stba-20251231
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
Form 10-K
For the fiscal year ended December 31, 2025
or
For the transition period from to
Commission file number0-12508
S&T BANCORP, INC.
(Exact name of registrant as specified in its charter)
(Address of principal executive offices) (zip code)
Registrant’s telephone number, including area code (800) 325-2265
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol Name of each exchange on which registered
Common Stock, par value $2.50 per share STBA NASDAQ Global Select Market
Securities registered pursuant to Section 12(g) of the Act: None
(Title of class)
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act.
Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act.
Yes ☐No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days.
Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files).
Yes☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large accelerated filer ☒ Accelerated filer ☐
Non-accelerated filer ☐ Smaller reporting company ☐
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of
the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C.
7262(b)) by the registered public accounting firm that prepared or issued its audit report. Yes ☒ No ☐
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to § 240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
State the aggregate market value of the voting and non-voting common equity held by non-affiliates computed by reference to the price at which the common equity was last sold, or the average bid and asked price of such common equity, as of the last business day of the registrant's most recently completed second fiscal quarter. The aggregate estimated fair value of the voting and non-voting common equity held by non-affiliates of the registrant as of June 30, 2025:
Common Stock, $2.50 par value – $1,434,409,389
The number of shares outstanding of each of the registrant's classes of common stock as of February 25, 2026:
Common Stock, $2.50 par value – 36,548,632
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the definitive Proxy Statement of S&T Bancorp, Inc., to be filed pursuant to Regulation 14A for the 2025 annual meeting of shareholders are incorporated by reference into Part III of this Annual Report on Form 10-K.
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Page No.
Part I
Item 1. Business 2
Item 1A. Risk Factors 16
Item 1B. Unresolved Staff Comments 28
Item 1C. Cybersecurity 28
Item 2. Properties 29
Item 3. Legal Proceedings 30
Item 4. Mine Safety Disclosures 30
Part II.
Item 6. Reserved 32
Item 7A. Quantitative and Qualitative Disclosures About Market Risk 52
Item 8. Financial Statements and Supplementary Data 54
Item 9A. Controls and Procedures 107
Item 9B. Other Information 107
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 107
Part III
Item 10. Directors, Executive Officers and Corporate Governance 108
Item 11. Executive Compensation 108
Item 14. Principal Accounting Fees and Services 108
Part IV
Item 15. Exhibits, Financial Statement Schedules 109
1
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
PART I
Item 1. BUSINESS
General
S&T Bancorp, Inc. was incorporated on March 17, 1983 under the laws of the Commonwealth of Pennsylvania as a bank holding company and is registered with the Board of Governors of the Federal Reserve System, or the Federal Reserve Board, under the Bank Holding Company Act of 1956, as amended, or the BHCA, as a bank holding company and a financial holding company. S&T Bancorp, Inc. has four active direct wholly-owned subsidiaries including S&T Bank, 9th Street Holdings, Inc., STBA Capital Trust I and DNB Capital Trust II, and owns a 50 percent interest in Commonwealth Trust Credit Life Insurance Company, or CTCLIC. When used in this Report, “S&T,” “we,” “us” or “our” may refer to S&T Bancorp, Inc. individually, S&T Bancorp, Inc. and its consolidated subsidiaries or certain of S&T Bancorp, Inc.’s subsidiaries or affiliates, depending on the context. As of December 31, 2025, we had approximately $9.9 billion in assets, $8.1 billion in total loans, $8.0 billion in deposits and $1.5 billion in shareholders’ equity.
S&T Bank is a full-service Pennsylvania chartered bank that is headquartered in Indiana, Pennsylvania. S&T Bank operates in Pennsylvania and Ohio through it's 72 branches. S&T Bank's primary regulators are the Federal Deposit Insurance Corporation, or FDIC, and the Pennsylvania Department of Banking and Securities, or PA DOBS. S&T Bank deposits are insured by the FDIC to the maximum extent provided by law. S&T Bank has three active wholly-owned operating subsidiaries including S&T Insurance Group, LLC, S&T Bancholdings, Inc. and DN Acquisition Company, Inc.
Through S&T Bank and our non-bank subsidiaries, we offer consumer, commercial and small business banking services, which include accepting time and demand deposits and originating commercial and consumer loans, brokerage services and trust services including serving as executor and trustee under wills and deeds and as guardian of employee benefits. We also manage private investment accounts for individuals and institutions through a registered financial services entity. Total Wealth Management assets under administration, which are not accounted for as part of our assets, were $2.1 billion at December 31, 2025.
The main office of both S&T Bancorp, Inc. and S&T Bank is located at 800 Philadelphia Street, Indiana, Pennsylvania, and our phone number is (800) 325-2265.
Human Capital Management
Our commitment to our customers starts with a talented team. To attract and retain our talented team, we strive to make S&T an inclusive workplace that provides our employees with opportunities to develop and grow. The S&T mindset is to encourage, develop and inspire all employees to achieve their best, motivated by their own personal progress and development. Our commitment is to foster a workplace where everyone utilizes their knowledge, skills, abilities and unique interests to help each other find success and drive positive results. S&T fosters a work culture where employees work together to better our company, products and services and community. We are committed to promoting a workplace that develops all people through ensuring fairness in all aspects of employment, educating our employees and fostering a culture to address employees’ and customers’ needs. As of December 31, 2025, we had approximately 1,209 full-time-equivalent employees.
Our Team and Culture
Our purpose is building a better future together through people-forward banking. We believe that all banking should be personal. We cultivate relationships rooted in trust, strengthened by going above and beyond and renewed with every interaction. We move banking forward, building better lives together by always putting people first.
Our team strives to embody values to encourage a culture that has enabled us to be named a top workplace. The following five core values support our purpose:
Make People our Purpose
Humility, empathy and a sincere desire to uplift each other and our community guide our actions every day. We are people in service of people, committed to constantly improving our communication and connection and delivering the right solutions.
Do the Right Thing
We are built on trust and following through on our promises. We hold ourselves accountable by delivering results, continuously learning and striving for better every day.
2
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Go Above and Beyond
We go as far as we possibly can to help advance the cause of our colleagues, customers and communities. In every case, we seek the right solutions based on a holistic understanding of the opportunities ahead of us.
Value Every Voice
We stand for inclusivity, accessibility and opportunity. We listen for forward-looking ideas to better ourselves and improve our experience. And we always welcome an honest and open dialogue with our colleagues, customers and the community at large.
Win as One Team
We function as one connected team working together to deliver a seamless experience. We communicate, collaborate and care enough to go the extra mile for the colleagues we work alongside, the customers we serve and the communities where we live.
Talent Development and Training
S&T strives to provide our employees with access to comprehensive training to enhance all job positions. Our corporate training department maintains oversight of training to ensure it is implemented and monitored properly and encourages career development for our employees. Our training programs offer a blended learning approach comprised of classroom, asynchronous online learning and synchronous online sessions. Our learning management systems, supported by vendor partnerships provide employees regulatory, compliance, skill-based, technology, leadership and career development trainings.
We encourage all employees to develop their skill sets and careers through a variety of internal and external training opportunities to align our organization for long-term success. We are dedicated to investing in and developing our managers, supervisors and future leaders of S&T. Our multi-tier succession plan includes replacement planning of vacancies, ongoing talent development and career path design of current employees. Additional resources that support these initiatives include S&T's annual training and recruitment plans that identify specific actionable programs and efforts. In 2025, our employees logged approximately 71,798 training hours, on average 59 hours per employee.
Safety, Health and Wellness
The safety, health and well-being of our employees is a top priority. We offer our employees and their families access to a variety of flexible and convenient health and welfare programs that provide resources to help them maintain and/or improve their physical and mental health. We also have a financial wellness program that assists our employees and their families with budgeting and various personal financial content consisting of an online personal financial program and internally produced webinars. We believe in the education and offering of programs and initiatives that make lasting positive impacts in the lives of our employees.
Access to United States Securities and Exchange Commission Filings
All of our reports filed electronically with the United States Securities and Exchange Commission, or the SEC, including this Annual Report on Form 10-K for the fiscal year ended December 31, 2025, our prior annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and our annual proxy statements, as well as any amendments to those reports, are accessible at no cost on our website at www.stbancorp.com under Financials, SEC Filings. These filings are also accessible on the SEC’s website at www.sec.gov. The charters of the Audit Committee, the Compensation and Benefits Committee, the Credit Risk Committee, the Executive Committee, the Nominating and Corporate Governance Committee and the Risk Committee as well as the Complaints Regarding Accounting, Internal Accounting Controls or Auditing Matters ("Whistleblower Policy"), the Code of Conduct for the Chief Executive Officer, or CEO, and Chief Financial Officer, or CFO, the General Code of Conduct, the Shareholder Communications Policy and the Corporate Governance Guidelines are also available at www.stbancorp.com under Governance.
3
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Supervision and Regulation
General
S&T and its bank and non-bank subsidiaries are extensively regulated under federal and state law. Regulation of bank holding companies and banks is intended primarily for the protection of consumers, depositors, borrowers, the Federal Deposit Insurance Fund, or DIF, and the banking system as a whole, and not for the protection of shareholders or creditors. The following describes certain aspects of that regulation and does not purport to be a complete description of all regulations that affect S&T, or all aspects of any regulation discussed here. To the extent statutory or regulatory provisions are described, the description is qualified in its entirety by reference to the particular statutory or regulatory provisions. The discussion of the regulations applicable to S&T provided below is based on our status as an institution with less than $10 billion in assets. If S&T’s assets cross the $10 billion threshold, we will be subject to different and additional regulations than those described below.
In addition, proposals to change the laws and regulations governing the banking industry are frequently raised in Congress, in state legislatures and before the various bank regulatory agencies that may impact S&T. Bank regulatory agencies may issue policy statements, interpretive letters and similar written guidance applicable to S&T or S&T Bank. Such initiatives to change the laws and regulations may include proposals to expand or contract the powers of bank holding companies and depository institutions or proposals to substantially change the financial institution regulatory system. Any such legislation could change bank statutes and our operating environment in substantial and unpredictable ways. If enacted, such legislation could affect how S&T and S&T Bank operate and could significantly increase costs, impede the efficiency of internal business processes, limit our ability to pursue business opportunities in an efficient manner or affect the competitive balance among banks, credit unions and other financial institutions, any of which could materially and adversely affect our business, financial condition and results of operations. The likelihood and timing of any changes and the impact such changes might have on S&T is impossible to determine with any certainty.
Regulation of S&T
We are a bank holding company subject to regulation under the BHCA and the examination and reporting requirements of the Federal Reserve and have elected to be a financial holding company. Under the BHCA, a financial holding company is restricted in the types of activities in which it may engage and subject to a range of supervisory requirements and activities, including regulatory enforcement actions for violations of laws and regulations.
In general, the BHCA limits the business of bank holding companies to banking, managing, or controlling banks and other activities that the Federal Reserve has determined to be closely related to banking. Bank holding companies that qualify and elect to become financial holding companies, such as S&T, may engage in any activity, or acquire and retain the shares of a company engaged in any activity, that is either financial in nature or incidental to such financial activity (as determined by the Federal Reserve in consultation with the Secretary of the Treasury), or complementary to a financial activity, and that does not pose a substantial risk to the safety and soundness of depository institutions or the financial system (as solely determined by the Federal Reserve). The BHCA identifies several activities as “financial in nature” including, among others, securities underwriting; dealing and market making; sponsoring mutual funds and investment companies; insurance underwriting and sales agency; investment advisory activities; merchant banking activities and activities that the Federal Reserve has determined to be closely related to banking. Banks may also engage in, subject to limitations on investment, activities that are financial in nature, other than insurance underwriting, insurance company portfolio investment, real estate development and real estate investment, through a financial subsidiary of the bank, if the bank is “well-capitalized,” “well-managed” and has at least a “satisfactory” Community Reinvestment Act, or CRA, rating.
4
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
In order to maintain our status as a financial holding company, we must remain “well-capitalized” and “well-managed” and the depository institutions controlled by us must remain “well-capitalized,” “well-managed” (as defined in federal law) and have at least a “satisfactory” CRA rating. Refer to Note 23. Regulatory Matters to the consolidated financial statements contained in Part II, Item 8 of this Report for information concerning the current capital ratios of S&T and S&T Bank. If S&T or S&T Bank fail to continue to meet these requirements, we could be subject to restrictions on new activities and acquisitions, and/or be required to cease and possibly divest operations that conduct existing activities that are not permissible for a bank holding company that is not a financial holding company. Additionally, the Federal Reserve could impose corrective capital and managerial requirements and activity restrictions on us if we cease to be “well-capitalized” or “well managed.”
As a financial holding company, we are expected under statutory and regulatory provisions to serve as a source of financial and managerial strength to our subsidiary bank. A financial holding company is also expected to commit resources, including capital and other funds, to support its subsidiary bank. The Federal Reserve may require a bank holding company to make capital injections into a troubled subsidiary bank and may charge the bank holding company with engaging in unsafe and unsound practices if it fails to commit resources to such a subsidiary bank, or if it undertakes actions that the Federal Reserve believes might jeopardize the bank holding company’s ability to commit resources to such subsidiary bank. Capital loans by banking holding companies to its subsidiary banks would be subordinate in right of payment to deposits and certain other debts of the subsidiary bank. In the event of bankruptcy, any commitment by a bank holding company to a federal bank regulatory agency to maintain the capital of a subsidiary bank would be assumed by the bankruptcy trustee and entitled to a priority of payment.
The BHCA requires that a financial holding company obtain the prior approval of the Federal Reserve before (i) acquiring direct or indirect ownership or control of more than 5 percent of the voting shares of any additional bank or bank holding company, (ii) taking any action that causes an additional bank or bank holding company to become a subsidiary of the financial holding company, or (iii) merging or consolidating with any other bank holding company. No prior regulatory approval is required for a financial holding company to acquire a company, other than a bank or savings association, engaged in activities that are financial in nature or incidental to activities that are financial in nature, as determined by the Federal Reserve, unless the total consolidated assets to be acquired exceed $10 billion. Federal law restricts the amount of voting stock of a bank holding company and a bank that a person may acquire without the prior approval of banking regulators. Federal law also imposes restrictions on acquisitions of stock in a bank holding company. Under the federal Change in Bank Control Act and the regulations thereunder, a person or group must give advance notice to the Federal Reserve before acquiring control of any bank holding company, such as S&T, and the FDIC before acquiring control of any state-chartered non-member bank, such as S&T Bank. Upon receipt of such notice, the bank regulatory agencies may approve or disapprove the acquisition. The Change in Bank Control Act creates a rebuttable presumption of control if a member or group acquires a certain percentage or more of a bank holding company’s or bank’s voting stock, or if one or more other control factors set forth in the Act are present. As a result, a person or entity generally must provide prior notice to the Federal Reserve before acquiring the power to vote 10 percent or more of S&T’s outstanding common stock.
S&T Bank
As a Pennsylvania-chartered, FDIC-insured non-member commercial bank, S&T Bank is subject to the supervision and regulation of the PA DOBS and the FDIC. We are also subject to various requirements and restrictions under federal and state law, including requirements to maintain reserves against deposits, restrictions on the types, amount and terms and conditions of loans that may be granted and limits on the types of other activities in which S&T Bank may engage and the investments it may make.
S&T Bank is subject to affiliate transaction rules in Sections 23A and 23B of the Federal Reserve Act as implemented by the Federal Reserve's Regulation W, that limit the amount of transactions between itself and S&T or any other company or entity that controls or is under common control with any company or entity that controls S&T Bank, including for most purposes any financial or depository institution subsidiary of S&T Bank. Under these provisions, “covered” transactions, including making loans, purchasing assets, issuing guarantees and other similar transactions, between a bank and its parent company or any other affiliate, generally are limited to 10 percent of the bank subsidiary’s capital and surplus, and with respect to all transactions with affiliates, are limited to 20 percent of the bank subsidiary’s capital and surplus. Loans and extensions of credit from a bank to an affiliate generally are required to be secured by eligible collateral in specified amounts, and in general all affiliated transactions must be on terms consistent with safe and sound banking practices. Furthermore, in general, transactions between a bank and its affiliates must be on terms and conditions that are at least as favorable to the bank as the terms that would apply in comparable transactions between the bank and a third party. Dodd-Frank Wall Street Reform and Consumer Protection Act, or Dodd-Frank Act, expanded the affiliate transaction rules to broaden the definition of "covered transactions" to include securities, borrowing or lending, repurchase and reverse repurchase agreements and certain derivative transactions. The Act also strengthened collateral requirements and significantly limited the Federal Reserve's authority to grant exemptions from these rules.
5
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Federal law also constrains the types and amounts of loans that S&T Bank may make to its executive officers, directors and principal shareholders. Among other things, these loans are limited in amount, must be approved by S&T Bank’s board of directors in advance and must be on terms and conditions as favorable to the bank as those available to an unrelated person. The Dodd-Frank Act strengthened restrictions on loans to insiders and expanded the types of transactions subject to the various limits to include credit exposure arising from a derivative transaction, a repurchase or reverse repurchase agreement and a securities lending or borrowing transaction. The Dodd-Frank Act also placed restrictions on certain asset sales to and from an insider to an institution, including requirements that such sales be on market terms and, in certain circumstances, approved by the institution’s board of directors.
Pursuant to Section 18(c) of the FDIA, more commonly known as the Bank Merger Act, or BMA, prior written approval from a bank’s primary federal regulator is required before any insured depository institution may consummate a merger transaction which includes a merger, consolidation, assumption of deposit liabilities and certain asset transfers between or among two or more institutions. Prior written approval of a bank’s primary federal regulator is also required for merger transactions between or among affiliated institutions, as well as for merger transactions between or among non-affiliated institutions. Transactions that do not involve a transfer of deposit liabilities typically do not require prior approval under the BMA, unless the transaction involves the acquisition of all or substantially all of an institution’s assets. In September 2024, the FDIC adopted a final rule amending its procedures for reviewing applications under the BMA and adding a policy statement on the FDIC’s substantive approach to evaluating bank mergers under the BMA, which, among other things, eliminated certain expedited review procedures and streamlined application processes. However, on May 20, 2025, the FDIC approved the rescission of its 2024 policy statement and reinstated its 2008 policy statement while it conducts a broader reevaluation of its bank merger review process. These actions reflect regulatory efforts to reduce procedural uncertainty and burden in the bank merger review process. The statutory framework underlying the BMA has not been materially changed by recent legislation, and agencies continue to exercise broad discretion in merger evaluation on a case-by-case basis. Proposed changes to bank merger policy, including oversight and application procedures, may arise from regulatory proposals or Congressional interest and could affect the timing, complexity or conditions of merger approvals.
In September 2024, the Department of Justice, or DOJ, withdrew its 1995 Bank Merger Guidelines and issued the 2024 Banking Addendum to 2023 Merger Guidelines, or the 2024 Banking Addendum. The DOJ clarified that it would assess competition considerations in connection with bank and bank holding company mergers using its 2023 Merger Guidelines which is the general merger review framework the DOJ now uses to evaluate transactions in all segments of the economy, and 2024 Banking Addendum. The 2024 Banking Addendum provides guidance on how the DOJ will assess competition in the context of bank and bank holding company mergers. An analysis under the 2023 Merger Guidelines and 2024 Banking Addendum may include consideration of theories of harm and relevant markets not considered under the 1995 Bank Merger Guidelines which focused primarily on concentrations of deposits and branches. Notwithstanding the actions of the FDIC in 2025, transactions that satisfy traditional banking regulator approval standards may nonetheless face extended DOJ review, additional information requests, conditions or challenges.
Supervision, Examination and Enforcement
The Federal Reserve and FDIC have broad supervisory, examination and enforcement authority with regard to bank holding companies and banks, including the power to impose nonpublic supervisory agreements, issue cease and desist or removal orders, impose fines and other civil and criminal penalties, initiate injunctive actions, terminate deposit insurance and appoint a conservator or receiver. In general, these actions may be initiated for violations of laws and regulations, as well as engagement in unsafe and unsound practices, and some of these actions also may be taken against an “institution affiliated party” as defined in the law. Specifically, the regulators may direct a bank holding company or bank to, among other things, increase its capital, sell subsidiaries or other assets, limit its dividends and distributions, restrict its growth or remove officers and directors. Supervision and examinations are confidential, and the outcomes of these actions may not be made public. In addition, if our total consolidated assets exceed $10 billion, we may be subject to additional supervision by the Consumer Financial Protection Bureau, or CFPB, with respect to consumer protection laws and regulations.
On August 7, 2025, Executive Order 14331,“Guaranteeing Fair Banking Access for All Americans,” was issued directing federal banking agencies to identify and address “politicized or unlawful” denial of financial services based on constitutionally or statutorily protected beliefs, affiliations, or political views. In response, the Small Business Administration, or SBA, required certain certifications from SBA lending program participants, and the FDIC conducted supervisory reviews of policies and practices at certain FDIC-supervised institutions.
6
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
In October 2025, the federal bank regulators issued a proposed rule to limit reputation risk as a factor in their supervisory frameworks. Under the proposed rule, the agencies would be prohibited from criticizing or taking adverse action against a financial institution based on reputation risk. Certain states have also enacted or proposed “fair access” laws that may affect how financial institutions approach account opening, account termination and related relationship decisions. These developments may result in evolving supervisory expectations, examination practices or compliance requirements applicable to S&T and its affiliates and could increase operational, compliance or legal complexity, including where requirements overlap with or potentially conflict with other legal or risk-management obligations.
Insurance of Accounts; Depositor Preference
The deposits of S&T Bank are insured up to applicable limits per insured depositor by the DIF, as administered by the FDIC. The Dodd-Frank Act codified FDIC deposit insurance coverage per separately insured depositor for all account types at $250,000.
The DIF is funded mainly through quarterly assessments on insured depository institutions, such as S&T Bank, and provides insurance coverage for certain deposits up to this maximum amount. As an FDIC-insured bank, S&T Bank is subject to FDIC insurance assessments which are imposed based upon the calculated risk the institution poses to the DIF. S&T Bank’s assessment is determined each quarter in accordance with the FDIC’s standardized risk-based methodology by multiplying its assessment rate by its assessment base. The assessment base is calculated as a percentage of average consolidated total assets less average tangible equity during the assessment period. Under the current assessment system, for an institution with less than $10 billion in assets, assessment rates are determined based on a combination of financial ratios and CAMELS (capital adequacy, asset quality, management, earnings, liquidity and sensitivity) composite ratings. The assessment rate schedule can change from time to time, at the discretion of the FDIC, subject to certain limits. Under the current system, premiums are assessed quarterly.
As part of its semiannual update of the restoration plan established by the FDIC to facilitate restoration of the reserve ratio of the DIF to the statutory minimum in the mandated time frame, the FDIC adopted a final rule in October 2022. The new rule, applicable to all insured depository institutions, increased the initial base deposit insurance assessment rate schedules uniformly by 2 basis points, beginning in the first quarterly assessment period of 2023 (January 1 through March 31, 2023). The increase in assessment rate schedules was intended to increase the likelihood that the reserve ratio of the DIF reaches the statutory minimum of 1.35 percent by the statutory deadline of September 30, 2028. The change in assessment rates was further intended to support the growth of the DIF in progressing toward the 2 percent Designated Reserve Ratio, or DRR, established by the FDIC. The FDIC has indicated that the new assessment rate schedules will remain in effect unless and until the DRR meets or exceeds 2 percent, absent further FDIC action. Under the new rule, the total base assessment rates on an annualized basis range from 2.5 basis points for certain “well-capitalized,” “well-managed” banks, with the highest ratings, to 42 basis points for complex institutions posing the most risk to the DIF compared to the 2022 rates that ranged from 1.5 to 40.
In addition to regular assessments, the FDIC has authority to impose special assessments on insured depository institutions, including to recover losses to the DIF associated with bank failures. In November 2023, the FDIC finalized a special assessment to recover DIF losses related to the closures of Silicon Valley Bank and Signature Bank. The assessment applies only to institutions with more than $5 billion in uninsured deposits as of December 31, 2022. Because S&T Bank’s uninsured deposits were below this threshold, the assessment does not apply to S&T.
The FDIC may terminate the deposit insurance of any insured depository institution if it determines, after hearing that the institution has engaged in unsafe or unsound practices, that the institution is in an unsafe or unsound condition to continue operations or has violated any applicable law, regulation, rule, order or condition imposed by the FDIC or the Federal Reserve. It also may suspend deposit insurance temporarily during the hearing process if the institution has no tangible capital. If insurance of accounts is terminated, the accounts at the institution at the time of termination, less subsequent withdrawals, will continue to be insured for a period of six months to two years, as determined by the FDIC.
Under federal law, deposits and certain claims for administrative expenses and employee compensation against insured depository institutions are afforded a priority over other general unsecured claims against such an institution, including federal funds and letters of credit, in the liquidation or other resolution of such an institution by a receiver. Such priority creditors would include the FDIC.
7
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Capital
S&T and S&T Bank are required under federal law to maintain certain minimum capital levels based on ratios of capital to total assets and capital to risk-weighted assets. The Federal Reserve and the FDIC have issued substantially similar minimum risk-based and leverage capital rules applicable to the banking organizations they supervise. These capital ratios represent regulatory minimums, and the Federal Reserve and FDIC may determine that a banking organization, based on its size, complexity, risk profile, growth plans or overall condition, must maintain capital levels in excess of the minimum requirements in order to operate in a safe and sound manner. In assessing capital adequacy, banking regulators consider a variety of qualitative and quantitative factors, including concentrations of credit risk, exposure to interest rate risk, liquidity risk, operational and market risks, risks arising from non-traditional activities and management’s ability to identify, measure, monitor and control those risks.
Under the applicable capital rules, S&T and S&T Bank are subject to the following risk-based capital ratios: a common equity tier 1, or CET1, risk-based capital ratio, a Tier 1 risk-based capital ratio, which includes CET1 and additional Tier 1 capital and a total capital ratio which includes Tier 1 and Tier 2 capital. CET1 is primarily comprised of the sum of common stock instruments and related surplus net of treasury stock, retained earnings and certain qualifying minority interests, less certain adjustments and deductions, including with respect to goodwill, intangible assets, mortgage servicing assets and deferred tax assets subject to temporary timing differences. Additional Tier 1 capital is primarily comprised of noncumulative perpetual preferred stock, tier 1 minority interests and grandfathered trust preferred securities, if applicable. Tier 2 capital consists of instruments disqualified from Tier 1 capital, including qualifying subordinated debt, certain trust preferred securities, other preferred stock and certain hybrid capital instruments and a limited amount of loan loss reserves up to a maximum of 1.25 percent of risk-weighted assets, subject to certain eligibility criteria.
The capital rules require a minimum CET1 risk-based capital ratio of 4.5 percent, a minimum overall Tier 1 risk based capital ratio of 6.0 percent, and a total risk-based capital ratio of 8.0 percent. In addition, the capital rules require a capital conservation buffer of 2.5 percent above each of the minimum capital ratio requirements (CET1, Tier 1, and total risk-based capital), which must be met for a bank or bank holding company to be able to pay dividends, engage in share buybacks or make discretionary bonus payments to executive management without automatic restrictions. The capital conservation buffer is 2.50 percent, so a banking organization needs to maintain a CET1 capital ratio of at least 7 percent, a total Tier 1 capital ratio of at least 8.5 percent and a total risk-based capital ratio of at least 10.5 percent or it would be subject to restrictions on capital distributions and discretionary bonus payments to its executive management.
The leverage capital ratio, which serves as a minimum capital standard, is the ratio of Tier 1 capital to quarterly average total assets, less goodwill and other disallowed intangible assets. The required minimum leverage ratio for all banks and bank holding companies is 4 percent.
To be well-capitalized, we must maintain the following capital ratios:
● CET1 risk-based capital ratio of 6.5 percent or greater;
● Tier 1 risk-based capital ratio of 8.0 percent or greater;
● Total risk-based capital ratio of 10.0 percent or greater; and
● Tier 1 leverage ratio of 5.0 percent or greater.
Failure to be well-capitalized or to meet minimum capital requirements could result in certain mandatory and possible additional discretionary actions by regulators that, if undertaken, could have an adverse material effect on our operations or financial condition. For example, only a well-capitalized depository institution may accept brokered deposits without prior regulatory approval. Failure to be well-capitalized or to meet minimum capital requirements could also result in restrictions on S&T’s or S&T Bank’s ability to pay dividends or otherwise distribute capital or to receive regulatory approval of applications or other restrictions on its growth.
On December 31, 2025, S&T’s and S&T Bank’s regulatory capital ratios were above the well-capitalized standards and met the fully phased-in capital conservation buffer.
8
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
The following table summarizes the leverage and risk-based capital ratios for S&T and S&T Bank:
(dollars in thousands) Amount Ratio Amount Ratio Amount Ratio
Leverage Ratio
Common Equity Tier 1 (to Risk-Weighted Assets)
Tier 1 Capital (to Risk-Weighted Assets)
Total Capital (to Risk-Weighted Assets)
Payment of Dividends
S&T is a legal entity separate and distinct from its banking and other subsidiaries. A substantial portion of our revenues consist of dividend payments we receive from S&T Bank. The payment of common dividends by S&T is subject to certain requirements and limitations of Pennsylvania law. S&T Bank, in turn, is subject to federal and state laws and regulations that limit the amount of dividends it can pay to S&T. In addition, both S&T and S&T Bank are subject to various general regulatory policies relating to the payment of dividends, including requirements to maintain adequate capital above regulatory minimums. The Federal Reserve has indicated that banking organizations should generally pay dividends only if (i) the organization’s net income available to common shareholders over the past year has been sufficient to fully fund the dividends, (ii) the prospective rate of earnings retention appears consistent with the organization’s capital needs, asset quality and overall financial condition and (iii) the organization will continue to meet minimum capital adequacy ratios. The policy also provides that a banking organization should inform the Federal Reserve reasonably in advance of declaring or paying a dividend that exceeds earnings for the period for which the dividend is being paid or that could result in a material adverse change to the bank holding company’s capital structure. Bank holding companies also are required to consult with the Federal Reserve before redeeming or repurchasing capital instruments when the bank holding company is experiencing financial weaknesses. Additionally, the Federal Reserve could prohibit or limit the payment of dividends by a bank holding company if it determines that payment of the dividend would constitute an unsafe or unsound practice.
Thus, under certain circumstances based upon our financial condition, our ability to declare and pay quarterly dividends may require consultation with the Federal Reserve and may be prohibited by applicable Federal Reserve guidance.
9
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Safety and Soundness Regulations
There are a number of obligations and restrictions imposed on bank holding companies such as us and our depository institution subsidiary by federal law and regulatory policy. These obligations and restrictions relate to internal controls, risk management, information systems, internal audit systems, loan documentation, credit underwriting, interest rate exposure, asset growth and compensation, fees and benefits. These guidelines in general require appropriate systems and practices to identify and manage specified risks and exposures. These obligations and restrictions are designed to reduce potential loss exposure to the FDIC’s DIF in the event an insured depository institution becomes in danger of default or is in default. Under current federal law, for example, the federal banking agencies possess broad powers to take prompt corrective action to resolve problems of insured depository institutions. The extent of these powers depends upon whether the institution in question is “well-capitalized,” “adequately capitalized,” “undercapitalized,” “significantly undercapitalized” or “critically undercapitalized,” as defined by the law. As of December 31, 2025, S&T Bank was classified as “well-capitalized.” Refer to the above section titled Capital within this Item 1. Business section for capital requirements. The classification of depository institutions is primarily for the purpose of applying the federal banking agencies’ prompt corrective action provisions and is not intended to be and should not be interpreted as a representation of overall financial condition or prospects of any financial institution.
Lending Standards and Guidance
The federal banking agencies have adopted uniform regulations prescribing standards for extensions of credit that are secured by liens on, or interests in, real estate or made for the purpose of financing permanent improvements to real estate. Under these regulations, all insured depository institutions, including S&T Bank, are required to adopt and maintain written policies that establish appropriate limits and standards for such extensions of credit. These policies must address, among other things, loan portfolio diversification standards, prudent underwriting standards (including clear and measurable loan-to-value limits), loan administration procedures and documentation, approval and reporting requirements. S&T Bank’s real estate lending policies are required to reflect consideration of the federal banking regulators’ Interagency Guidelines for Real Estate Lending Policies.
The federal banking agencies have also jointly issued supervisory guidance on Concentrations in Commercial Real Estate Lending (the “Guidance”). The Guidance defines commercial real estate loans to include exposures secured by raw land, land development and construction (including one-to-four family residential construction), multifamily property and non-farm nonresidential property where the primary or a significant source of repayment is derived from rental income associated with the property (generally defined as loans for which 50 percent or more of the source of repayment is derived from third-party, non-affiliated rental income) or from the proceeds of the sale, refinancing or permanent financing of the property.
The Guidance provides that insured depository institutions should maintain appropriate processes to identify, monitor and control risks associated with concentrations in commercial real estate lending. Where concentrations are present, management is expected to employ heightened risk management practices which may include enhanced board and management oversight and strategic planning, portfolio management, underwriting standards, risk assessment and monitoring through market analysis and stress testing and the maintenance of capital levels appropriate to support the level of commercial real estate lending. These heightened risk management practices may also include enhanced internal controls, portfolio stress testing, risk exposure limits, compensation and incentive programs and, where appropriate, higher allowances for credit losses.
10
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Prompt Corrective Action
The federal banking agencies’ prompt corrective action powers, which increase depending upon the degree to which an institution is undercapitalized, can include, among other things, requiring an insured depository institution to adopt a capital restoration plan which cannot be approved unless guaranteed by the institution’s parent company; placing limits on asset growth and restrictions on activities, including restrictions on transactions with affiliates; restricting the interest rates the institution may pay on deposits; restricting the institution from accepting brokered deposits; prohibiting the payment of principal or interest on subordinated debt; prohibiting the holding company from making capital distributions, including payment of dividends, without prior regulatory approval; and, ultimately, appointing a receiver for the institution.
The federal banking agencies have also adopted guidelines prescribing safety and soundness standards relating to internal controls and information systems, internal audit systems, loan documentation, credit underwriting, interest rate exposure, asset growth, fees and compensation and benefits. In general, the guidelines require appropriate systems and practices to identify and manage specified risks and exposures. The guidelines prohibit excessive compensation as an unsafe and unsound practice and characterize compensation as excessive when the amounts paid are unreasonable or disproportionate to the services performed by an executive officer, employee, director or principal shareholder. In addition, the agencies have adopted regulations that authorize, but do not require, an agency to order an institution that has been given notice by an agency that it is not in compliance with any of such safety and soundness standards to submit a compliance plan. If, after being so notified, an institution fails to submit an acceptable compliance plan, the agency must issue an order directing action to correct the deficiency and may issue an order directing other actions of the types to which an “undercapitalized” institution is subject under the prompt corrective action provisions described above.
Regulatory Enforcement Authority
The enforcement powers available to federal banking agencies are substantial and include, among other things and in addition to other powers described herein, the ability to assess civil money penalties and impose other civil and criminal penalties, to issue cease-and-desist or removal orders, to appoint a conservator to conserve the assets of an institution for the benefit of its depositors and creditors and to initiate injunctive actions against banks and bank holding companies and “institution affiliated parties,” as defined in the Federal Deposit Insurance Act, or FDIA. In general, these enforcement actions may be initiated for violations of laws and regulations, and engagement in unsafe or unsound practices. Other actions or inactions may provide the basis for enforcement action, including misleading or untimely reports filed with regulatory authorities. At the state level, the PA DOBS also has broad enforcement powers over S&T Bank, including the power to impose fines and other penalties and to appoint a conservator or receiver.
Interstate Banking and Branching
The BHCA currently permits bank holding companies from any state to acquire banks and bank holding companies located in any other state, subject to certain conditions, including certain nationwide and state-imposed deposit concentration limits. In addition, because of changes to law made by the Dodd-Frank Act, S&T Bank may now establish de novo branches in any state to the same extent that a bank chartered in that state could establish a branch.
Fair Lending and Consumer Protection Laws
In connection with its lending activities, S&T Bank is subject to a number of state and federal laws and regulations designed to protect consumers and promote lending to various sectors of the economy and population. The federal laws include, among others, the Equal Credit Opportunity Act, the Truth-in-Lending Act, the Truth-in-Savings Act, the Home Mortgage Disclosure Act, the Real Estate Settlement Procedures Act, the Fair Credit Reporting Act, Fair Housing Act and the Community Reinvestment Act, or CRA. In addition, federal rules require disclosure of privacy policies to consumers.
Fair lending laws prohibit discrimination in the lending practices, and include the Equal Credit Opportunity Act and the Fair Housing Act which outlaw discrimination in credit transactions and residential real estate on the basis of prohibited factors including, among others, race, color, national origin, sex and religion. If a pattern or practice of lending discrimination is alleged by a regulator, then that agency is required to refer the matter to the DOJ for investigation. S&T Bank is required to have a fair lending program that is of sufficient scope to monitor the inherent fair lending risk of the institution and ensure compliance with all applicable fair lending laws and regulations.
11
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
In addition, the Dodd-Frank Act provides that the amount of any interchange fee charged for electronic debit transactions by debit card issuers having assets over $10 billion must be reasonable and proportional to the actual cost of a transaction to the issuer. The Federal Reserve has adopted a rule, Regulation II, which limits the maximum permissible interchange fees that such issuers can receive for an electronic debit transaction. Regulation II was effective on October 1, 2011 and amended on October 3, 2022 to require debit card issuers to provide at least two unaffiliated payment card networks to process card-not-present debit card transactions. Regulation II does not apply to a bank that, together with its affiliates, has less than $10 billion in assets, which includes S&T. In addition, their future application is subject to uncertainty. Ongoing litigation has challenged the Federal Reserve’s implementation of the interchange fee cap, and while no statutory changes have been enacted, adverse judicial outcomes or future regulatory action could modify or invalidate the current framework. The Federal Reserve has not finalized any amendments to Regulation II, and institutions below $10 billion in consolidated assets continue to qualify for the small-issuer exemption. However, as S&T grows, it may become subject to Regulation II, depending on the outcome of ongoing litigation and any applicable rule changes. Additionally, in February of 2026, a federal court in Illinois partially upheld a first-of-its-kind state law restricting interchange fees. This Illinois Interchange Fee Prohibition Act goes into effect on July 1, 2026. The majority of our customers are not located in Illinois, however, there may be similar state laws promulgated over time.
In March 2023, the CFPB issued the “Small Business Lending Rule” to implement Section 1071 of the Dodd-Frank Act for the stated purpose of increasing transparency in small business lending, promoting economic development, and combating unlawful discrimination. Under the Small Business Lending Rule, covered lenders, including S&T Bank, are required to collect and report information about the small business credit applications they receive, including geographic and demographic data, lending decisions and the price of credit. The Small Business Lending Rule has been subject to extensive litigation and court stays have extended the compliance deadlines for certain entities involved in the litigation. As a result, the CFPB announced on April 30, 2025, that it will not prioritize enforcement or supervision of the Small Business Lending Rule for entities not covered by the stay. On June 18, 2025, the CFPB issued an interim final rule to extend compliance deadlines by approximately one year which was finalized on October 2, 2025. In addition, on November 13, 2025, the CFPB proposed significant changes to the Small Business Lending Rule that would exclude certain credit from the definition of covered credit transaction, increase loan origination thresholds for covered companies, change revenue thresholds for the definition of small businesses, remove certain data points from reporting and further extend the compliance date to January 1, 2028 for all covered financial institutions.
In October 2024, the CFPB finalized its “Open Banking Rule” to implement Section 1033 of the Dodd-Frank Act, which would require certain entities, including S&T and S&T Bank, to, among other things, make available to a consumer, upon request, information in its control or possession concerning the consumer financial product or service that the consumer obtained from that entity. The Open Banking Rule has been subject to extensive litigation since its adoption. As part of that litigation, on May 23, 2025, the CFPB stated in a litigation status report that the Open Banking Rule is unlawful. As a result, litigation was stayed while the CFPB conducted new rulemaking process.On August 22, 2025, the CFPB released an advanced notice of proposed rulemaking soliciting public comment to the Open Banking Rule.
S&T Bank is continuing to monitor and evaluate the impact of the Small Business Lending Rule and Open Banking Rule, though compliance may require operational, technology and policy changes, may increase S&T Bank’s compliance costs and could subject S&T Bank to heightened litigation and enforcement risk.
12
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Community Reinvestment Act
The CRA requires the appropriate federal banking agency, in connection with its examination of a bank, to assess the bank’s record in meeting the credit needs of the communities served by the institution, including low- and moderate-income, or LMI, borrowers and neighborhoods. The CRA is designed to encourage regulated banks to help meet the credit needs of the local communities in which they are chartered. The Federal Reserve, the FDIC and the OCC implement the CRA through their CRA regulations which establish the framework for how the agencies assess a bank’s record of helping to meet the credit needs of the communities that they serve, including LMI neighborhoods, consistent with safe and sound operations. Furthermore, such assessment is required of any bank that has applied, among other things, to merge or consolidate with or acquire the assets or assume the liabilities of an insured depository institution, or to open or relocate a branch office. In the case of a bank holding company, including a financial holding company, applying for approval to acquire a bank or bank holding company, the Federal Reserve will assess the record of each subsidiary bank of the applicant bank holding company in considering the application. Under the CRA, institutions are assigned a rating of “outstanding,” “satisfactory,” “needs to improve” or “unsatisfactory.” S&T Bank was rated “satisfactory” in its most recent CRA performance evaluation.
On October 24, 2023, the FDIC, OCC and Federal Reserve jointly issued a final rule to the CRA designed to strengthen and modernize the regulations implementing the CRA. The changes are designed to encourage banks to expand access to credit, investment and banking services in LMI communities, adapt to changes in the banking industry, including mobile and internet banking, provide greater clarity and consistency in the application of the CRA regulations and tailor CRA evaluations and data collection to bank size and type. Most of the final rule’s requirements were applicable beginning in January 2026, while the remaining requirements, including data reporting requirements, will be applicable in January 2027. The 2023 CRA final rule has been subject to legal challenge, and its effectiveness and implementation have been enjoined by a federal court. In light of the foregoing, FDIC, OCC and Federal Reserve jointly issued a proposal on July 16, 2025, to rescind the final CRA final rule issued in October 2023 and replace it with the prior CRA regulations that were originally adopted by the agencies in 1995, with certain technical amendments. Until any new CRA rule becomes effective, we expect to continue to be evaluated under the CRA regulations currently in effect. Any future changes to the CRA framework (including changes to assessment areas, evaluation methods, data collection or reporting requirements and the standards applied in connection with regulatory applications) could increase our compliance costs and may affect our ability to obtain regulatory approvals.
With respect to consumer protection, the Dodd-Frank Act created the CFPB which took over rulemaking responsibility on July 21, 2011 for the principal federal consumer financial protection laws, such as those identified above. Institutions that have assets of $10 billion or less, such as S&T Bank, are subject to the rules established by the CFPB, but will continue to be supervised in this area by their state and primary federal regulators which in the case of S&T Bank is the FDIC. S&T Bank continues to comply with all applicable consumer protection laws and regulations.
Anti-Money Laundering Rules
S&T Bank is subject to the Bank Secrecy Act, or BSA, its implementing regulations and other anti-money laundering, or AML, laws and regulations, including the USA Patriot Act of 2001. Among other things, these laws and regulations require S&T Bank to take steps to prevent the bank from being used to facilitate the flow of illegal or illicit money, to report large currency transactions and to file suspicious activity reports. S&T Bank is also required to develop and implement a comprehensive AML/Countering The Financing Of Terrorism, or CFT, compliance program. Banks must also have in place appropriate “know your customer”, or KYC, policies and procedures which includes requirements to (1) identify and verify, subject to certain exceptions, the identity of the beneficial owners of all legal entity customers at the time a new account is opened, and (2) include in its AML/CFT program, risk-based procedures for conducting ongoing customer due diligence, which are to include procedures that (a) assist in understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile, and (b) require ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. Violations of these requirements can result in substantial civil and criminal sanctions. In addition, provisions of the USA Patriot Act of 2001 require the federal financial institution regulatory agencies to consider the effectiveness of a financial institution’s AML/CFT activities when considering applications for bank mergers and bank holding company acquisitions.
In June 2025, the federal bank regulators in coordination with the Financial Crimes Enforcement Network, or FinCEN, issued an exemption order from the customer identification program requirement for banks to collect Taxpayer Identification Numbers (TINs) directly from customers before opening accounts. The exemption allows banks to obtain TIN information from third-party sources, provided they still comply with other Customer Identification Program, or CIP, requirements, including risk-based procedures to verify customer identities. This exemption aims to address evolving customer interaction methods and privacy concerns, especially related to identity theft risks. Banks are not required to use this alternative collection method but may choose to do so if it aligns with their risk-based approach to customer verification.
13
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
The Anti-Money Laundering Act of 2020, enacted on January 1, 2021 as part of the National Defense Authorization Act, or AMLA, amends the BSA but does not directly impose new requirements on banks. However, AMLA requires the U.S. Treasury Department to, among other things, issue National Anti-Money Laundering and Countering the Financing of Terrorism Priorities and implementing regulations, and conduct studies and issue regulations that may, over the next few years, significantly alter certain due diligence, recordkeeping and reporting requirements that the BSA and its implementing regulations impose on banks. AMLA also contains provisions that increase penalties for violations of the BSA and includes whistleblower incentives, both of which could increase regulatory enforcement against banks. Implementation of AMLA is ongoing and is anticipated to impact S&T Bank’s AML compliance program.
In an effort to increase transparency in the U.S. financial system and prevent shell entities from being used to launder money or hide assets, AMLA includes the Corporate Transparency Act, or CTA, which requires the U.S. Treasury Department’s Financial Crimes Enforcement Network, or FinCEN, to, among other things, establish a national beneficial ownership information registry. In September 2022, FinCEN issued the final Beneficial Ownership Information Reporting Requirements rule, or BOI Reporting Rule, which effective January 1, 2024, requires certain “reporting companies” to file beneficial ownership information reports with FinCEN that will be stored in the national beneficial ownership registry and will detail the reporting company’s beneficial owners. In December 2023, FinCEN issued the final Beneficial Ownership Information Access and Safeguards rule - the second of three rulemakings that would implement the CTA - which governs access to the national beneficial ownership registry. The constitutionality of the CTA is subject to litigation, and on March 21, 2025, FinCEN issued an interim final rule that significantly revised the definition of “reporting company” in its implementing regulations to mean only those entities that are formed under the law of a foreign country and that have registered to do business in any U.S. State or Tribal jurisdiction by the filing of a document with a secretary of state or similar office (formerly known as “foreign reporting companies”). FinCEN also exempts entities previously known as “domestic reporting companies” from BOI reporting requirements. Thus, through this interim final rule, all entities created in the United States — including those previously known as “domestic reporting companies” — and their beneficial owners are exempt from the requirement to report BOI to FinCEN. Foreign entities that meet the new definition of a “reporting company” and do not qualify for an exemption from the reporting requirements must report their BOI to FinCEN under new deadlines, detailed below. These foreign entities, however, will not be required to report any U.S. persons as beneficial owners, and U.S. persons will not be required to report BOI with respect to any such entity for which they are a beneficial owner.
OFAC Regulation
The U.S. Treasury Department’s Office of Foreign Assets Control, or OFAC is responsible for administering U.S. economic sanctions which can prohibit certain transactions with designated foreign countries, nationals and others. OFAC-administered sanctions take on many different forms. For example, sanctions may include: (1) restrictions on trade with or investment in a sanctioned country, including prohibitions against direct or indirect imports from and exports to a sanctioned country and prohibitions on U.S. persons engaging in financial transactions relating to, making investments in, or providing investment-related advice or assistance to, a sanctioned country; and (2) blocking assets in which certain sanctioned foreign governments, entities or individuals have an interest, by prohibiting transfers of property subject to U.S. jurisdiction, including property in the possession or control of U.S. persons. OFAC also maintains a list of designated persons, groups or entities that are the target of sanctions, including the “Specially Designated Nationals and Blocked Persons List.” The assets of designated persons, groups or entities are blocked and U.S. persons are generally prohibited from dealing with any such persons. Moreover, blocked assets, for example property and bank deposits, cannot be paid out, withdrawn, set off or transferred in any manner without a license from OFAC. If we find a name on any transaction, account or wire transfer associated with a sanctioned person, we must freeze or block such account or transaction, file a blocked property report with OFAC and notify the appropriate authorities. Failure to comply with U.S. economic sanctions could have serious legal and regulatory consequences.
The Volcker Rule
In December 2013, federal regulators adopted final regulations regarding the Volcker Rule established in the Dodd-Frank Act. The Volcker Rule generally prohibits banks and their affiliates from engaging in proprietary trading and investing in and sponsoring certain unregistered investment companies generally covering hedge funds and private equity funds, subject to certain exemptions. Banking entities had until July 21, 2017 to conform their activities to the requirements of the rule. Since S&T generally does not engage in the activities prohibited by the Volcker Rule, the effectiveness of the rule has not had a material effect on S&T Bank or its affiliates.
14
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Data Privacy and Cybersecurity
We are subject to a variety of regulatory requirements regarding data privacy, data security and cybersecurity. For example, current federal laws, rules, regulations and standards, including the Gramm-Leach-Bliley Act, or GLBA, require financial institutions to, among other things, periodically disclose their privacy policies and practices relating to sharing personal information and enable retail customers to opt out of our ability to share such personal information with unaffiliated third parties under certain circumstances. Such laws and regulations also require financial institutions to implement a comprehensive cybersecurity program that includes administrative, technical and physical safeguards to ensure the security and confidentiality of customer records and information. Other federal and state laws and regulations impact our ability to share certain information with affiliates and non-affiliates for marketing and/or non-marketing purposes, or to contact customers with marketing offers. Federal law also makes it a criminal offense, except in limited circumstances, to obtain or attempt to obtain customer information of a financial nature by fraudulent or deceptive means. S&T Bank is also subject to rules and regulations issued by the Federal Trade Commission which regulates unfair or deceptive acts or practices, including with respect to data privacy and cybersecurity. Additionally, like other lenders, S&T Bank uses credit bureau data in its underwriting activities. Use of such data is regulated under the Fair Credit Reporting Act which also regulates reporting information to credit bureaus, prescreening individuals for credit offers, sharing of information between affiliates, and using affiliate data for marketing purposes. Similar state laws may impose additional requirements on us and our subsidiaries. The federal government also is considering, and may pass, additional data privacy and cybersecurity legislation, to which we may become subject if passed.
Federal and state regulators of financial institutions have issued guidance regarding cybersecurity, addressing the scope of controls that financial institutions should implement and maintain and business continuity planning and recovery processes that should be in place. Additionally, the FDIC, OCC and Federal Reserve issued a final rule that became effective in May 2022, requiring banking organizations that experience a computer-security incident to notify certain entities and its federal regulator as soon as possible and no later than 36 hours after the bank determines a computer-security incident has occurred. This rule also requires banking organizations to notify their customers of a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours. In March of 2022, the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, was enacted and once final rules are adopted, will require certain covered entities to report a covered cyber incident to the U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency, or CISA, within 72 hours after a covered entity reasonably believes an incident has occurred. Separate reporting to CISA will also be required within 24 hours if a ransom payment is made as a result of a ransomware attack. Furthermore, in September 2023, the SEC’s Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure rules went into effect requiring, among other disclosure obligations, companies to publicly disclose the occurrence of a material cybersecurity incident, including the material aspects of the nature, scope, timing and impact of the incident on the company's financial condition and results of operations and brand beginning with any material cybersecurity incidents that occur on or after December 18, 2023.
State regulators have also been increasingly active in implementing privacy and cybersecurity standards and regulations, including data access requests and breach notification requirements. We actively monitor developments regarding regulatory expectations and federal and state requirements with respect to cybersecurity, data access requests and data breach notifications.
Other Legislative and Regulatory Changes
Various legislative and regulatory proposals are being considered by the executive branch of the federal government, Congress and various state governments, including Pennsylvania, that would result in substantial changes in banking, the regulation of banks, thrifts and other financial institutions, compensation, the regulation of financial markets and their participants, financial instruments and securities and the regulators and taxation of these entities.
Throughout 2025, Congress and the federal bank regulators expanded the scope of permissible digital asset activities for banks. The Government Enabling New Innovative Unstoppable Systems Act, or GENIUS Act, enacted in July 2025 as a significant piece of legislation aimed at establishing a comprehensive regulatory framework for stablecoins and digital assets in the U.S. The GENIUS Act provides clarity on the treatment of digital currencies, including the framework for stablecoin issuances by bank and non-banking entities, custody, reserves and payments systems and adopts a supervisory framework for stablecoin issuers. Under the GENIUS Act, banks are allowed to engage in stablecoin issuances and hold related reserves, provided they comply with established AML, KYC and capital adequacy standards.
In addition, the FDIC and Federal Reserve issued revised guidance regarding their engagement in crypto-related activities. This guidance rescinds prior guidance which previously required banks to submit prior notifications to the FDIC before engaging in such activities. Under the new framework, banks may engage in permissible crypto-related services, including custody and stablecoin reserve management, without needing to receive prior FDIC approval. However, banks are still required to manage risks effectively, including market, liquidity, operational and cybersecurity risks, and to comply with all AML/CFT and consumer protection requirements.
15
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
While we are not yet directly involved in stablecoin issuance or similar digital asset services, we continue to monitor developments under the GENIUS Act and FDIC policy, particularly as they evolve in the areas of digital asset custody, payments systems and associated regulatory requirements. The FDIC’s recent approach signals that smaller banks have greater flexibility to explore these opportunities, provided they adhere to compliance standards designed to protect customers and ensure safety and soundness.
Competition
S&T Bank competes with other local, regional and national financial services providers, such as other financial holding companies, commercial banks, credit unions, finance companies, brokerage and insurance firms and financial technology companies, including competitors that provide their products and services online and through mobile devices. Some of our competitors are not subject to the same level of regulation and oversight that is required of banks and bank holding companies and are thus able to operate under lower cost structures. Our wealth management business competes with trust companies, mutual fund companies, investment advisory firms, law firms, brokerage firms and other financial services companies.
Changes in bank regulation, such as changes in the products and services banks can offer and permitted involvement in non-banking activities by bank holding companies, as well as bank mergers and acquisitions, can affect our ability to compete with other financial services providers. Our ability to do so will depend upon how successfully we can respond to the evolving competitive, regulatory, technological and demographic developments affecting our operations.
Our customers are primarily in Pennsylvania and the contiguous states of Ohio, New York, West Virginia, New Jersey, Delaware and Maryland. The majority of our commercial and consumer loans are made to businesses and individuals in these states resulting in geographic concentration. Our market area has a high density of financial institutions, some of which are significantly larger institutions with greater financial resources than us, and many of which are our competitors to varying degrees. Our competition for loans comes principally from commercial banks, mortgage banking companies, credit unions, online lenders and other financial service companies. Our most direct competition for deposits has historically come from commercial banks and credit unions. We face additional competition for deposits from non-depository competitors such as the mutual fund industry, securities and brokerage firms, insurance companies and financial technology companies. Since larger competitors have advantages in attracting business from larger corporations, we do not generally attempt to compete for that business. Instead, we concentrate our efforts on attracting the business of individuals, and small and medium-sized businesses. We consider our competitive advantages to be customer service and responsiveness to customer needs, the convenience of banking offices and hours, access to electronic banking services and the availability and pricing of our customized banking solutions. We emphasize personalized banking and the advantage of local decision-making in our banking business.
The financial services industry is likely to become more competitive as further technological advances enable more companies to provide financial services on a more efficient and convenient basis. Technological innovations have lowered traditional barriers to entry and enabled many companies to compete in financial services markets. Many customers now expect a choice of banking options for the delivery of services, including traditional banking offices, telephone, internet, mobile, ATMs, self-service branches, in-store branches and/or digital and technology-based solutions. These delivery channels are offered by traditional banks and savings associations, credit unions, brokerage firms, asset management groups, financial technology companies, finance and insurance companies, internet-based companies and mortgage banking firms.
Item 1A. RISK FACTORS
Investments in our common stock involve risk. The following discussion highlights the risks that we believe are material to S&T, potentially impacting our business, results of operations, financial condition and cash flows. However, other factors not discussed below or elsewhere in this Annual Report on Form 10-K could adversely affect our businesses, results of operations and financial condition. Therefore, the risk factors below do not necessarily include all risks that we may face.
Risks Related to Credit
Our ability to assess the credit-worthiness of our customers may diminish which may adversely affect our results of operations.
We incur credit risk by virtue of making loans and extending loan commitments and letters of credit. Credit risk is one of our most significant risks. We manage our exposure to credit risk through the use of consistent underwriting standards that emphasize “in-market” lending while avoiding excessive industry and other concentrations. Our credit administration function employs risk management techniques to ensure that loans adhere to corporate policy and problem loans are promptly identified. There can be no assurance that such measures will be effective in avoiding undue credit risk. If the models and approaches that we use to select, manage and underwrite our consumer and commercial loan products change and our underwriting standards do not reflect or capture the rapid changes in the economy, we may have higher credit losses.
16
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
The value of the collateral used to secure our loans may not be sufficient to compensate for the amount of unpaid loans and we may be unsuccessful in recovering the remaining balances from our customers.
Decreases in collateral values underlying our loans, particularly with respect to our commercial real estate, or CRE, and commercial and industrial, or C&I, could adversely affect our customers’ ability to repay these loans which in turn could impact our profitability. Repayment of our commercial loans is often dependent on the cash flow of the borrower which may become unpredictable. If the value of the assets, such as real estate or business assets, serving as collateral for the loan portfolio were to decline materially, a significant part of the loan portfolio could become under-collateralized. If the loans that are secured by real estate become troubled when real estate market conditions are declining or have declined, in the event of foreclosure, we may not be able to realize the amount of collateral that was anticipated at the time of originating the loan. The underlying business assets that serve as collateral for C&I loans may be specific and unique to the borrowers industry; therefore, when the borrower encounters financial difficulties, the business assets may not have sufficient value. This could result in higher charge-offs which could have a material adverse effect on our operating results and financial condition.
Changes to our provision for credit losses or ACL could significantly impact our operating results and financial condition.
Like other lenders, we face the risk that our customers will not repay their loans. We reserve for losses in our loan portfolio based on our assessment of expected credit losses. Management determines the amount of allowance for credit losses, or ACL, through undergoing a periodic review of the loan portfolio, where it considers historical losses, forward-looking information including management's assessment of the macroeconomic conditions, including the national unemployment forecast produced by the Federal Reserve and qualitative factors around current conditions including changes in lending policies and practices, economic conditions, changes in the loan portfolio, changes in lending management, results of internal loan reviews, asset quality trends, collateral values, concentrations of credit risk and other external factors. This process, which is critical to our financial results and condition, requires complex judgment including our assessment of economic conditions which are difficult to predict. The amount of future losses is difficult to predict because it is susceptible to changes in economic, operating and other conditions, including changes in interest rates which may be beyond our control. Although we have policies and procedures in place to determine future losses, due to the subjective nature of this area, there can be no assurance that our management has accurately assessed the level of allowance reflected in our consolidated financial statements. We may underestimate our expected credit losses and fail to hold an ACL sufficient to account for these losses or we may overestimate expected credit losses and maintain an ACL in excess of what is required. Incorrect assumptions could lead to material underestimates or overestimates of expected losses and an inadequate or excessive ACL. As our assessment of expected losses changes, we may need to increase or decrease our ACL which could significantly impact our operating results and financial condition.
Our loan portfolio is concentrated within our market area, and our lack of geographic diversification increases our risk profile.
The regional economic conditions within our market area affect the demand for our products and services as well as the ability of our customers to repay their loans and the value of the collateral securing these loans. A significant decline in the regional economy caused by inflation, recession, unemployment or other factors could negatively affect our customers, the quality of our loan portfolio and the demand for our products and services. Any sustained period of increased payment delinquencies, foreclosures or losses caused by adverse market or economic conditions in our market area could adversely affect the value of our assets, revenues, results of operations and financial condition. Moreover, we cannot give any assurance that we will benefit from any market growth or favorable economic conditions in our primary market area.
17
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Our loan portfolio has a significant concentration of commercial loans that have a higher risk of loss.
The majority of our loans are to commercial borrowers including C&I, Commercial Real Estate, or CRE, and construction loans. The commercial loan portfolio typically involves a higher degree of credit risk than other types of loans. For the C&I segment this is due to the customer’s repayment ability being based upon the success of its business operations, the susceptibility of the customer’s business to changing economic conditions, the dependence of our customer on maintaining sufficient cash flow to make payments on the loan and our reliance on the underlying collateral which is usually only the business assets that may not have sufficient value when the borrower encounters financial difficulties. For the CRE segment higher risk is due to higher loan principal amounts, where the repayment of these loans is generally dependent, in large part, on sufficient income from the properties securing the loans to cover operating expenses and debt service. Because payments on loans secured by CRE often depend upon the successful operation and management of the properties, repayment of these loans may be affected by factors outside the borrower’s control, including adverse conditions in the real estate market or the economy. Additionally, we have a number of significant credit exposures to commercial borrowers, and while the majority of these borrowers have numerous projects that make up the total aggregate exposure, if one or more of these borrowers default or have financial difficulties, we could experience higher credit losses which could adversely impact our financial condition and results of operations. Further, an individual commercial loan balance is typically larger than other loans in our portfolio, creating the potential for larger credit losses on an individual loan. The deterioration of one or a few of these loans could have a material adverse effect on our financial condition and results of operations.
18
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Risks Related to General Economic Conditions
General economic conditions may adversely impact our business, financial condition, results of operations or cash flows.
Various aspects of our business could be impacted by general macroeconomic conditions including, among others, inflation, interest rates, rising or elevated unemployment, declines in GDP, consumer spending, property values, supply chain complications and economic uncertainty. These conditions generally have a negative impact on businesses, financial markets and consumers which may impact the underlying credit quality of our customers. The following could increase the risk of our customers defaulting or becoming delinquent in their obligations to us which could increase credit losses and adversely affect our credit portfolios and provision for credit losses: (i) increased cost of borrowings, (ii) additional borrowings and increased leverage, (iii) drawdown from savings due to business disruption, (iv) financial difficulties, or (v) business losses, particularly for borrowers in our C&I or CRE portfolio. Furthermore, the United States has recently enacted significant new tariffs and may enact additional tariffs. There continues to be significant uncertainty and concern about the future relationship between the U.S. and other countries, including with respect to trade policies, treaties, government regulations, sanctions, tariffs, and application thereof, since the imposition of tariffs that began in April 2025. We are continuing to evaluate the impact of tariffs and trade policies on our business and our customers; however, we cannot provide any assurance about the ultimate outcome or impact of these measures. Additional changes to United States tariffs and/or other trade policies, retaliatory measures and the effect of cost increases and continued uncertainty may have a negative effect on the underlying credit quality of our customers, and increase the risk of our customers defaulting or becoming delinquent in their obligations to us. If the macroeconomic environment worsens, our credit portfolio and ACL could be adversely impacted. These unfavorable economic conditions could also impact the demand for loans and other products and services offered by us, the level of customer deposits, the value of our investment securities, loans held for sale or other assets secured by residential or commercial real estate or the level of net interest income or net interest margin. Any of these developments could adversely impact our business, financial condition, results of operations or cash flows. Additionally, changes to the size, structure, and operation of the federal government, including the workforce reduction, elimination or curtailment of federal agencies, delivery of government services and distribution of federal program funds and benefits may cause economic disruption that could adversely impact our customers and our business, results of operations and financial condition.
We may not accurately predict the nature and timing of the policies of the Federal Reserve and other governmental agencies and their impact on interest rates and financial markets which could negatively impact our financial condition and results of operations.
The monetary policies of the Federal Reserve have a significant impact on interest rates, the value of financial instruments and other assets and liabilities, and overall financial market performance. These policies have a significant impact on the activities and results of operations of banks and bank holding companies such as S&T. An important function of the Federal Reserve is to monitor the national supply of bank credit and set certain interest rates. The actions of the Federal Reserve influence the rates of interest that we charge on loans and that we pay on borrowings and interest-bearing deposits. In addition, monetary policy actions by governmental authorities in the European Union or other countries could have an impact on global interest rates which could affect rates in the U.S. We may not accurately predict the nature or timing of future changes in monetary policies and interest rates or the precise effects that they may have on our activities and financial results which could negatively impact our financial condition and results of operations.
Financial challenges at other banking institutions; adverse developments affecting the financial services industry; concerns regarding the soundness of financial institutions; and further disruption to the economy and the U.S. banking system may adversely affect our business, results of operations, liquidity and stock price
Several bank receiverships in 2023 caused a state of volatility in the financial services industry and uncertainty with respect to liquidity and the health of the U.S. banking system. Although we were not directly affected by these bank receiverships, this news caused fear among depositors which caused them to withdraw or attempt to withdraw their funds from these and other financial institutions. Uncertainty may be compounded by the reach and depth of media attention, including social media, and its ability to disseminate concerns or rumors about any events of these kinds or other similar risks, and have in the past and may in the future lead to market-wide liquidity problems. Additionally, the stock prices of many financial institutions dropped and became volatile. While the FDIC resolution of these banks was done in a manner that protected depositors, there remains concern over the U.S. banking system as a result of continued economic volatility. Furthermore, financial services institutions are interrelated as a result of trading, clearing, counterparty or other relationships which may expose us to credit risk and losses in the event of a default by a counterparty or client. As a result of these events, we face the potential for brand risk, deposit outflows and increased credit risk, which individually or in the aggregate, could have a material adverse effect on our business, financial condition and results of operations and liquidity.
19
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Furthermore, if such levels of financial market and economic disruption and volatility continue, if actual events or concerns or rumors involving limited liquidity, defaults, or other adverse developments, or if other banks and financial institutions enter receivership or become insolvent in the future in response to financial conditions affecting the banking system and financial markets, our ability to access our existing cash, cash equivalents and investments may be threatened due to market-wide liquidity problems. While we maintain liquidity primarily through customer deposits and through access to other short-term funding sources, including advances from the Federal Home Loan Bank, or FHLB, our efforts to monitor and manage liquidity risk may not be successful or sufficient to deal with dramatic or unanticipated increases or reductions in our liquidity, particularly in light of the impact of increased interest rates on the market value of investment securities. This situation could have a material adverse impact on our results of operations and financial condition.
Although the FDIC made deposit insurance assessment accommodations December 2025, periods of stress in the banking industry often result in increased deposit insurance assessments when banks fail, increased scrutiny by federal and state regulators, including State attorneys general, as well as potential investigations or litigation relating to liquidity management, deposit practices, disclosures or risk management. Such actions, regardless of merit, could have material adverse effects on our business, results of operations, financial condition and growth prospects.
Geopolitical tensions and conflicts between nations have created significant economic and financial disruptions and uncertainties which could adversely affect our business, financial condition and results of operations.
The continuing conflict resulting from Russia’s military attack on Ukraine in February 2022 and other armed conflicts such as that involving Hamas and Israel beginning in October 2023 may cause detrimental effects on the global economy. This conflict, as well as further escalation of tensions between Israel and various countries in the Middle East, North Africa and rising tensions between United States and Venezuela, may cause additional detrimental effects on the global economy, including financial and capital markets which could adversely impact our results of operations.
Although the extent and duration of these military conflicts and any future escalation of such hostilities, market disruptions and volatility and the result of any diplomatic negotiations remains uncertain, these consequences, including those we cannot yet predict, may cause our business, financial condition, results of operations and the price of our common stock to be adversely affected.
20
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Risks Related to Our Operations
Failure to keep pace with technological changes and successfully implement current or future information technology system enhancements could have a material adverse effect on our results of operations and financial condition.
The financial services industry is constantly undergoing rapid technological change with frequent introductions of new technology-driven products and services, including the use of artificial intelligence and digital assets. The effective use of technology increases efficiency and enables financial institutions to better service customers and reduce costs. Our future success depends, in part, upon our ability to address the needs of our customers by using technology to provide products and services that will satisfy their demands, as well as create additional efficiency within our operations. We continue to invest in information technology systems in order to provide functionality to improve our operating efficiency and to streamline our client experience. We may not be able to effectively implement new technology-driven products, enhancements and services quickly or be successful in marketing these products and services to our customers. Failure to successfully keep pace with technological change affecting the financial services industry, including but not limited to changes affecting our information systems resulting in incidents, attacks or breaches in cybersecurity; or utilize system enhancements that are implemented in the future, could have a material adverse impact on our business, financial condition and results of operations. As such, we cannot guarantee anticipated long-term benefits from these system enhancements and operational initiatives.
A cyber attack, information or security breach, or a failure of ours or of a third-party's infrastructure, computer and data management systems could adversely affect our ability to conduct our business or manage our exposure to risk, result in the disclosure or misuse of confidential or proprietary information, increase our costs to maintain and update our operational and security systems and infrastructure, and adversely impact our results of operations, liquidity and financial condition, as well as cause diminished customer, employee or investor confidence.
Our business is highly dependent on the security and efficacy of our infrastructure, computer and data management systems, as well as those of third parties with whom we interact. Cybersecurity risks for financial institutions have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists and other external parties, including foreign state actors. Our operations rely on the secure processing, transmission, storage and retrieval of confidential, proprietary and other information in our computer and data management systems and networks, and in the computer and data management systems and networks of third parties. We rely on digital technologies, computer, database and email systems, software and networks to conduct our operations. In addition, to access our network and products and services, our customers and third parties may use personal mobile devices or computing devices that are outside of our network environment. We have taken measures to implement backup systems and other safeguards to support our operations, but our ability to conduct business may be adversely affected by any significant disruptions to us or to third parties with whom we interact. We further issue debit cards which are susceptible to compromise at the point of sale via the physical terminal through which transactions are processed and by other means of hacking. The security and integrity of these transactions are dependent upon the retailers’ vigilance and willingness to invest in technology and upgrades. Issuing debit cards to our clients exposes us to potential losses, which in the event of a data breach at one or more major retailers, may adversely affect our business, financial condition and results of operations.
Financial services institutions, and third parties whom they conduct business with, have been subject to, and are likely to continue to be the target of, cyber attacks, including computer viruses, malicious or destructive code, phishing attacks, denial of service, adversarial artificial intelligence or other security breaches that could result in the unauthorized release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary and other information of the institution, its employees or customers or of third parties, or otherwise materially disrupt network access or business operations. For example, denial of service attacks have been launched against a number of large financial institutions and several large retailers have disclosed substantial cybersecurity breaches affecting debit accounts of their customers. We have experienced cybersecurity incidents in the past, such as vendor malware attacks, phishing and other social engineering schemes designed to gain access to confidential information from our employees, customers or vendors and, although not material, we anticipate that we could experience further incidents of that nature as well as other types of attempts or incidents. Specifically, the rapid evolution of artificial intelligence, generative artificial intelligence and quantum computing has enabled malicious actors to develop more advanced social engineering attacks. Furthermore, the potential development of quantum computing capabilities poses future risks to existing cryptographic standards which could jeopardize the integrity of our secure data transmissions. There can be no assurance that we will not suffer material losses or other material consequences relating to technology failure, cyber incidents or other information or security breaches.
In addition to external threats, insider threats also present a risk to us. Insiders, having legitimate access to our systems and the information contained in them, have the opportunity to make inappropriate use of the systems and information, or as a result of human error, misconduct or malfeasance, expose us to risk. We have policies, procedures and controls in place designed to prevent or limit this risk, but we cannot guarantee that these policies, procedures and controls fully mitigate this risk.
21
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Additionally, a number of our employees have the ability to work from remote locations, increasing the number of surfaces that require protection and the overall risks and exposures to cyber threats.
We have taken and continue to take measures to design, implement and reassess our controls, backup systems and other safeguards to support our operations, but no matter how well designed or implemented, we may not be able to anticipate and prevent all potential types of security incidents and breaches, and we may not be able to implement effective preventive measures against such security breaches in a timely manner. As cyber threats continue to evolve, we may also be required to expend significant additional resources to continue to modify or enhance our systems or to investigate and remediate vulnerabilities. System enhancements and updates have further potential to create risks associated with implementing and integrating new systems. Due to the complexity and interconnectedness of information technology systems, the process of enhancing our systems can itself create a risk of systems disruptions and security issues. Any of these matters could result in failure, circumvention of our security systems or significant disruptions to us or third parties with whom we interact, misappropriation or destruction of our confidential information and/or that of our customers, or damage to our customers’ and/or third parties’ computers or systems, loss of our customers and business opportunities, and could result in a violation of applicable privacy laws and other laws, litigation exposure, regulatory fines, penalties or intervention, loss of confidence in our security measures, negative public opinion, reimbursement or other compensatory costs and additional compliance costs. In addition, any of the matters described above could have a material adverse impact on our results of business operations and financial condition.
Any of the foregoing risks may cause us to experience a cybersecurity incident, attack or breach. A successful security breach of our information or security systems or those of third parties whom we interact with could incur substantial costs or other negative consequences which cause us to suffer material losses. Examples of such material losses include, but are not limited to: (1) remediation costs, such as liability for stolen assets or information, repairs of system damage and incentives to customers in an effort to maintain relationships after an attack; (2) violations of applicable privacy and other laws; (3) loss of confidence in its security measures; (4) increased cybersecurity protection costs, such as organizational changes, deploying additional personnel and protection technologies, training employees and engaging third party experts and consultants; (5) significant litigation exposure; (6) negative public opinion; (7) financial loss; and (8) damage to our competitiveness, stock price and long-term shareholder values. There can be no assurance we will not suffer material losses or other material consequences relating to technology failure, cyber incidents or other information or security breaches experienced by us or the third parties whom we interact with.
While we maintain a cyber insurance policy that is designed to cover a majority of loss resulting from cybersecurity breaches, there is no assurance such coverage or other protective measures we employ will be adequate to address all potential material adverse impacts as cybersecurity incidents increase in frequency and magnitude. Any breach of our system security could result in disruption of our operations, unauthorized access to confidential customer information, significant regulatory costs, litigation exposure and other possible damages, loss or liability. Such costs or losses could exceed the amount of available insurance coverage, if any, and would adversely affect our results of operations.
Moreover, we are subject to laws and regulations in the United States and other jurisdictions regarding privacy, data protection and data security and there continues to be heightened legislative and regulatory focus in this area. These laws and regulations are rapidly evolving and increasing in complexity and will require us to incur costs, some of which may be significant, to achieve and maintain compliance and could restrict our ability to provide certain products and services which could have an adverse effect on our business, financial condition and results of operations. Furthermore, as cybersecurity incidents increase in frequency and magnitude, we may be unable to obtain cybersecurity insurance in amounts and on terms we view as adequate for our operations.
For more information on how S&T manages cybersecurity risk, please refer to the discussion provided below under “Part I, Item 1C. Cybersecurity.”
Fraudulent activity associated with our products and services could adversely affect our results of operations, financial condition and stock price, negatively impact our brand and result in regulatory intervention or sanctions.
As a financial institution we are exposed to operational risk in the form of fraudulent activity that may be committed by customers, other third parties or employees, targeting us and our customers. The risk of fraud continues to increase for the financial services industry. Fraudulent activity has escalated, become more sophisticated, and continues to evolve, as there are more options to access financial services. The sophistication of generative artificial intelligence enables the automation and refinement of fraudulent schemes, including the creation of deceptive financial records, synthetic media and highly persuasive social engineering attacks. While we believe we have operational risk controls in place to prevent or detect fraud or to mitigate the impact of any fraud, we cannot provide assurance that we can prevent or detect fraud or that we will not experience future fraud losses or incur costs or other damage related to such fraud, at levels that adversely affect our results of operations, financial condition or stock price. Furthermore, fraudulent activity could negatively impact our brand which could also adversely affect our results of operations, financial condition or stock price. Fraudulent activity could also lead to regulatory intervention or regulatory sanctions.
22
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
We rely on certain critical third-party providers for a number of services that are important to our business. An interruption or cessation of an important service by any critical third-party provider could have a material adverse effect on our business.
We are dependent for the majority of our technology, including our core operating system, on certain critical third-party providers. If these companies were to discontinue providing services to us, we may experience significant disruption to our business. In addition, each of these third parties faces the risk of cyber attack, information breach or loss or technology failure. If any of our critical third-party service providers experience such difficulties, or if there is any other disruption in our relationships with them, we may be required to find alternative sources of such services. We are dependent on these critical third-party providers securing their information systems, over which we have limited control, and a breach of their information systems could adversely affect our ability to process transactions, service our clients or manage our exposure to risk and could result in the disclosure of sensitive, personal customer information which could have a material adverse impact on our business through damage to our brand, loss of business, remedial costs, additional regulatory scrutiny or exposure to civil litigation and possible financial liability. We also depend on third-party vendors and service providers for core systems and specialized tools that may incorporate artificial intelligence functionality. Our ability to manage artificial intelligence related risk is therefore partially dependent on the controls, governance and resilience of those third parties. If a vendor's artificial intelligence system fails, is inadequately governed, is subject to regulatory action or experiences a cyber incident or service disruption, we may be unable to continue certain operations, may incur remediation costs or may face contractual or regulatory consequences. Assurance cannot be provided that we could negotiate terms with alternative service sources that are as favorable or could obtain services with similar functionality as found in existing systems without the need to expend substantial resources, if at all, thereby resulting in a material adverse impact on our business and results of operations.
Failure to continue to attract, develop and maintain a highly skilled workforce may have an adverse effect on our business.
Our business requires that we attract, develop and maintain a highly skilled workforce. Competition for qualified employees and personnel in the banking industry is strong, and there are a limited number of qualified persons with knowledge of, and experience in, the banking industry where we conduct our business. Our ability to attract and retain skilled personnel cost effectively is subject to a variety of external factors, including the limited availability of qualified personnel in the workforce in the local markets in which we operate, unemployment levels within those markets, prevailing wage rates which have increased significantly, health and other insurance costs and changes in employment and labor laws. Furthermore, the complexities introduced into the labor market as a result of the transition to increased work-from-home arrangements have impacted the competitive landscape in our labor market. Based on current conditions in the labor market, we have experienced some difficulty in retaining and attracting personnel and there is no assurance that we will be able to continue to successfully do so.
Risks Related to Our Business Strategy
Our strategy includes growth plans through organic growth and by means of acquisitions. Our financial condition and results of operations could be negatively affected if we fail to grow or fail to manage our growth effectively.
We intend to continue pursuing a growth strategy through organic growth within our current footprint and through market expansion. We also actively evaluate acquisition opportunities as another source of growth. We cannot give assurance that we will be able to expand our existing market presence, or successfully enter new markets or that any such expansion will not adversely affect our results of operations. Failure to manage our growth effectively could have a material adverse effect on our business, future prospects, financial condition or results of operations and could adversely affect our ability to successfully implement our business strategy.
Our failure to find suitable acquisition candidates, or successfully bid against other competitors for acquisitions, could adversely affect our ability to fully implement our business strategy. If we are successful in acquiring other entities, the process of integrating such entities will divert significant management time and resources. We may not be able to integrate efficiently or operate profitably any entity we may acquire. We may experience disruption and incur unexpected expenses in integrating acquisitions. These failures could adversely impact our future prospects and results of operations.
23
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
We are subject to competition from both banks and non-banking companies.
The financial services industry is highly competitive, and we encounter strong competition for deposits, loans and other financial services in our market area, including online providers of these products and services. Our principal competitors include other local, regional and national financial services providers, such as other financial holding companies, commercial banks, financial technology companies, credit unions, finance companies and brokerage and insurance firms, including competitors that provide their products and services online. Many of our non-bank competitors are not subject to the same degree of regulation that we are and have advantages over us in providing certain services. Additionally, many of our competitors are significantly larger than we are and have greater access to capital and other resources. Failure to compete effectively for deposit, loan and other financial services customers in our markets could cause us to lose market share, slow our growth rate and have an adverse effect on our financial condition and results of operations.
In addition, transactions utilizing digital assets, including cryptocurrencies, stablecoins and other similar assets have increased over the past few years and continue to gain wider market acceptance. Certain characteristics of digital asset transactions, including their speed and anonymity are appealing to certain consumers notwithstanding the various risks posed by such transactions. In addition, certain cryptocurrency exchanges and other market participants may pay yield on digital asset holdings in the same manner as interest-bearing deposit accounts which may result in loss of deposits. Accordingly, digital asset service providers, who currently are not subject to the same extensive regulation as banking organizations and other financial institutions, have become potential competitors for our customers' banking business.
We may be required to raise capital in the future, but that capital may not be available or may not be on acceptable terms when it is needed.
We are required by federal regulatory authorities to maintain adequate capital levels to support operations. While we believe we currently have sufficient capital, if we cannot raise additional capital when needed, we may not be able to meet these requirements. In addition, our ability to further expand our operations through organic growth, which includes growth within our current footprint and growth through market expansion, may be adversely affected by any inability to raise necessary capital. Our ability to raise additional capital at any given time is dependent on capital market conditions at that time and on our financial performance and outlook.
Risks Related to Interest Rates and Investments
Our net interest income could be negatively affected by interest rate changes which may adversely affect our financial condition and results of operations.
Our results of operations are largely dependent on net interest income which is the difference between the interest and fees earned on interest-earning assets and the interest paid on interest-bearing liabilities. Therefore, any change in general market interest rates, including changes resulting from the Federal Reserve Board's policies, can have a significant effect on our net interest income and total income. There may be mismatches between the maturity and repricing of our assets and liabilities that could cause the net interest rate spread to compress, depending on the level and type of changes in the interest rate environment. Interest rates are highly sensitive to many factors that are beyond our control, including general economic conditions and the policies of various governmental agencies. In addition, some of our customers often have the ability to prepay loans or redeem deposits with either no penalties or penalties that are insufficient to compensate us for the lost income. A significant reduction in our net interest income will adversely affect our business and results of operations. If we are unable to manage interest rate risk effectively, our business, financial condition and results of operations could be materially impacted.
Declines in the value of investment securities held by us could require write-downs which may adversely affect our financial condition and results of operations.
In order to diversify earnings and enhance liquidity, we own debt instruments of the U.S. government, U.S. government agencies and U.S. municipalities. We may be required to record impairment charges on our debt securities if they suffer a decline in value due to the underlying credit of the issuer. Additionally, the value of these investments may fluctuate depending on the interest rate environment, general economic conditions and circumstances specific to the issuer. Volatile market conditions may detrimentally affect the value of these securities, such as through reduced valuations due to the perception of heightened credit or liquidity risks. Changes in the value of these instruments may result in a reduction to earnings and/or capital which may adversely affect our results of operations and financial condition.
24
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Risks Related to Regulatory Compliance and Legal Matters
We are subject to extensive governmental regulation and supervision.
As discussed above, under "Supervision and Regulation" in Item 1, we are subject to extensive state and federal regulation, supervision and legislation that govern nearly every aspect of our operations. The regulations are primarily intended to protect depositors, customers and the banking system as a whole, not shareholders. These regulations affect our lending practices, capital structure, investment practices, dividend policy and growth, among other things. Congress and federal regulatory agencies continually review banking laws, regulations and policies for possible changes. The Dodd-Frank Act, enacted in July 2010, instituted major changes to the banking and financial institutions regulatory regimes. Other changes to statutes, regulations or policies could affect us in substantial and unpredictable ways. Any regulatory changes could subject us to additional costs of regulatory compliance and of doing business, limit the types of financial services and products we may offer and/or increase the ability of non-banks to offer competing financial services and products, among other things, and could divert management’s time from other business activities. Failure to comply with applicable laws, regulations, policies or supervisory guidance could lead to enforcement and other legal actions by federal or state authorities, including criminal or civil penalties, the loss of FDIC insurance, the revocation of a banking charter, other sanctions by regulatory agencies and/or damage to our brand. The ramifications and uncertainties of the level of government intervention and regulatory changes in the U.S. financial system could also adversely affect us. Failure to comply with the different or additional regulations could further adversely affect us.
As we grow, the heightened expectations of regulatory agencies may expose us to additional regulatory risk and compliance costs.
The regulations that we are subject to at this time are generally tailored to institutions with less than $10 billion in total consolidated assets. Should our total consolidated assets exceed the $10 billion threshold, we would be subject to additional regulatory requirements and supervisory oversight applicable to larger institutions. These requirements are intended to enhance risk management, governance and compliance frameworks and may include minimum standards for the design and implementation of the risk management framework and heightened requirements relating to enterprise risk management, board oversight, data governance, compliance management systems, internal audit, vendor oversight and cybersecurity controls, as well as increased regulatory scrutiny from our primary federal and state banking regulators. In addition, institutions with $10 billion or more in total consolidated assets are subject to supervision and examination by the CFPB with respect to applicable federal consumer financial laws and, beginning July 1 of the year following the calendar year in which the threshold is exceeded, to limitations on debit card interchange fees under the Durbin Amendment (subject to applicable exemptions). Deposit insurance assessment methodologies may also differ for institutions above this asset threshold.
The regulatory framework applicable to institutions above the $10 billion threshold is subject to ongoing rulemaking activity and supervisory calibration. Certain rules and standards applicable to larger institutions have been proposed, modified, delayed or challenged in court, and federal agencies have signaled an intent in some areas to streamline or tailor supervisory expectations. The timing, scope and ultimate impact of regulatory requirements applicable to institutions above the $10 billion threshold therefore remain subject to change. This evolving environment may create uncertainty in our compliance planning, capital allocation and operational investments and may require us to modify systems, policies and staffing as regulatory expectations develop. While we have taken steps to enhance our risk management and compliance infrastructure in anticipation of future growth, our existing enterprise risk framework and related systems may not be fully scalable to meet applicable expectations without significant additional investment. We may be required to incur substantial costs to upgrade systems, enhance internal controls and hire or train personnel with specialized expertise. Failure to effectively implement and maintain required controls could subject us to increased supervisory scrutiny, enforcement actions or civil penalties which could materially and adversely affect our business, financial condition, results of operations, reputation and ability to pursue strategic growth initiatives.
Our controls and policies and procedures may fail or be circumvented which may result in a material adverse effect on our business, financial condition and results of operations.
Management regularly reviews and updates our internal controls, disclosure controls and procedures and operating, risk management and corporate governance policies and procedures. Any system of controls, policies and procedures, however well designed and operated, is based in part on certain assumptions and can provide only reasonable, not absolute, assurances that the objectives of the system are met. Furthermore, our risk management framework is subject to inherent limitations and risks may exist, or develop in the future, that we have not identified or anticipated. Any failure or circumvention of internal controls, disclosure controls and procedures, or operating, risk management and corporate governance policies and procedures, whether as a result of human error, misconduct or malfeasance, or failure to comply with regulations related to controls and policies and procedures could have a material adverse effect on our business, results of operations and financial condition.
25
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Furthermore, we may in the future discover areas of our internal controls, disclosure controls and procedures, or operating, risk management and corporate governance policies and procedures that need improvement. Failure to maintain effective controls or to timely implement any necessary improvement of our internal and disclosure controls, or operating, risk management and corporate governance policies and procedures, could, among other things, result in losses from errors, harm our brand, or cause investors to lose confidence in our reported financial information, all of which could have a material adverse effect on our results of operations and financial condition.
Negative public opinion could damage our brand and adversely impact our results of operations and liquidity.
Brand impacts to strategic risk, including the risk to our business, earnings, liquidity and capital from negative public opinion, is inherent in our operations. Negative public opinion could result from our actual or alleged conduct in a variety of areas, including legal and regulatory compliance, lending practices, corporate governance, cybersecurity incident or breach, failures by third parties whom we interact with, litigation, ethical issues or inadequate protection of customer information. Financial companies are highly vulnerable to brand damage when they are found to have harmed customers, particularly retail customers, through conduct that is illegal or viewed as unfair, deceptive, manipulative or otherwise wrongful. We are dependent on third-party providers for a number of services that are important to our business. Refer to the risk factor titled, “We rely on certain critical third-party providers for a number of services that are important to our business. An interruption or cessation of an important service by any third-party provider could have a material adverse effect on our business.” for additional information. A failure by any of these third-party service providers could cause a disruption in our operations which could result in negative public opinion about us or damage to our brand. We expend significant resources to comply with regulatory requirements, and the failure to comply with such regulations could result in brand harm or significant legal or remedial costs. Damage to our brand could adversely affect our ability to retain and attract new customers and employees, expose us to litigation and regulatory action and adversely impact our results of operations and liquidity.
Our ability to pay dividends on our common stock may be limited.
Holders of our common stock will be entitled to receive only such dividends as our Board of Directors may declare out of funds legally available for such payments. The payment of common stock dividends by S&T is subject to certain requirements and limitations of Pennsylvania law. Although we have historically declared cash dividends on our common stock, we are not required to do so and our Board of Directors could reduce, suspend or eliminate our dividend at any time. Substantial portions of our revenue consist of dividend payments we receive from S&T Bank. The payment of common dividends by S&T Bank is subject to certain requirements and limitations under federal and state laws and regulations that limit the amount of dividends it can pay to S&T. In addition, both S&T and S&T Bank are subject to various general regulatory policies relating to the payment of dividends, including requirements to maintain adequate capital above regulatory minimums. Any decrease to or elimination of the dividends on our common stock could adversely affect the market price of our common stock.
Our business could be negatively impacted by complex, evolving, and conflicting environmental, social and governance, or ESG, regulations and expectations, including climate change and related legislative and regulatory initiatives.
Certain federal actions have created a complex environment with respect to ESG. Navigating the varying expectations of policy makers and other stakeholders may expose us to negative publicity, shareholder or other stakeholder engagement or potential enforcement or investigation by regulatory authorities, each of which could have an adverse impact on our business.
Although federal bank regulators have rescinded some prior ESG guidance and policies, new guidance and policies may be implemented in the future. Failure to adapt to or comply with regulatory requirements or investor or stakeholder expectations and standards with respect to ESG matters or failure to successfully manage varied stakeholder expectations could have a material adverse impact on our future results of operations, financial condition, cash flows, ability to do business with certain third parties and our stock price.
26
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Risks Related to Liquidity
We rely on a stable core deposit base as our primary source of liquidity.
We are dependent for our funding on a stable base of core deposits. Our ability to maintain a stable core deposit base is a function of our financial performance, our brand and the security provided by FDIC insurance, which combined, gives customers confidence in us. If any of these considerations deteriorates, the stability of our core deposits could be harmed. Customers are also focused on the amount of deposit account balances that we hold in excess of FDIC insurance limits. As a result, they may decide to withdraw deposits in excess of these limits. In addition, deposit levels may be affected by factors such as general interest rate levels, rates paid by competitors, returns available to customers on alternative investments and general economic conditions. Accordingly, we may be required from time to time to rely on other sources of liquidity to meet withdrawal demands or otherwise fund operations. Additional funding sources accessible to S&T include borrowing availability through the Federal Reserve Borrower-in-Custody Program, the FHLB, federal funds lines with other financial institutions and brokered deposits.
Our ability to meet contingency funding needs, in the event of a crisis that causes a disruption to our core deposit base, is dependent on access to wholesale markets, including funds provided by the FHLB of Pittsburgh, Federal Reserve Borrower-in-Custody Program and other short-term funding sources, including brokered deposits.
We own stock in the FHLB, in order to qualify for membership in the FHLB system which enables us to borrow on our line of credit that is secured by a blanket lien on a significant portion of our loan portfolio. Changes or disruptions to the FHLB or the FHLB system in general may materially impact our ability to meet short- and long-term liquidity needs or meet growth plans. Additionally, we cannot be assured that the FHLB will be able to provide funding to us when needed, nor can we be certain that the FHLB will provide funds specifically to us, should our financial condition and/or our regulators prevent access to our line of credit. We have other funding sources that can be used such as the Federal Reserve Borrower-in-Custody Program and brokered deposits. The inability to access this source of funds could have a materially adverse effect on our ability to meet our customer’s needs. Our financial flexibility could be severely constrained if we were unable to maintain our access to funding or if adequate financing is not available at acceptable interest rates.
Risks Related to Owning Our Stock
The market price of our common stock may fluctuate significantly in response to a number of factors.
Our quarterly and annual operating results have varied significantly in the past and could vary significantly in the future which makes it difficult for us to predict our future operating results. Our operating results may fluctuate due to a variety of factors, many of which are outside of our control, including the changing U.S. economic environment and changes in the commercial and residential real estate market, any of which may cause our stock price to fluctuate. If our operating results fall below the expectations of investors or securities analysts, the price of our common stock could decline substantially. Additionally, our stock price can fluctuate significantly in response to a variety of factors including, among other things:
•volatility of stock market prices and volumes in general;
•changes in market valuations of similar companies;
•the nature and composition of our ownership base;
•investor views on the attractiveness of a given sector in the market;
•the flow of capital among market sectors;
•changes in the conditions of credit markets;
•changes in accounting policies or procedures as required by the Financial Accounting Standards Board, or FASB, or other regulatory agencies;
•legislative and regulatory actions, including the impact of the Dodd-Frank Act and related regulations, that may subject us to additional regulatory oversight which may result in increased compliance costs and/or require us to change our business model;
•government intervention in the U.S. financial system and the effects of and changes in trade and monetary and fiscal policies and laws, including the interest rate policies of the Federal Reserve;
•additions or departures of key members of management;
•fluctuations in our quarterly or annual operating results; and
•changes in analysts’ estimates of our financial performance.
27
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
General Risk Factors
We may be a defendant from time to time in a variety of litigation and other actions which could have a material adverse effect on our financial condition and results of operations.
From time to time, customers and others make claims and take legal action pertaining to the performance of our responsibilities. Whether customer claims and legal action related to the performance of our responsibilities are founded or unfounded, if such claims and legal actions are not resolved in a manner favorable to us, they may result in significant expenses, attention from management and financial liability. Any financial liability or brand damage could have a material adverse effect on our business which in turn could have a material adverse effect on our financial condition and results of operations.
Item 1B. UNRESOLVED STAFF COMMENTS
There are no unresolved SEC staff comments.
Item 1C. CYBERSECURITY
Risk Management and Strategy
S&T’s Information Security Program provides policies, procedures, controls and technical measures to assess, identify and manage material cybersecurity risks. The Information Security Program is a part of S&T’s overall Enterprise Risk Management, or ERM Program. The Information Security Program is designed to achieve the following objectives:
•protecting data through the use of automated and manual processes;
•periodically assessing and updating the program to address an evolving threat environment;
•maintaining a team of IT security professionals that continually monitor, detect, analyze, investigate and report cybersecurity threats; and
•ensuring business continuity and disaster recovery.
We based and tailored our framework on the National Institute of Standards and Technology, or NIST, Cybersecurity Framework and the Center for Internet Security, or CIS, Critical Security Controls.
The S&T Information Security Program utilizes a defense in depth strategy that leverages multiple security measures to protect the bank's assets. We encrypt and leverage data loss prevention technology for sensitive data and use advanced transport layer security encryption for our applications. S&T employees are required to undergo annual information security awareness training which includes information regarding evolving threats such as phishing, malware and social engineering testing.
S&T performs periodic risk assessments that seek to identify both technical and physical risks to information systems. The assessments incorporate cybersecurity-related principles from the Federal Financial Institutions Examination Council, or FFIEC, Information Technology Examination Handbook, regulatory guidance and concepts from other industry standards, including the NIST Cybersecurity Framework. An assessment typically includes:
•identifying reasonably foreseeable internal and external threats that could result in a cybersecurity incident;
•assessing the likelihood and potential impact of those threats; and
•assessing the sufficiency of policies, procedures, practices and technical measures in place to manage risks.
In addition to periodic risk assessments, S&T evaluates changes to IT systems or physical systems for any information security impacts. S&T utilizes staff and independent third parties to conduct annual penetration testing and IT security health assessments. We engage third parties to facilitate tabletop incident response and business continuity exercises. Additionally, we participate in various cybersecurity industry forums and have access to law enforcement analysis regarding current threats.
Our third-party risk management program is integrated into our Information Security Program within our ERM Program. The policies, procedures and practices applicable to the cybersecurity components of the third-party risk management program were developed and are maintained consistent with the FFIEC IT Examination Handbook, as well as guidance from our prudential regulators. We perform a risk assessment, including cyber threats, associated with use of third-party vendors and exercise appropriate due diligence before entering into a vendor arrangement. We also engage a third party to actively monitor our cybersecurity risks and gather threat intelligence of select vendors and their products and services. Additionally, we conduct information security assessments before sharing or allowing the hosting of sensitive data in computing environments managed by third parties. Our contracts governing third party engagements require certain security and privacy protections where applicable. All third parties with access to our information systems must review and acknowledge our Acceptable Use Policy before access is granted.
When a cybersecurity incident occurs, whether detected internally or from third-party cybersecurity incidents, we evaluate the incident for criticality across a range of contributing indicators, including service availability, impact to operations, and brand, regulatory and legal considerations, data sensitivity and direct financial impact. The potential impact of the incident, individually or in aggregate, is evaluated by the Chief Security Officer, or CSO, continuously across these criteria. We have
28
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
escalation procedures to notify members of senior and executive management, the Board (or an applicable subset) and regulators in a timely manner based on the criticality of the cybersecurity incident. S&T also has in place incident response and business continuity plans. The Incident Response Program outlines the policies, procedures and technical measures for identifying an incident, assessing its nature and scope, minimizing and containing the impact, investigating the root cause and reporting, as applicable. S&T uses data from incidents to reassess risk, evaluate and implement any additional controls deemed necessary and measure the success of the incident response team. The Incident Response Program also includes staff training, annual updates and testing. The Business Continuity Plan defines the policies, procedures and technical measures to restore systems and critical operations. S&T also maintains business continuity plans for critical systems and applications managed or hosted by third-party vendors.
To date, risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. We may nevertheless be unsuccessful in the future in preventing or mitigating a cybersecurity incident that could have a material impact on our business, results of operations or financial condition. At December 31, 2025, management has assessed known cybersecurity incidents for potential materiality and disclosure using formal documented processes and has determined that there have been no material cybersecurity incidents, individually or in aggregate.
Governance
Board Oversight
The Risk Committee is appointed by the Board and is authorized to perform its functions in assisting the Board with fulfilling its fiduciary responsibilities with respect to its oversight and assessment of S&T’s enterprise-wide risk management framework. The Risk Committee oversees risk from cybersecurity threats as a part of its oversight of the ERM Program. The Risk Committee regularly reviews reports from, and has discussions with, S&T’s Chief Risk Officer, or CRO, Chief Operating Officer, or COO, Chief Information Officer, or CIO, CSO, and Director of Operational Risk Management regarding cybersecurity risks, the threat landscape, updates on incidents and reports on our investments in cybersecurity risk mitigation and governance. The Risk Committee chairperson reports activities and recommendations with respect to such matters to the Board as are relevant and deemed appropriate by the Risk Committee. In the event of a material cybersecurity event, the CSO is responsible for promptly reporting such incidents to the CRO, executive management and the Board. A special meeting of the Board will be held, as deemed necessary by the Chairperson of the Board in consultation with the Chair of the Risk Committee.
Management’s Role
At the management level, the ERM Committee, CRO, COO, CIO, CSO and Director of Operational Risk Management are responsible for assessing and managing material risks from cybersecurity threats. The ERM Committee reports information to the Risk Committee on a quarterly basis, or more often as needed.
Risk Management leadership, which assists the ERM Committee in assessing and managing cybersecurity threats, include our CRO, COO, CIO, CSOand Director of Operational Risk Management. Our CRO who oversees the risk management information security program reports to our CEO, but has direct access to the Risk Committee.Our CRO is a Certified Public Accountant, holds a Certification in Risk Management Assurance and has over 25 years of financial services experience. Our COO has over 20 years of banking technology and operations experience, including serving as head of digital for a business unit at a large national bank. Our CSO reports to the CRO and has 18 years of information technology and cybersecurity experience, including prior roles as chief information officer, assistant director of information technology, chief information security officer and chief security officer in federal law enforcement and banking organizations. Our CIO has over 25 years of financial services, information technology, cybersecurity and emerging technologies experience. Our Director of Operational Risk Management has over 25 years of information technology and cybersecurity experience, including serving as a former chief information officer for a financial institution.
For more information regarding the risks associated with cybersecurity that may impact our business strategy, results of operations or financial condition, see “ Part I, “Item 1A. Risk Factors” of this Annual Report on Form10-K.
Item 2. PROPERTIES
S&T Bancorp, Inc. headquarters is located in Indiana, Pennsylvania. We operate in Pennsylvania and Ohio. At December 31, 2025, we operate 72 banking branches and three loan production offices, of which 41 are leased facilities.
29
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Item 3. LEGAL PROCEEDINGS
The nature of our business generates a certain amount of litigation that arises in the ordinary course of business. However, in management’s opinion, there are no proceedings pending that we are a party to or to which our property is subject that would be material in relation to our financial condition or results of operations. In addition, no material proceedings are pending nor are known to be threatened or contemplated against us by governmental authorities or other parties.
Item 4. MINE SAFETY DISCLOSURES
Not applicable.
30
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
PART II
Item 5. MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED SHAREHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
Stock Information
Our common stock is listed on the NASDAQ Global Select Market System, or NASDAQ, under the symbol STBA. As of the close of business on February 24, 2026 we had approximately 2,194 shareholders of record. The number of record-holders does not reflect the number of persons or entities holding stock through mutual funds, exchange traded funds or in nominee name through banks, brokerage firms and other nominees.
Dividends
As discussed under "Our ability to pay dividends on our common stock may be limited." included in Item 1A. Risk Factors in Part I, the amount and timing of dividends is subject to the discretion of the Board and depends upon business conditions and regulatory requirements. The Board has the discretion to change the dividend at any time for any reason. The Board of Directors presently intends to continue the policy of paying quarterly cash dividends. The amount of any future dividends will depend on economic and market conditions, our financial condition and operating results and other factors, including applicable government regulations and policies. S&T’s Board of Directors approved a quarterly cash dividend of $0.36 per share on January 28, 2026.
Securities Authorized for Issuance under Equity Compensation Plans
Certain information relating to securities authorized for issuance under equity compensation plans is set forth under the heading Equity Compensation Plan Information in Part III, Item 12 Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters of this Report.
Purchases of Equity Securities
On May 13, 2025, our Board of Directors authorized an extension of its $50 million share repurchase plan. The new repurchase authorization will expire July 31, 2026. This repurchase authorization permits S&T to repurchase shares of S&T's common stock from time to time through a combination of open market and privately negotiated repurchases up to the authorized $50 million aggregate value of S&T's common stock. The specific timing, price and quantity of repurchases will be at the discretion of S&T and will depend on a variety of factors, including general market conditions, the trading price of the common stock, legal and contractual requirements and S&T’s financial performance. The repurchase plan does not obligate S&T to repurchase any particular number of shares. S&T expects to fund any repurchases from cash on hand and internally generated funds. Any share repurchases will not begin until permissible under applicable laws. The following table is a summary of our purchases of common stock during the fourth quarter of 2025:
(1)Excludes excise tax and commissions.
On January 22, 2026, our Board of Directors authorized a new $100 million share repurchase program which replaced the existing share repurchase program effective January 26, 2026 and is set to expire February 1, 2027. The remaining capacity of $13.8 million under the existing share repurchase program was terminated. The new program authorizes the share repurchase of S&T's common stock from time to time through a combination of open market and privately negotiated transactions up to the authorized $100 million aggregate value of S&T's common stock. The specific timing, price and quantity of repurchases will be at the discretion of S&T and will depend on a variety of factors, including general market conditions, the trading price of the common stock, applicable securities laws and other legal and contractual requirements, as well as S&T’s financial performance. The repurchase program does not obligate S&T to repurchase any particular number of shares and may be extended, modified or discontinued at any time. As of February 25, 2026, 856,900 shares were repurchased under the new plan, at an average price of $43.45, for $37.2 million.
31
Table of Contents
S&T BANCORP, INC. AND SUBSIDIARIES
Five-Year Cumulative Total Return