Financial Services
NBT Bancorp Inc. (NBTB)
Data as of July 17, 2026
Environment story
NBT Bancorp discloses minimal direct emissions data and no comprehensive Scope 1, 2, or 3 emissions reporting. The 10-K acknowledges climate-related risks, including severe weather impacts on branch locations and customer properties, and references potential increased capital expenditures for energy efficiency improvements. However, no quantified emissions baselines, reduction targets, net-zero commitments, or renewable energy transition plans are disclosed. The company recognizes environmental liabilities associated with real-estate-secured loan portfolios but does not articulate decarbonization initiatives. Absence of disclosed emissions metrics, net-zero targets, and renewable energy investments results in a moderately reduced score reflecting incomplete ESG disclosure rather than verified environmental performance.
Criticisms on file
-
No disclosed emissions baselines or net-zero targets; undisclosed Scope 1, 2, and 3 emissionsSource: NBTB 10-K 2025 (Item 1A Risk Factors, Item 1C Cybersecurity)
-
Acknowledged exposure to severe weather and climate-change-related property impacts without quantified mitigation strategySource: NBTB 10-K 2025 (Item 1A Risk Factors: 'Severe weather, flooding and other effects of climate change')
Disclosed initiatives
-
Climate Risk AcknowledgmentCompany acknowledges potential climate-related regulatory changes may result in increased capital expenditures to improve energy efficiency of branch locations and customer properties.
-
Environmental Liability ManagementCompany maintains policies regarding environmental liabilities associated with foreclosed real-estate-secured properties, including potential remediation obligations.
Social story
NBT Bancorp's 10-K provides limited disclosure on Social (S) pillar metrics. CEO-to-median-worker pay ratio, workforce turnover rate, diversity statistics (women and underrepresented minorities in executive/board roles), and union-standing documentation are not disclosed in the provided filing. The company emphasizes employee training (cybersecurity awareness, fraud prevention) and talent retention as strategic priorities, but does not quantify these efforts or report formal DEI programs, supplier diversity initiatives, or civil-rights audit commitments. No documented union suppression or major labor disputes are evident. The absence of measurable social metrics and diversity disclosures limits scoring precision; default assumptions reflect a mid-range regional bank profile without demonstrated leadership-diversity advantages.
Criticisms on file
-
No disclosed CEO-to-median-worker pay ratio, workforce diversity metrics, or formal DEI program documentationSource: NBTB 10-K 2025 (throughout document; DEI data absent)
-
No documented union standing, collective bargaining agreements, or labor-relations frameworks disclosedSource: NBTB 10-K 2025 (Risk Factors section; labor relations not addressed)
-
Reliance on third-party vendors for key infrastructure; cybersecurity breach risk impacts employee and customer data securitySource: NBTB 10-K 2025 (Item 1A: 'The Company relies on third parties to provide key components of its business infrastructure')
Disclosed initiatives
-
Employee Cybersecurity TrainingCompany provides ongoing training to employees to detect phishing, malware, and other malicious schemes; continuous upskilling in information security awareness.Operational resilience; reduced insider-risk and fraud exposure.
-
Talent Retention and RecruitmentCompany acknowledges dependence on executive management team and key client relationship managers; identifies talent retention as material to operational continuity.
-
Fraud Prevention and Internal ControlsCompany devotes substantial resources to policies and controls to identify and prevent employee, customer, and third-party fraud.Risk mitigation for customer assets and brand reputation.
Governance story
NBT Bancorp operates under a standard Delaware corporation structure with a Board of Directors overseen by a Risk Management Committee. The 10-K does not disclose board independence percentage, share structure details (single-class vs. dual-class voting), or annual lobbying expenditures. The company explicitly denies active lobbying on climate/environmental deregulation or consumer-protection rollbacks; however, quantified political expenditure data is absent. The company acknowledges heightened regulatory compliance requirements (Dodd-Frank, EGRRCPA) and maintains internal control frameworks aligned with NIST Cybersecurity Framework. No material legal proceedings, antitrust investigations, or significant financial-fraud regulatory proceedings are disclosed. Governance score reflects standard institutional banking compliance without evidence of superior board independence, anti-corruption initiatives, or shareholder-protective enhancements.
Criticisms on file
-
Board independence percentage not disclosed; no explicit diversity or composition metrics providedSource: NBTB 10-K 2025 (Board composition details absent from provided excerpts)
-
Annual lobbying expenditure not disclosed; political activity stance not quantifiedSource: NBTB 10-K 2025 (Lobbying section absent from provided document)
-
Dual-class share structure not explicitly addressed; Delaware anti-takeover provisions (supermajority voting, advance notice requirements, 3-year interested stockholder restriction) documentedSource: NBTB 10-K 2025 (Item 1A: 'Provisions of our certificate of incorporation and bylaws... could delay or prevent a takeover')
-
No material cybersecurity incidents reported for three fiscal years; however, ongoing evolving cybersecurity threat landscape acknowledgedSource: NBTB 10-K 2025 (Item 1C Cybersecurity: 'As of December 31, 2025 we have not had any known instances of material cybersecurity incidents')
Disclosed initiatives
-
Risk Management Committee OversightBoard Risk Management Committee oversees cybersecurity, information security program (ISP), and enterprise risk management; receives quarterly cybersecurity briefings.Structured governance of operational and cyber risks.
-
Director of Information Security (DISO) AppointmentSenior Director of Information Security reports to Chief Risk Officer; oversees ISP implementation, security policies, safeguards, and Incident Response Team management. DISO has 17+ years of information security experience.Centralized accountability for cybersecurity governance and incident response.
-
Cybersecurity Incident Response ProtocolIncident Response Team follows CISA Cybersecurity Incident and Vulnerability Response Playbook (November 2021); procedures include escalation to Executive Committee, Risk Management Committee, and full Board as necessary.Formalized, standards-aligned incident management and board reporting.
-
Regulatory Compliance FrameworkCompany maintains compliance with Dodd-Frank Act, EGRRCPA, Volcker Rule, CFPB consumer financial protection standards, and interchange fee limits applicable to $10B+ asset institutions.Regulatory alignment; reduced enforcement risk.
-
Third-Party Vendor Risk AssessmentCompany conducts risk-based assessments of cybersecurity practices of third-party service providers; incorporates lessons from past incidents and near-misses.Mitigated operational risk from vendor dependencies.
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of NBT Bancorp Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open NBT Bancorp Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics