SB FINANCIAL GROUP, INC. 10-K Cybersecurity GRC - 2026-03-06

Page last updated on March 6, 2026

SB FINANCIAL GROUP, INC. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2026-03-06 12:48:17 EST.

Filings

10-K filed on 2026-03-06

SB FINANCIAL GROUP, INC. filed a 10-K at 2026-03-06 12:48:17 EST
Accession Number: 0001213900-26-024471

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity The Company regularly assesses risks from cybersecurity threats, monitors its information systems for potential vulnerabilities, and tests those systems pursuant to the Company's cybersecurity policies, standards, processes, and practices, which are integrated into the Company's overall risk management program. We have adopted aspects of the National Institute of Standards and Technology ("NIST") cybersecurity framework, to which risk management in relation to our information systems is aligned. We categorize our information systems as either Tier 1 (critical) or Tier 2 or Tier 3 (essential), depending on business value and/or risk of financial or compliance impact of cybersecurity incidents. Our information security team uses a multifaceted approach to monitor, assess, identify, and manage material risks to the Company from cybersecurity threats, including testing of the effectiveness of our cybersecurity incident prevention and response systems; conducting routine vulnerability scanning of information systems assets; network/endpoint detection and response coupled with advanced identification-enhanced logging capabilities powered by artificial intelligence software; discovery through collaboration with the Company's internal audit team; monitoring of threat intelligence feeds provided by industry associations/groups, service providers, and federal/state authorities; and professional service engagements, such as retaining the services of an external 24/7 security operations center and partnering with third parties in testing our information systems for vulnerabilities from external, internal, and social engineering perspectives and assessing the effectiveness of our cybersecurity controls. 25 The Company partners with third-party service providers and employs processes to assess, identify, and manage material risks from cybersecurity threats arising from the use of such third-party service providers. Our latest assessment attempted to identify vulnerabilities in our network and systems from external, internal, and social engineering perspectives. Our cybersecurity practices (including with respect to third-party service providers) have been assessed to represent a level of maturity consistent with industry best practices. Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected the Company, including its business strategy, results of operations, and financial condition. For more information about these and other risks, see ITEM 1A. RISK FACTORS. Our Board of Directors oversees the Company's risk management process, including cybersecurity risks, directly and through its committees, specifically the Risk Management Committee of the Board. The Audit Committee and the Board of Directors provide structured oversight of the Company's risk management program, which focuses on the most significant short, intermediate, and long-term risks the Company faces. The Company has an Information Security Council (the "Council") that is responsible for overseeing the development and upkeep of written policies and procedures aimed at safeguarding the Company's information systems and the nonpublic information stored within them. In addition, the Council plays a crucial role in the governance of the cybersecurity risk management process. This involves collaborating with third-party industry experts and the Company's internal audit team to conduct risk assessments of the Company's information security program (the "Program"). The assessments encompass an evaluation of the Company's adherence to the Program, including the elements of the Program that are dictated by relevant laws, regulations, and the Company's information security policy and procedures. Reports of the Council are shared regularly throughout the year with the Board of Directors. Furthermore, the Company conducts periodic cybersecurity assessments and preparedness analyses, supervised by our designated Chief Technology Innovation Officer ("CTIO"). Our CTIO has extensive systems and network experience at a global scale including work as Network and Telecommunications Leader for GE Corporate in the Latin America group and Manager of Global Networks for GE Lighting. His experience involved managing systems, development, and operations for GE Insurance Solutions, Swiss Re, and GE Capital Treasury. He holds a Cybersecurity Certification from Harvard since 2021 Cybersecurity: Managing Risk in the Information Age. The Company routinely engages third-party industry experts to perform risk assessments of the Program. At least annually, our internal audit team conducts a formal risk assessment and develops an audit plan that identifies, assesses, and prioritizes risks that include cybersecurity. The results of the risk assessment and the proposed audit plan are communicated to various leaders within the Company as well as the Audit Committee for input. The audit plan is reassessed throughout the year, and the plan is subject to modification by our internal audit team, e.g., based on such considerations as changes to resources, business operations, or internal or external risk factors.


Company Information

NameSB FINANCIAL GROUP, INC.
CIK0000767405
SIC DescriptionState Commercial Banks
TickerSBFG - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndDecember 31