INFORMATION SECURITY & PRIVACY 27 Information Commitment to Security Security and and Confidentiality The Information Security program is structured by At Hancock Whitney, we expect each associate to be Privacy a comprehensive collection of policies, guidelines responsible for the security and confidentiality of client and procedures, which are periodically updated and information. We communicate this responsibility to approved by the appropriate committees. These policies, associates upon hiring and regularly throughout their guidelines and procedures align with regulatory guidance, employment. Hancock Whitney’s Chief Information Security Officer the ISO Code of Practice for Information Security Controls (CISO) directs the company’s Information Security and common industry practices. We require each associate to complete training to protect program. The program is designed to protect the security the confidentiality of client information at the time of hire of our computer systems, networks, software and As required by Federal Financial Institutions Examination and during each year of employment. Associates must information assets, including client data. Council guidance, the CISO provides an annual report successfully pass a test to demonstrate understanding on the state of the Information Security program to the of these requirements and provide acknowledgement Led by our CISO, a team of dedicated security Risk Committee. of their responsibilities under the Information Systems professionals examines risks to the company’s Acceptable Use Policy. information systems and assets, designs and implements The company’s Enterprise Risk Management program security solutions, monitors the environment and also has a role in governance of the Information Security We regularly provide associates with Information Security provides immediate responses to threats. program, working with Information Security management awareness training, including the recognition and to facilitate performance of Risk and Control Self appropriate handling of potential phishing emails, which Assessments, the results of which are included in Risk can introduce malware to a company’s network, result in Program Governance Committee metrics. the theft of user credentials and, ultimately, place client and Structure information at risk. Hancock Whitney employs a number Our Enterprise Risk Management program shapes our of technical controls to mitigate the risk of phishing emails Information Security strategy and development. Teams of targeting associates. We regularly test associates to Governance of the Information Security program begins internal resources and independent expert cybersecurity determine their susceptibility to phishing test emails. We with the IT Risk Governance Subcommittee, whose firms perform risk assessments on an ongoing basis to require susceptible associates to take additional training objective is to protect the integrity, security, safety and identify risks and associated controls. We use the findings and provide regular reports to management. resiliency of corporate information systems and assets. to identify opportunities to strengthen the program and remedy residual risks. Hancock Whitney’s Associate Handbook and Code of This management-level subcommittee meets regularly Conduct and the Code of Business Ethics for Officers and to review the development of the program, make The company’s prudential regulators, the FDIC and Associates contain additional guidance on the protection recommendations and provide regular subcommittee the Mississippi Department of Banking and Consumer and privacy of client information. reports to the Operations Committee, Capital Committee Finance, regularly examine the Information Security and, ultimately, the board of directors via the Risk program. Internal Audit also performs regular reviews Committee. of the program.
2022 Hancock Whitney ESG Report Page 26 Page 28