The Bank discloses its cybersecurity governance and incident response policy in its 10-K Item 1C. The Board oversees cybersecurity risks and receives monthly monitoring reports. The Bank maintains an Incident Response Policy (IR Policy) applicable to employees, contractors, and third parties. The IR Policy outlines procedures for detection, containment, eradication, and recovery, including communication with stakeholders and regulators. The filing states that cybersecurity risks, including previous incidents, did not materially affect the Company's business, strategy, or financial condition during the fiscal year ended December 31, 2025.