INFORMATION SECURITY & PRIVACY 28 Associates must also follow established procedures for Information Security Threat Intelligence the safe storage and handling and secure disposal of Protections and Defense client information. All retired computer assets are subject In addition to ongoing updates to our security tools, to defined procedures and processes to ensure safe Hancock Whitney’s Cyber Defense Center team destruction of information contained on those devices. Hancock Whitney protects its network and information constantly monitors threat intelligence sources to For paper-based information, we train all associates assets with industry-proven security products and anticipate and research evolving threats, investigates to dispose of paper using a secure company-wide processes. Our Information Security Architecture team their potential impact to financial services companies, document destruction program. performs market research on potential products and examines company controls to detect and defend against tools. The team implements technology and applications those threats and proactively adjusts company defenses to protect the security of the systems and data from the against those threats. Technology Controls beginning of their life cycles. and Protocols The board of directors and our executives appreciate the severity of cybersecurity-related risks and support Security Monitoring the continuous development of and investment in the We allow only approved, company-managed devices to and Response Information Security program. join the private network for access and handling of client information in electronic form. We also have a secure thin-client access solution that allows authorized users The Cyber Defense Center team actively monitors Third-party Vendor to view and work with client information while keeping company networks and systems to detect suspicious or Controls that information secure within the company network. malicious events. A Managed Security Service Provider Associates may also access email, calendars, files, and supplements our monitoring to provide 24 hours a day, other resources on our private network by use of a secure seven days a week coverage. Internal investigators As the services of third-party providers are engaged, the application on the associate’s personal device. With use triage and investigate detected events. The company company utilizes a robust due diligence process prior of this secure application, all information remains on the maintains a cybersecurity Incident Response Plan. Per to executing an agreement. This process is led by the company network or in that company-managed secure the Incident Response Plan, an Incident Response team Vendor Management team and includes participation application container on the personal device. We strictly regularly performs exercises to simulate responses to of dedicated Information Security resources. Risk prohibit associates from exposing company and client cybersecurity events. Each exercise results in lessons assessments are performed using Service Organization information to non-Hancock Whitney-approved devices learned and subsequent improvement of the plan. The Controls (SOC) reports, self-attestation questionnaires or unauthorized parties. company also keeps expert firms on retainer to assist with and other tools. Third parties processing sensitive forensic investigation and management of any large-scale client data are contractually required to meet all legal cybersecurity events that could occur. and regulatory obligations to protect client data against security threats or unauthorized access. After contract executions, vendors undergo ongoing monitoring to ensure they continue to meet their security obligations.
2022 Hancock Whitney ESG Report Page 27 Page 29