XML 22 R7.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management, Strategy, and Governance
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Item 1C. Cybersecurity.

Innovex maintains a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats. The underlying controls of the cyber risk management program are based on recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) and the Cybersecurity Framework. Innovex has an annual assessment, performed by a third party, of the Company’s cyber risk management program against the NIST Cybersecurity Framework. Innovex contracts a Cyber Security Operations Center operating in three locations to provide 24/7 monitoring of its global cybersecurity environment and to coordinate the investigation and remediation of alerts. An annual incident response drill is in place to prepare support teams in the event of a significant incident. Cyber partners are a key part of Innovex’s cybersecurity infrastructure. Innovex partners with leading cybersecurity companies and organizations, leveraging third-party technology and expertise. Innovex engages with these partners to monitor and maintain the performance and effectiveness of products and services that are deployed in Innovex’s environment.

Innovex’s VP of IT reports to Innovex’s Chief Financial Officer and is the head of the Company’s cybersecurity team. The VP of IT is responsible for assessing and managing Innovex’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts. The cybersecurity team has decades of experience selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants engaged by Innovex. The Audit Committee of the board of directors oversees Innovex’s cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks. The IT department briefs the Audit Committee on the effectiveness of Innovex’s cyber risk management program, typically on a semiannual basis. In addition, cybersecurity risks are reviewed by the Innovex board of directors, at least annually, as part of the Company’s corporate risk mapping exercise. Innovex faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation. Innovex has experienced, and will continue to experience, cyber incidents in the normal course of its business. However, prior cybersecurity incidents have not had a material adverse effect on Innovex’s business, financial condition, results of operations, or cash flows. See “Item 1A. Risk Factors—Risks Related to Technology Advancement—We are subject to cyber security risks. A cyber incident could occur and result in information theft, data corruption, operational disruption and/or financial loss” and “Item 1A. Risk Factors—Risks Related to Technology Advancement—We have experienced IT system disruptions and cyber attacks in the past, and a failure of our IT infrastructure and cyber attacks could adversely impact us in the future.”

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Innovex maintains a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] Innovex faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation.
Cybersecurity Risk Board of Directors Oversight [Text Block]

Innovex’s VP of IT reports to Innovex’s Chief Financial Officer and is the head of the Company’s cybersecurity team. The VP of IT is responsible for assessing and managing Innovex’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts. The cybersecurity team has decades of experience selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants engaged by Innovex. The Audit Committee of the board of directors oversees Innovex’s cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks. The IT department briefs the Audit Committee on the effectiveness of Innovex’s cyber risk management program, typically on a semiannual basis. In addition, cybersecurity risks are reviewed by the Innovex board of directors, at least annually, as part of the Company’s corporate risk mapping exercise. Innovex faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation. Innovex has experienced, and will continue to experience, cyber incidents in the normal course of its business. However, prior cybersecurity incidents have not had a material adverse effect on Innovex’s business, financial condition, results of operations, or cash flows. See “Item 1A. Risk Factors—Risks Related to Technology Advancement—We are subject to cyber security risks. A cyber incident could occur and result in information theft, data corruption, operational disruption and/or financial loss” and “Item 1A. Risk Factors—Risks Related to Technology Advancement—We have experienced IT system disruptions and cyber attacks in the past, and a failure of our IT infrastructure and cyber attacks could adversely impact us in the future.”

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee of the board of directors oversees Innovex’s cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The IT department briefs the Audit Committee on the effectiveness of Innovex’s cyber risk management program, typically on a semiannual basis. In addition, cybersecurity risks are reviewed by the Innovex board of directors, at least annually, as part of the Company’s corporate risk mapping exercise.
Cybersecurity Risk Role of Management [Text Block] The IT department briefs the Audit Committee on the effectiveness of Innovex’s cyber risk management program, typically on a semiannual basis. In addition, cybersecurity risks are reviewed by the Innovex board of directors, at least annually, as part of the Company’s corporate risk mapping exercise. Innovex faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The VP of IT is responsible for assessing and managing Innovex’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The cybersecurity team has decades of experience selecting, deploying, and operating cybersecurity technologies, initiatives, and processes around the world, and relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants engaged by Innovex.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The VP of IT is responsible for assessing and managing Innovex’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true