critical component of this program, given the increasing reliance on technology and potential for a cybersecurity incident to occur, which could disrupt business operations or compromise sensitive data. Our Chief Information Security Officer (“CISO”) is primarily responsible for this cybersecurity component and is a key member of the organization, reporting directly to the Chief Information Officer and, as discussed below, periodically to the Innovation and Technology Committee of our board of directors. To date, the Company has not, to its knowledge, experienced an incident materially affecting or reasonably likely to materially affect the Company. To prepare and respond to incidents, the Company has implemented a multi-layered cybersecurity program that is intended to comply with Gramm-Leach-Bliley Act (GLBA) 12 CFR 364, Appendix B, integrating people, technology, and processes. This includes employee training, the use of innovative technologies, and the implementation of policies and procedures in the areas of Information Security, Data Governance, Business Continuity and Disaster Recovery, Privacy, Third-Party Risk Management, and Incident Response. Our objective for managing cybersecurity risk is to avoid or minimize the impacts of external threat events or other efforts to penetrate, disrupt or misuse our systems or information. The cybersecurity program is built upon a foundation of advanced security technology, our internal employee team, and operations based on industry best practices recommendations from the National Institute of Standards and Technology (NIST) Cybersecurity Framework, Federal Financial Institutions Examination Council (FFIEC) Guidelines, and Center for Internet Security (CIS) Benchmarks. This consists of controls designed to identify, protect, detect, respond and recover from information and cyber security incidents. Our Chief Information Security Officer and our Chief Information Officer, who reports directly to our Chief Executive Officer, along with key members of their teams, regularly collaborate with peer banks, industry groups, and policymakers to discuss cybersecurity trends and issues and identify best practices. The information security program is periodically reviewed by such personnel with the goal of addressing changing threats and conditions. We also employ a variety of preventative and detective tools designed to monitor, block, and provide alerts regarding suspicious activity, as well as to report on suspected advanced persistent threats. We have established processes and systems designed to mitigate cyber risk, including regular and on-going education and training for employees, preparedness simulations and tabletop exercises, and recovery and resilience tests. We engage in regular assessments of our infrastructure, software systems, and network architecture, using internal cybersecurity experts and third-party specialists. We also actively monitor our email gateways for malicious phishing email campaigns and monitor remote connections as a significant portion of our workforce has the option to work remotely. The Company relies on third-party vendor solutions to support its operations. Many of these vendors, especially in the financial services industry, have access to sensitive and proprietary information. To mitigate the operational, informational and other risks associated with the use of vendors, the Company maintains a Third-Party Risk Management Program, which is implemented through a Third-Party Risk Management Policy and includes a detailed onboarding process and periodic reviews of vendors with access to sensitive Company data. The Third-Party Risk Management Policy applies to any business arrangement between the Company and another individual or entity, by contract or otherwise, in compliance with the Interagency Guidance on Third-Party Relationships: Risk Management. The Third-Party Risk Management Program is audited periodically in accordance with our Board approved Internal Audit plan. We leverage internal and external auditors and independent external partners to periodically review our processes, systems, and controls, including with respect to our information security program, to assess their design and operating effectiveness and make recommendations to strengthen our information security and risk management programs. Regular internal monitoring is integral to the Company’s risk assessment process, which includes regular testing of internal key controls, systems, and procedures. In addition, independent third-party penetration testing of the effectiveness of security controls and preparedness measures is conducted at least annually or more often, if warranted by the risk assessment or other external factors. Management determines the scope and objectives of the penetration analysis. We maintain both an Incident Response Plan and a Crisis Management Plan (the “Plans”) that provide a documented framework for responding to actual or potential cybersecurity incidents, including timely notification of and escalation to the appropriate Board-approved management committees, as discussed further below, and to the Innovation and Technology Committee of our board of directors. The Plans are coordinated through the Business Resiliency Manager and Major Incident Manager, who ultimately report to the Chief Information Officer, and key members of management are embedded into the Plans by their design. The Plans facilitate coordination across multiple parts of our organization and are evaluated at least annually. Integral elements of the Plans related to the Company’s response to security vulnerabilities include the following. - Identifying the appropriate team and any appropriate sub-teams to address specific information and/or cyber security incidents, or categories of information and/or cyber security incidents. - Coordinating Incident or Crisis Management activities, including developing, maintaining, and following appropriate procedures to respond to and document identified information and/or cyber security incidents. - Conducting post-incident reviews to gather feedback on information and/or cyber security incident response procedures and address any identified gaps in security measures. - Providing training and conducting periodic exercises to promote employee and stakeholder preparedness and awareness of the Plans. - Reviewing the Plans at least annually, or whenever there is a material change in the Company’s business practices that may reasonably affect its cyber incident response procedures. Notwithstanding our defensive measures and processes, the threat posed by cyber-attacks is severe. Our internal systems, processes, and controls are designed to mitigate loss from cyber-attacks and, while we have experienced cybersecurity incidents in the past, to date, risks from cybersecurity threats have not materially affected our company. For further discussion of risks from cybersecurity threats, see the section captioned “Risks Related to Operational Matters” in Item 1A. Risk Factors. Governance Our Chief Information Security Officer is accountable for managing our enterprise information security department and delivering our information security program. The responsibilities of this department include cybersecurity risk assessment, defense operations, cyber incident response, vulnerability assessment, threat intelligence, identity access governance, and the evaluation of third-party risk management and business resilience as it relates to the cybersecurity program. The foregoing responsibilities are covered on a day-to-day basis by our Chief Information Security Officer and their team. The department consists of information security professionals with varying degrees of education and experience. Individuals within the department are generally subject to professional education and certification requirements. Our Chief Information Security Officer has substantial relevant expertise and formal training in the areas of information security and cybersecurity risk management, including 20 years of cybersecurity experience, 12 of which was spent at the Company. Our Operational Risk Management group provides guidance, oversight, monitoring and challenge of the first line’s activities. The second line of defense function is separated from the first line of defense function through organizational structure and ultimately reports directly to the Chief Risk Officer. Our board of directors has established management committees including the Information Technology Steering Committee, which focuses on technology and business impact, and the Operational Risk Management Committee, which focuses on the identification, monitoring, assessment, and management of risk associated with our cyber and information security programs. These committees provide oversight and governance of the technology program and the information security program and are chaired by the Chief Information Officer and Chief Operational Risk Management Officer, respectively, and include the Chief Information Security Officer and other key departmental managers from throughout the entire company. The Information Technology Steering Committee meets monthly and the Operational Risk Management Committee meets at least quarterly to provide oversight of the risk management strategy, standards, policies, practices, controls, and mitigation and prevention efforts employed to manage security risks. More frequent meetings occur from time to time in accordance with the Incident Response Plan to facilitate timely informing and monitoring efforts. The Chief Information Security Officer reports summaries of key issues, including significant cybersecurity incidents, discussed at committee meetings and the actions taken to the Innovation and Technology Committee of our board of directors on a quarterly basis (or more frequently as may be required by the Incident Response Plan). The Innovation and Technology Committee of our board of directors is responsible for overseeing our information security and technology programs, including management’s actions to identify, assess, mitigate, and remediate or prevent material cybersecurity issues and risks. Our Chief Information Security Officer and our Chief Information Officer provide quarterly reports to the Innovation and Technology Committee of our board of directors regarding the information security program and the technology program, key enterprise cybersecurity initiatives, and other matters relating to cybersecurity processes. The Innovation and Technology Committee of our board of directors reviews and approves our information security and technology budgets and strategies annually. Additionally, the Risk Committee of our board of directors reviews key metrics summarizing our cyber security risk profile on a quarterly basis. The Innovation and Technology Committee and Risk Committee of our board of directors each provide a report of their activities to the full board of directors at each board meeting. Lastly, at least annually, the CISO reports directly to the Board the overall status of the Information Security Program and the Company’s compliance with the Interagency Guidelines for Safeguarding Customer Information. Any material findings related to the risk assessment, risk management and control decisions, service provider arrangements, results of testing, security breaches or violations are discussed as are management’s responses and any recommendations for program changes.


Company Information

NameNorthwest Bancshares, Inc.
CIK0001471265
SIC DescriptionNational Commercial Banks
TickerNWBI - Nasdaq
Website
CategoryLarge accelerated filer
Fiscal Year EndDecember 30