2026 Pub. 20 Issue 4

2026 ISSUE 4 OFFICIAL PUBLICATION OF THE NEBRASKA BANKERS ASSOCIATION President’s Message Collective Support Leads to a Stronger Industry

800.228.2581 MHM.INC Now more than ever people want self-service options. With our core integrated ITMs we can make this a reality both in the lobby and in the drive-up of your branch. SELF-SERVICE BANKING ​233 S. 13th St., Ste. 700 Lincoln, NE 68508 Phone: (402) 474-1555 • Fax: (402) 474-2946 www.nebankers.org EDITORIAL STAFF RICHARD BAIER President & CEO richard.baier@nebankers.org GISELA JUNDT Director of Communications & Marketing gisela.jundt@nebankers.org​ BOARD OF DIRECTORS TRAVIS SEARS NBA Chair Union Bank & Trust Co., Lincoln SCOTT ZIMBELMAN NBA Chair-Elect Homestead Bank, Cozad MARK LINVILLE NBA Past Chair Homestead Bank, Randolph KRISTY BARTAK Nebraska State Bank & Trust Co. Broken Bow NICK BAXTER First National Bank of Omaha Omaha THOMAS CORRIGAN ACCESSbank Omaha KRYSTI CUNNINGHAM Security National Bank of Omaha Omaha JASON HANSEN Associated Bank Omaha CURTIS HEAPY Western Nebraska Bank Curtis ZAC HOLOCH Cornerstone Bank York JEFF KANGER First State Bank Nebraska Lincoln KRISTEN MARSHALL-MASER Five Points Bank Grand Island JEREMY McHUGH Corn Growers State Bank Murdock AARON OTTEN Elkhorn Valley Bank & Trust Norfolk KEVIN POSTIER Henderson State Bank Henderson LUKE RICKERTSEN Flatwater Bank Gothenburg BRIAN SCHWEIGER U.S. Bank, N.A. Lincoln RYNE SEAMAN Cattle Bank & Trust Seward RYAN STEFFENSMEIER First Community Bank Beemer KELLY TRAMBLY South Central State Bank Campbell NICK VRBA RVR Bank Fremont MICHAEL WHEELER Wells Fargo Bank, N.A. Omaha ANDREW WITT Dundee Bank Omaha​ NBA 4 NEBRASKA BANKER

EDITORIAL: Nebraska Banker seeks to provide news and information relevant to Nebraska and other news and information of direct interest to members of the Nebraska Bankers Association. Statement of fact and opinion are made on the responsibility of the authors alone and do not represent the opinion or endorsement of the NBA. Articles may be reproduced with written permission only. ADVERTISEMENTS: The publication of advertisements does not necessarily represent endorsement of those products or services by the NBA. The editor reserves the right to refuse any advertisement. SUBSCRIPTION: Subscription to the magazine, which began bimonthly publication in May 2006, is included in membership fees to the NBA. ©2026 The Nebraska Bankers Association (NBA) | MBR Connect™. All rights reserved. Nebraska Banker is published six times per year and is the official publication for this association. The information contained in this publication is intended to provide general information for review, consideration and education. The contents do not constitute legal advice and should not be relied on as such. If you need legal advice or assistance, it is strongly recommended that you contact an attorney as to your circumstances. The statements and opinions expressed in this publication are those of the individual authors and do not necessarily represent the views of NBA, its board of directors or the publisher. Likewise, the appearance of advertisements within this publication does not constitute an endorsement or recommendation of any product or service advertised. Nebraska Banker is a collective work, and as such, some articles are submitted by authors who are independent of NBA. While a first-print policy is encouraged, in cases where this is not possible, every effort has been made to comply with any known reprint guidelines or restrictions. Content may not be reproduced or reprinted without prior written permission. For further information, please contact the publisher at (801) 676-9722. CONTENTS 9 18 7 PRESIDENT’S MESSAGE COLLECTIVE SUPPORT LEADS TO A STRONGER INDUSTRY Richard J. Baier, President and CEO, Nebraska Bankers Association 9 NEBRASKA BANKS’ TOOLS TO COMBAT ELDER FINANCIAL ABUSE When Something Doesn’t Look Right Ryan McIntosh, General Counsel, Nebraska Bankers Association 12 COUNSELOR’S CORNER CONCERNING TRENDS IN CYBER-ENABLED FRAUD An Internet Crime Update for Financial Institutions Robert Kardell, Attorney, and Aiden Welsh, Summer Associate, Baird Holm LLP 18 TECH TALK BENEFITS OF RED TEAMING FOR FINANCIAL INSTITUTIONS Dylan Smith, Senior Network Security Engineer, SBS CyberSecurity 20 SBA LENDING IN A CHANGING RISK ENVIRONMENT What Compliance Officers Should Be Watching Now Alison Stokes, CRCM, Virtual Compliance Officer, Compliance Alliance 22 FROM PLAYBOOK TO PRACTICE: EMBEDDING RISK CULTURE Tracy R. Pastella, CERP, CRCM, CFE, AAP, CFSA, American Bankers Association 26 “GROUND” RULES: NEBRASKA FARM LEASE TERMINATION REQUIREMENTS John F. Zimmer, V, Cline Williams Wright Johnson & Oldfather LLP 28 2026 EDUCATION CALENDAR 5 NEBRASKA BANKER

BETTERTOOLS SERVICE BANKING Call Tim or Travis today to find out how much you could save. Why do community banks make the switch to MIB? Innovation & Technology: We continually enhance our services through a forwardthinking tech culture and strategic investments. User-Friendly Systems: Intuitive systems and easy-to-use services save customers time, effort, and stress. Superior Service: We go above and beyond—our experts will even visit onsite during service transitions. Operational Efficiency: Streamlined operations allow us to offer high-value services at highly competitive prices. mibanc.com MEMBER FDIC Lending Services Operational Services Audit Services* Tim Burns 402-480-0075 Travis Anderson 402-440-2448 * Audit Services are offered thru MIB Banc Services, LLC, a subsidiary of our holding company.

Collective Support Leads to a Stronger Industry Richard J. Baier, President and CEO Nebraska Bankers Association Supported by banks of all sizes in communities across Nebraska, the Nebraska Bankers Association (NBA) proudly serves as the state’s leading advocate for the banking industry. As the 2026-2027 NBA fiscal year began, NBA membership was reflected across Nebraska institutions, ranging from nearly $17 million in deposits at the smallest member bank to over $17 billion at the largest. Together, NBA member banks operate 1,048 branches in 338 Nebraska communities and employ more than 15,500 hardworking Nebraskans. The following chart highlights NBA membership by institution size and overall employment. NBA Members by Size Number of Institutions % of Membership % of Total Dues Total NE FTEs % of Total FTEs Under $251 Million 85 57% 24% 1,474 13% $251+ Million to $1 Billion 49 33% 41% 3,982 34% $1+ Billion to $5 Billion 12 8% 23% 4,482 39% $5+ Billion 3 2% 12% 1,634 14% Total 149 100% 100% 11,572 100% The association also benefits from the strong engagement of its Associate Members, Preferred Vendors and NBA Business Partners. The breadth and strength of the NBA result from members engaging with companies in these groups. More than 100 Associate Members strengthen the NBA through the Service Provider, Financial Affiliate and Emeritus categories. This diverse group includes construction firms, insurance companies, accounting and law firms, compliance companies, technology vendors, credit card processors, retired bankers and other valued partners. They regularly contribute as exhibitors, speakers and content providers, enriching NBA programs and resources. Learn more about associate membership on our website at nebankers.org/membership. The other groups of NBA supporters are Preferred Vendors and NBA Business Partners designated by the Nebraska Bankers Insurance Services Company (NBISCO) Board of Directors. As the NBA’s for-profit subsidiary, NBISCO selects businesses and organizations that offer distinctive products and services to Nebraska banks. Each NBA Preferred Vendor and Business PRESIDENT’S MESSAGE 7 NEBRASKA BANKER

Partner completes a thorough due diligence and review process, provides positive references from NBA member banks and regional or national banking organizations, and makes at least one formal presentation to the NBISCO Board. These firms further advance the NBA’s work through advertising, sponsorships and royalties. To help NBA member institutions confidently navigate advances in technology, evolving regulations and strategic opportunities, the NBISCO Board recently approved several new Preferred Vendors and a new NBA Business Partner. The following brief overview introduces each organization and the value it can bring to your institution. We encourage you to connect with these new vendors or partners and explore how their capabilities can support your goals. NBA Business Partner C8 Capital Network C8 Capital Network is a banking industry utility that connects commercial borrowers with vetted private capital providers and other banks, enabling traditional financial institutions to fund loans outside their internal capacity while retaining customer relationships and earning fee income. Preferred Vendors Data Driven Partners Data Driven Partners provides relationship intelligence that helps financial institutions find the right business opportunities faster. Lending Leads unifies market, competitor and portfolio intelligence so leaders, lenders and compliance teams can move faster together, finding qualified prospects, defending key relationships and strengthening CRA and Fair Lending performance. Profit Resource Inc. (PRI) PRI is a bank consulting firm specializing in identifying profitability improvement areas for financial institutions through revenue growth, cost control, streamlining processes and effective use of technology. PRI’s specialties include navigating core, payment, EFT, digital and LOS contract negotiation, bank strategic planning and special project management. Stablecore Stablecore enables banks to modernize their offerings with digital assets and instant payments. Stablecore allows banks to bring together stablecoins, tokenized deposits and digital assets seamlessly within existing core, digital banking and compliance platforms. The Stablecore system was designed with security, controls and compliance as core values. Thank you to the bank members, Associate Members, Preferred Vendors and NBA Business Partners whose collective support allows the NBA to represent the banking industry in Nebraska. Together, we are making Nebraska residents, businesses, organizations, farmers and communities stronger! Together, we are making Nebraska residents, businesses, organizations, farmers and communities stronger! LINCOLN BRUNING endacotttimmer.com 402-817-1000 Legal advice. Community banking experience. 8 NEBRASKA BANKER

Nebraska Banks’ Tools to Combat Elder Financial Abuse When Something Doesn’t Look Right Ryan McIntosh, General Counsel Nebraska Bankers Association As all Nebraska bankers know, fraud is no longer a distant threat or an occasional customer-service challenge. It is a daily and growing risk for financial institutions across the country, and Nebraska is not immune. Nebraska bankers are often the last line of defense when an older customer is pressured to wire money overseas, drain a safe deposit box, add a new joint owner, change beneficiaries or move funds under suspicious circumstances. That is why the Nebraska Bankers Association has worked with lawmakers, regulators, law enforcement, member banks and other partners to provide financial institutions with practical legal tools to help protect vulnerable adults and senior adults. The Nebraska Legislature recognized this need in 2020 with LB 909 and expanded those protections in 2026 with LB 838. Together, these laws give Nebraska financial institutions discretion, protection and flexibility when they reasonably believe financial exploitation may have occurred or is being attempted. A Legislative Response Built Around Bankers’ Real-World Experience LB 909 began as LB 853, introduced in 2020 by Sen. Matt Williams of Gothenburg. After testimony from NBA member banks and the director of the Nebraska Department of Banking and Finance, the bill was amended into LB 909, passed on July 21, 2020, and became effective that November. The law created Nebraska’s transaction-hold and notification framework for suspected financial exploitation. In 2026, Sen. Mike Jacobson of North Platte introduced LB 838 to build on that framework by authorizing financial institutions to establish an “authorized contact” program. LB 838 passed on April 10, 2026, and went into effect on July 18, 2026. The legislative findings, now contained in statute, reflect the balance bankers must strike every day, recognizing that financial institutions are uniquely positioned to detect exploitation, while also acknowledging banks’ contractual and federal and state law obligations to follow valid customer instructions faithfully and in a timely manner. Just as important, the law does not impose a duty to override valid customer instructions. It gives banks discretion to act when the facts warrant action. That distinction is important. Nebraska’s law is not a mandate that every suspicious circumstance lead to a hold, refusal or notification. It is a shield and a tool, allowing a bank to determine whether action is appropriate based on the information available at the time. What the Law Allows Banks to Do Under Neb. Rev. Stat. § 8-2903, when a financial institution or employee reasonably believes that financial exploitation of a vulnerable adult or senior adult may have occurred, may have been attempted, is occurring or is being attempted, the institution may delay or refuse a transaction. The definition of “transaction” is broad. It includes transfers or disbursements, wires, ACH transactions, money orders, cashier’s checks, checks, changes in ownership or account access, loans or extensions of credit, encumbrances on property, and changes to beneficiary designations or contract rights at death. In practical terms, the law applies to many situations bankers actually see, not just withdrawals. A transaction hold generally expires upon the earlier of 30 business days after the institution first acted, the point at which the institution is satisfied the transaction will not result in exploitation, or termination by court order. However, unless otherwise directed by a court, a financial institution may extend the hold if it reasonably believes exploitation may continue or continue to be attempted. Third-Party Notification and Authorized Contacts Nebraska law also allows banks to notify a third party reasonably associated with a vulnerable adult or senior adult. This may include a parent, spouse, adult child, sibling, family member, close associate, co-owner, authorized signer, beneficiary, trustee, conservator, guardian, attorney-in-fact, fiduciary or attorney known to represent the customer. 9 NEBRASKA BANKER

LB 838 adds another option: the authorized contact. An authorized contact is an adult designated by a vulnerable adult or senior adult to be contacted in the event of an emergency, loss of contact with the customer or suspected financial exploitation. Authorized contact programs are optional, and a financial institution is immune from liability for choosing not to implement one. If a bank does implement a program and acts reasonably, the bank is protected. The law also provides that a financial institution is not liable for the actions of an authorized contact and may decline to interact with one if the contact may be involved in exploitation or if interaction is not in the customer’s best interests. This flexibility is critical. In some cases, a trusted contact may be the fastest way to interrupt a scam. In others, the person closest to the customer may be part of the problem. Nebraska law gives banks room to use judgment. Immunity, Safe Harbors and Privacy Considerations Bankers have long been concerned that acting too quickly could create liability, while failing to act could allow devastating customer losses. Nebraska’s elder financial abuse law addresses that concern directly. A financial institution, its bank holding company, and its employees, agents, officers and directors are immune from civil, criminal or administrative liability for delaying or refusing a transaction, or for choosing not to delay or refuse a transaction, under the law. The law also includes important safe harbors. A refusal to engage in a transaction under the elder abuse law does not constitute wrongful dishonor under Nebraska’s Uniform Commercial Code. A reasonable belief that payment of a check will facilitate financial exploitation also constitutes reasonable grounds to doubt collectability for purposes of federal funds availability laws and Regulation CC, as referenced in the Nebraska statute. Privacy concerns are addressed as well. The Gramm-Leach-Bliley Act and Regulation P contain exceptions that allow disclosures to protect against or prevent actual or potential fraud, unauthorized transactions, claims or liability, and to comply with federal, state or local legal requirements. A Practical Call to Action for Nebraska Banks The best fraud prevention tool is still a well-trained banker who knows the customer, recognizes a red flag and understands how to escalate concerns. Regardless of bank size or bank employee scope of duties, the message is the same: Nebraska law gives you tools to act when something does not look right. Banks should consider written procedures for transaction holds, third-party notification, authorized contacts, escalation, documentation and referrals to law enforcement and Adult Protective Services. The law does not require every financial institution to build the same program, but every institution should understand the authority it has and the protections available when staff act reasonably and in good faith. Nebraska bankers have always been more than transaction processors. They are trusted advisers, community leaders and often the first people to see when a customer is being targeted. LB 909 and LB 838 give banks additional tools, but it will be the judgment, training and commitment of Nebraska bankers that turn those tools into real protection. When a red flag appears, Nebraska banks now have more than concern. They have authority, discretion and legal protection to help stop exploitation before a lifetime of savings disappears. Current and past NBA leadership recognize Sen. Mike Jacobson (North Platte) on behalf of the Fraud Free Nebraska Coalition for championing legislation to protect senior adults from fraud. Left to right: NBA General Counsel Ryan McIntosh, NBA Past Chair Mark Linville (Homestead Bank, Randolph), Nebraska Sen. Jacobson and NBA President & CEO Richard Baier 10 NEBRASKA BANKER

While our n me h s ch nged under new ownership, the he rt of our comp ny rem ins the s me — including the reli ble, friendly te m you’ve lw ys worked with. Our go l is to be trusted p rtner for tr de nd profession l ssoci tions, strengthening membership nd connecting member businesses with their future customers. We look forward to what’s to come! New name. Same people. Renewed commitment. We’re excited to nnounce th t is now mbr-connect.com (801) 676-9722 hello@mbr-connect.com 11 NEBRASKA BANKER

COUNSELOR’S CORNER Concerning Trends in Cyber-Enabled Fraud An Internet Crime Update for Financial Institutions Robert Kardell, Attorney, and Aiden Welsh, Summer Associate Baird Holm LLP The Federal Bureau of Investigation (FBI) maintains the Internet Crime Complaint Center (IC3) and issues an annual report. The latest report, issued in 2025 and accessible by scanning the QR code, presents some concerning statistics. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf Cyber-Enabled Crime Continues to Rise Fraud conducted through the internet and other electronic communications has grown into one of the most significant financial crime problems facing American consumers and businesses. The IC3 2025 Annual Report stated that 1,008,597 complaints were filed, which resulted in approximately $20.9 billion in losses. That represents a 26% increase in reported losses from 2024 and amounts to an average reported loss of approximately $20,699 per complaint. IC3 is now receiving nearly 3,000 complaints every day. Those figures are striking not simply because they are large, but because of how rapidly the financial consequences of fraud are increasing. The FBI reported approximately $16.6 billion in losses in 2024, compared with $20.9 billion in 2025. 12

Cyber-Enabled Fraud Accounts for Most Financial Losses The report distinguishes general cybercrime complaints from what it describes as cyber-enabled fraud, a category of schemes in which criminals use the internet or other technology to steal money, information or identities or to facilitate fraudulent transactions. In 2025, IC3 received 452,868 cyber-enabled fraud complaints, representing approximately 45% of all complaints submitted to the center. Those cases were responsible for an extraordinary $17.7 billion in losses, or approximately 85% of all reported IC3 losses for the year. That disparity illustrates an important feature of modern fraud. The schemes that produce the most complaints are not necessarily the ones causing the largest financial losses. Of all cyber-enabled crimes, phishing and spoofing remained the most frequently reported crime category, generating 191,561 complaints. Extortion followed with 89,129 complaints, while investment-related schemes generated 72,984 complaints. Investment Fraud According to the graphic above, investment fraud was by far the most financially damaging category reported to IC3 in 2025. Victims reported approximately $8.65 billion in investment fraud losses. That single category accounted for more than 40% of all losses reported to IC3. Business email compromise (BEC) ranked second with approximately $3.05 billion in losses, followed by tech and customer-support scams at approximately $2.13 billion. Personal data breach-related complaints were associated with approximately $1.31 billion in losses, while confidence and romance scams resulted in approximately $929 million in reported losses. Government impersonation scams caused another $798 million in losses. The three-year comparison contained in the IC3 report is particularly revealing. Investment fraud complaints increased from 39,570 in 2023 to 47,919 in 2024 and 72,984 in 2025. Government impersonation complaints also climbed dramatically, from 14,190 in 2023 to 17,367 in 2024 and 32,424 in 2025. Tech-support complaints increased from 36,002 in 2024 to 47,794 in 2025. These trends show that fraudsters continue to refine schemes that rely less on technically sophisticated computer intrusions and more on manipulating victims into voluntarily transferring money. Cryptocurrency Has Become a Major Vehicle for Fraud IC3 received 181,565 cryptocurrency-related complaints in 2025, a 21% increase over 2024. Those complaints were associated with approximately $11.37 billion in losses, an increase of 22%. The average loss among cryptocurrency-related complainants was approximately $62,604, and 18,589 complainants reported losses exceeding $100,000. Cryptocurrency does not necessarily constitute a separate type of fraud. Instead, it increasingly serves as the mechanism for money transfers to investment scams, impersonation schemes, romance fraud and other crimes. The age distribution is especially noteworthy. Individuals aged 60 and older reported approximately $4.43 billion in cryptocurrency-related losses, substantially more than any other age group. People between 50 and 59 reported another $2.14 billion. These numbers help explain why cryptocurrency has become attractive to organized fraud operations. Transfers can occur rapidly, victims may have difficulty reversing transactions, and criminals can move proceeds through numerous accounts, wallets and jurisdictions. Continued on page 15 13 NEBRASKA BANKER

The Clear Choice Elevate your debit program performance With superior net economics, unmatched personal service, transparent billing, and Experian®-backed cardholder security benefits, Discover Debit delivers the capabilities to grow a successful debit program – making it the clear choice for community financial institutions like yours. Learn more at DiscoverDebit.com/Choice Discover® Debit

Older Americans Are Suffering Disproportionate Losses One of the most troubling findings in the 2025 report involves Americans aged 60 and older. IC3 received 201,266 complaints from individuals aged 60 or older, an increase of 37% from 2024. Reported losses for this group reached approximately $7.75 billion, a 59% increase in a single year. The average reported loss was $38,500, and 12,444 complainants over the age of 60 reported losses exceeding $100,000. By comparison, individuals between 50 and 59 reported approximately $3.68 billion in losses. Those ages 40 to 49 reported about $2.96 billion; ages 30 to 39 reported $1.74 billion; and ages 20 to 29 reported approximately $563 million. Victims under age 20 reported approximately $67 million in losses. Among older victims, investment fraud was the greatest financial threat, producing approximately $3.52 billion in losses. Tech-support scams caused more than $1.04 billion in losses among people 60 and older, while confidence and romance scams resulted in approximately $584 million. BEC and government impersonation scams accounted for another $568 million and $413 million, respectively. Fake Banking Websites One of the ways criminals can so easily perpetrate cyber-enabled fraud is the proliferation of fake banking websites. With the help of AI, cybercriminals can create a look-alike domain and site in just a few minutes, complete with security controls for In the last year alone, the IC3 report showed more effective efforts by fraudsters to exploit individuals in the modern era of online banking, investing and cryptocurrencies. 15 NEBRASKA BANKER

authentication and a fake accounting ledger. Criminals use such websites for everything from creating demand deposit accounts and certificates of deposit (CDs) to cryptocurrency trading. The fake CD websites are particularly difficult to address because the individuals tricked into sending their money to a fake website are often not looking for the money for six, 12, or 24 months. By the time the investor seeks repayment, the website is often gone, the perpetrators have moved on, the accounts to which the original investment was sent are empty or closed, and there are fewer leads or the leads are harder to follow due to the passage of time. Common steps taken by banks is to (1) monitor their own domain and search for look-alike domains; (2) educate customers as to how to spot and identify the correct domain banking website; (3) talk to customers on a regular basis either using email campaigns, old-fashioned letter campaigns, or hosting educational sessions for customers; and (4) if a fake domain is identified notify the domain registrar to immediately take it down. As an example of fake domains, a search for the domain of “capitalone” returned domains such as: • CAAPITALONE.COM • CABITALONE.COM • CACPITALONE.COM • CAIPITALONE.COM • CAITALONE.COM • CAJPITALONE.COM • CALITALONE.COM • CALPITALONE.COM • CAMPITALONE.COM • CANPITALONE.COM A search for “citi” produced numerous spoofed names such as: • EITI.COM • BITI.COM • CETI.COM • C-ITI.COM • XITI.COM • C1TI.COM • ICTI.COM • ITI.COM • CITI.IO • CLTI.COM In addition to banking sites, there are numerous fake cryptocurrency investment sites actively targeting and soliciting vulnerable individuals. Conclusion In the last year alone, the IC3 report showed more effective efforts by fraudsters to exploit individuals in the modern era of online banking, investing and cryptocurrencies. Such schemes are disproportionately affecting older individuals in communities and take many forms, making a blanket defense difficult to provide. Cyber-enabled schemes pose the greatest threat and cause most of the overall losses attributable to fraud. Greater access to technology does not necessarily mean more sophisticated schemes, but it does create a greater volume of schemes, making it difficult to slow the growth of fraud and protect consumers. Banks can help thwart the frauds by (1) monitoring domains similar to their own, and when such domains are discovered quickly notify the registrars to request takedown; (2) educating customers with presentations and regular fraud awareness campaigns through email, letters, account statements, webinars and branch events; and (3) helping customers identify and implement security controls appropriately for products and services such as CDs, new deposit accounts, wire transfers and cryptocurrency-related transactions, especially when customers are moving large sums to unfamiliar sites. Your Full-Service Bankers' Bank United Bankers' Bank is proud to be the nation's first bankers' bank, serving over 1,000 community banks from the West Coast to the Great Lakes and South Atlantic. We can't wait to share our passion for community banking with you! To Request Pricing Visit ubbRequest.com Contact your Nebraska Calling Officer: Michael Hahn VP, Correspondent Banking Officer michael.hahn@ubb.com ubb.com 16 NEBRASKA BANKER

RxHelp@myphahealth.com (844)742-9675 106 W 3 Street, McCook, NE 69001 rd Take Charge of Your Health! Prescription Education You have the power to be an informed consumer of healthcare. Prioritize Your Health, Starting Today Call PHA Health at (844)742-9675 Participate in our annual Wellness Partners Preventive Care Clinic Talk To Your Doctor Review your medications with your primary care physician at least once a year. If you see multiple doctors for conditions, ensure each physician knows your current medication to avoid potential side effects. Know Your Medications Ensure you understand the purpose, prescribed dosage, storage instructions, expiration date, and side effects of each medication. Don’t skip a dose or alter the prescribed dosage of your medication. Ask About Alternatives Ask if your medication has a generic or another affordable alternative. Call our Rx Advocates to review your medication for opportunities to eliminate or reduce your copay and out-of-pocket cost for your high-cost prescriptions. Live A Healthy Lifestyle Medication cannot replace the importance of a healthy diet and regular exercise. Preventive care gives you an opportunity to recognize and avoid potential future diseases before they even develop. Receive a comprehensive booklet that includes 40+ lab test results Identifying illnesses prior to the onset of symptoms is a key component in lowering your healthcare costs and maintaining quality of life. Visit with our Specialists to create a plan for your success Take your PCC results to your next PCP appointment Call PHA Health to identify which of your prescriptions could be eligible for savings.

Financial institutions are under constant siege from cyber threats. As the guardians of sensitive personal data, large financial assets, and complex transaction systems, banks and credit unions have become prime targets for increasingly sophisticated threat actors. To stay ahead, they must move beyond traditional defenses. Enter red teaming: a proactive, strategic approach to simulating real-world cyberattacks and uncovering security blind spots — before attackers do. What Red Teaming Reveals That Pen Testing Doesn’t Red teaming refers to the practice of simulating adversary tactics to test an organization’s ability to detect and respond to real-world attacks. Unlike traditional penetration testing, which typically identifies known vulnerabilities in isolated systems, red teaming mimics the tactics, techniques and procedures (TTPs) of real threat actors. This includes tailored attack paths, persistence mechanisms and lateral movement within the network. For financial institutions, red teaming provides a more holistic assessment — testing not only technical defenses but also employee readiness, incident response and policy effectiveness. Why Financial Institutions Are Prime Targets Banks and credit unions hold a wealth of valuable data: personally identifiable information (PII), account credentials, transaction histories and internal communications. This makes them high-value targets for cybercriminals and nation-state actors alike. Common threat vectors include: • Phishing • Credential stuffing • Ransomware • Insider threats • Supply chain attacks Reports consistently show the financial sector among the most targeted industries. For example, IBM’s “Cost of a Data Breach Report 2026” notes that breaches in this sector average more than $6.29 million per incident — making them not just frequent but financially devastating. Key Advantages of Red Teaming for Financial Institutions Proactive Threat Identification Red teaming uncovers weaknesses before adversaries do. These exercises test your institution’s ability to detect, respond and recover from advanced threats — strengthening agility and organizational awareness. Regulatory and Compliance Alignment Red teaming aligns with financial regulations such as FFIEC, Gramm-Leach-Bliley Act (GLBA) and Payment Card Industry Data Security Standard (PCI-DSS). It provides documentation that demonstrates proactive risk management, supports audit readiness and meets evolving compliance standards. Stronger Internal Security Practices These engagements often reveal misconfigurations, policy gaps or employee training shortfalls. These insights help information technology (IT), security operations center (SOC), compliance and leadership teams align on strategic security improvements. TECH TALK Benefits of Red Teaming for Financial Institutions Dylan Smith, Senior Network Security Engineer SBS CyberSecurity 18 NEBRASKA BANKER

As cyber threats grow more complex, financial institutions must take proactive steps to protect their systems, data and reputations. Realistic Training By simulating tactics like phishing, lateral movement and privilege escalation, red teaming gives defenders hands-on experience in high-stakes scenarios — boosting detection and response maturity. How to Effectively Implement Red Teaming in Financial Institutions Define Scope and Objectives Align red team efforts with your institution’s risk profile. Be clear on what’s in scope — applications, personnel, infrastructure — and secure executive buy-in for a smooth engagement. Work with Experienced Providers Choose partners with deep financial-sector expertise. Look for teams with a track record of success and a strong understanding of your regulatory environment. SBS CyberSecurity offers red teaming services specifically designed for financial institutions. Conduct a Post-Engagement Review After the exercise, hold a thorough debrief. Prioritize remediation based on risk, document key findings, and integrate lessons learned into ongoing strategy. Red teaming should be part of a continuous improvement cycle. Addressing Common Red Teaming Challenges Operational Risk Minimize disruptions through out-of-hours testing, clearly defined rules of engagement, and escalation protocols to avoid false alarms or downtime. Regulatory Coordination Engage regulators early. Transparency around testing objectives and outcomes demonstrates due diligence and strengthens compliance alignment. Resource Constraints Limited budget or bandwidth? Start with a phased or hybrid red/purple team engagement. Prioritize high-risk areas to maximize value. Elevating Financial Security with Red Teaming As cyber threats grow more complex, financial institutions must take proactive steps to protect their systems, data and reputations. Red teaming goes beyond technical testing — it evaluates how your people, processes and technologies hold up under pressure. If you’re wondering whether your organization could withstand a targeted attack, it’s time to find out. The threats aren’t waiting — why should you? This article was originally published on sbscyber.com. SBS helps business leaders identify and understand cybersecurity risks to make more informed and proactive business decisions. For more information, contact Ryan Kast at (605) 270-9381 or ryan.kast@sbscyber.com. Learn more at sbscyber.com. 19 NEBRASKA BANKER

SBA Lending in a Changing Risk Environment What Compliance Officers Should Be Watching Now Alison Stokes, CRCM, Virtual Compliance Officer Compliance Alliance Small Business Administration (SBA) lending remains one of the most meaningful ways banks can support local communities while building a strong portfolio. At the same time, the risk environment surrounding SBA lending has evolved. Banks are navigating faster origination expectations, more sophisticated fraud schemes, complex third-party relationships, and heightened documentation and governance standards. For compliance officers, the goal is not to slow down SBA lending. Instead, the objective is to support efficient lending by strengthening controls that protect the bank, the borrower and the SBA guaranty. By establishing clear oversight and well-defined processes, compliance helps the business lend with confidence. The following are key areas currently warranting attention. Fraud Controls Should Be Part of Daily Operations Fraud attempts tied to small business lending have become more persistent and harder to detect. While some of the most visible cases surfaced during emergency-era lending programs, many of the same patterns continue today. Common indicators include inconsistent borrower information, questionable or altered supporting documentation, and business activity that does not align with the stated purpose or operational profile. Compliance can support SBA lending teams by reinforcing clearly defined fraud-validation steps and escalation protocols. Strong intake controls and consistent handling of red flags reduce reliance on individual judgment and promote timely, well-supported decision-making when activity does not align or raises concern. 20 NEBRASKA BANKER

Documentation Should Support the Decision SBA lending has always required strong documentation, but expectations have shifted to ensure the loan file clearly supports each decision. Many banks can explain underwriting decisions in conversation, but the loan file itself may not always reflect the same rationale in a way that a second-line reviewer, auditor or examiner can easily validate. A practical approach is to define what “complete documentation” means and reinforce those expectations through checklists and procedure standards. At a minimum, the file should support borrower eligibility, the credit decision and required approvals. Strong file quality is more than a best practice; it also reduces servicing challenges and helps protect the SBA guaranty. Third-Party Oversight Matters More Than Ever Banks increasingly rely on third parties such as referral sources, loan agents, technology platforms and document support services. These relationships can improve speed and capacity, but they also introduce risk when responsibilities are unclear or oversight is informal. Compliance should help ensure the bank has clarity around who performs which activities across the SBA lifecycle, from borrower intake through closing and servicing. Monitoring should confirm that third parties operate within the bank’s expectations, issues are escalated in a timely manner, and the bank retains access to critical records. If a loan file cannot be retrieved quickly without third-party involvement, the relationship may be creating more risk than the business realizes. Change Management Must Be Consistent SBA programs are governed by procedural guidance, operational rules and internal bank requirements. When updates occur, many institutions implement changes operationally but do not consistently document how the change was assessed, approved, communicated and validated. Compliance can strengthen SBA programs by introducing lightweight, consistent and repeatable change-management practices. A sound approach includes defining the change and its impact, identifying affected procedures and training, confirming approvals, documenting implementation timing and validating execution. Banks may refer to SBA procedural guidance, such as SBA SOP 50 10, by scanning the QR code. https://www.sba.gov/document/ sop-50-10-lender-development-company-loan-programs Exception Tracking Helps Control Risk Although SBA lending differs from consumer lending, regulators still expect disciplined and consistent processes. Risk increases when credit decisions rely heavily on discretion without clear documentation standards and structured controls around exceptions. Compliance officers should pay close attention to how exceptions are defined, approved and tracked. A high volume of exceptions, unclear rationale or inconsistent approvals can create both compliance exposure and operational instability. Strong exception governance is one of the most effective ways to reduce avoidable risk while supporting responsible growth. Servicing Cannot Be an Afterthought Many institutions place their strongest controls in origination, but issues often surface during post-close servicing. Missing documentation, incomplete follow-up or weak monitoring can turn a well-underwritten SBA loan into a higher-risk asset over time. Compliance can support servicing teams by confirming they have the procedures and tools needed to maintain file integrity, track key borrower requirements and escalate issues that could affect performance or documentation quality. Strong servicing controls reinforce the bank’s ability to support its decisions long after closing. Build Exam Readiness Into the Process A strong SBA program should not require a scramble at the start of an examination. Exam readiness is built through repeatable file standards, clear governance and routine self-review. Compliance can support this effort by implementing a risk-based review cadence that includes periodic file sampling or targeted quality-control testing. The objective is to identify and correct issues early, before they become systemic. This approach also helps the business view compliance as a partner in long-term success rather than a final checkpoint. Final Thoughts SBA lending remains a key growth strategy for many banks. The strongest SBA programs are not the most complex; they are built on clear expectations, strong file integrity, disciplined execution and proactive readiness. For compliance officers, focusing on fraud resilience, documentation quality, third-party oversight, structured change management, exception discipline and servicing consistency protects the institution while enabling SBA lending to scale responsibly. 21 NEBRASKA BANKER

In banking, risk management ultimately succeeds or fails based on culture. Policies, controls and monitoring frameworks are necessary — but without reinforcement through daily decisions, they do not determine outcomes. Culture determines how decisions are made, how accountability is exercised, and whether employees feel both empowered and expected to raise concerns. When culture is clear and intentional, risk management becomes part of how work is performed as a day-to-day practice rather than a separate compliance exercise. Regulators increasingly evaluate not just whether controls exist, but whether they are consistently applied in practice. A strategic risk culture aligns core values, governance and execution. It helps employees understand not only what is required, but why it matters to customers, the institution’s safety and soundness, regulatory compliance, institutional reputation and long-term performance. For risk and compliance leaders, the focus is on translating expectations into consistent behavior — through role clarity, governance, accountability and training that builds judgment throughout the employee lifecycle. Foundation: Culture as the Bedrock of Risk Management Culture represents the shared values, expectations and behaviors that guide how work is performed across an organization. In banking, it serves as the foundation for trust, service and sound decision-making, and it directly shapes how growth is balanced with risk. Culture also influences how employees interact with customers, how issues are escalated and how growth objectives are balanced against risk considerations. A strong risk culture begins with clearly articulated core values that translate strategy into behavior. Rather than treating core values as theoretical ideals, effective institutions define them as operational expectations that guide decisions at every level of the organization. When core values are consistently reinforced, they provide a stable framework for managing risk in both routine and high-pressure situations. Core Values Supporting Risk Management To be effective, core values must be clear, concise and reinforced throughout the organization. They are more than From Playbook to Practice: Embedding Risk Culture Tracy R. Pastella, CERP, CRCM, CFE, AAP, CFSA American Bankers Association 22 NEBRASKA BANKER

branding; core values are risk-aligned operational behaviors that shape how teams manage risk in day-to-day operations by identifying risk, escalating issues and balancing growth with sound judgment. Well-defined values also clarify the behaviors that enable employees to succeed and help leaders assess whether “how we work” is aligned with the institution’s risk appetite. In practice, these expectations are reflected in consistent behaviors across the organization: • Collaboration: Effective risk cultures reinforce cross-functional communication that supports early issue identification, timely escalation and coordinated resolution across business lines. • Decision-Making: Accountability is demonstrated when authority and responsibility are aligned at the point of decision, and employees take ownership of outcomes, follow issues through to resolution and consider risk implications. • Professional Standards: Customers and regulators expect confidentiality, integrity and competence, which reinforces trust in both employees and the institution. • Customer Service: Customer feedback mechanisms, including surveys and complaint trends, provide insight into operational weaknesses and control gaps, helping institutions remain responsive while operating within their policy, controls and risk appetite. • Capability Building: Sustained performance requires ongoing learning such as role-based training, coaching and continuing education that keeps pace with changing products, risks and regulations. When these core values are consistently reinforced, employees treat risk management as part of professional responsibility — not as a periodic compliance exercise. Just as important, employees who feel respected and supported are more likely to ask questions, raise concerns and escalate early, improving outcomes for customers and the institution. Shared Responsibility: Risk and Compliance in Every Role Risk management is not the responsibility of a single department. It is a shared responsibility that spans every role across the organization. Every decision — no matter how routine — has the potential to affect the institution’s risk profile or impact the bottom line. Examiners routinely assess whether this shared responsibility is clearly defined, understood and consistently applied across the organization. Effective risk ownership begins with clarity. Job descriptions, performance expectations and reporting structures should explicitly define how risk and compliance responsibilities align with day-to-day activities. When employees understand how their role ties into institutional protection, regulatory compliance and reputation, accountability becomes practical, not theoretical. Risk awareness informs judgment, encourages timely escalation and promotes consistent and transparent decision-making across the organization. The Three Lines of Defense: A Foundational Framework When effectively implemented, the three lines of defense model provides a concise and widely accepted governance and risk management framework that defines how risk is managed across the organization while maintaining clear accountability across functions. First Line of Defense: Business Lines and Operations Business lines own and manage risk as part of executing their responsibilities. This includes the following policies and procedures, identifying and assessing risks, operating controls and escalating issues. A strong first line advances business objectives while operating within the institution’s risk appetite and control environment. Second Line of Defense: Risk Management and Compliance Independent risk management and compliance functions provide oversight, guidance, tools and credible challenges. They interpret regulatory expectations, monitor risk trends and help the first line identify emerging issues before they become events — supporting a proactive, well-controlled operating model. Third Line of Defense: Internal Audits Internal audit provides independent, objective assurance that governance, risk management and controls are designed appropriately and operating effectively. Audit’s perspective helps the organization validate what is working, identify gaps and reinforce accountability. When clearly communicated, the three lines of defense reinforce that risk management is coordinated, independent and comprehensive — without duplicating effort or diluting accountability. Accountability: Turning Culture Into Action Culture works when it is reinforced by accountability. Accountability is what connects score values to execution and ensures expectations are applied consistently and fairly across the organization. In practice, accountability is what allows institutions to demonstrate to regulators that risk management is functioning as intended. That starts with clearly defined roles that articulate responsibilities, performance standards and escalation expectations. These definitions should tie directly to performance evaluations, incentive structures and succession planning. Partnering with supervisors, executive leadership and human resources to document role-based risk responsibilities helps shift the organization from “defense” to operational discipline. 23 NEBRASKA BANKER

| Bank Stock Loans | Loan Participations | ATM/Debit | International Services | | Cash Management | Securities Safekeeping | Merchant Services | 800-873-4722 | NE: 888-467-5544 | www.bbwest.com Where community banks bank Est. 1980 – Over 45 years of service to community banks “As a service provider exclusively focused on community banks, Bankers’ Bank of the West is here to help strengthen our clients and the communities they serve.” Across the western states and Great Plains, we’re the place where community banks bank. That’s because we provide the services, technology, and expertise to help you extend your resources, deliver for your customers, and stand out in your market. 5 reasons to partner with us BBW CEO and Vice Chair – Bill Mitchell 1. You can unlock efficiencies and cost savings. We can provide sophisticated solutions and economies of scale because we’re powered by hundreds of community banks across our region. 5. Our priorities are aligned with yours. 2. You can expand your capabilities. 4. We’ll never compete for your customers. 3. You can count on prompt, reliable service. • Independent loan review • Loan and credit administration consultation • Strategic planning facilitation • Management, staffing, & succession planning • Acquisition & expansion • BSA/AML compliance • Regulatory risk consultation President, Jim Swanson President, Anne Benigsen • Consulting • Phishing Tests • Vulnerability Management • Security Monitoring Cyber/information security, strategic planning, independent loan review, AND MORE. Consulting Services $ 8.45B assets under management $ 1.9B daily transaction value processed/settled Serving more than 60% of community banks across 7 states

RkJQdWJsaXNoZXIy MTg3NDExNQ==