XML 44 R25.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We have a cybersecurity risk management program to identify, monitor, and mitigate cybersecurity risks. The program consists of formal roles and responsibilities for information security and incident response, and is overseen by our IT Steering Committee, which consists of key executives and employees with guidance from our third-party cybersecurity vendor. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. In addition to continuous cyber monitoring,
the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.

The Audit Committee has ultimate oversight of cybersecurity risks and our cybersecurity risk management program. Management provides cybersecurity program briefings to the Audit Committee on at least an annual basis, and more frequently if circumstances warrant. These briefings include assessments of cyber risks, the threat landscape, updates on any incidents, and reports on our investments in cybersecurity risk mitigation and governance. Management utilizes the National Institute of Standards and Technology (NIST) Cybersecurity Framework as a guideline to manage our cybersecurity risks and inform the Audit Committee on the overall progress of our information security program.

We have a formal IT Security Policy to provide appropriate governance over information security including control requirements for change management and patching, multi-factor authentication, data backup, security monitoring, mobile device management and asset management. Management performs annual testing of security controls, including penetration testing from a different cybersecurity vendor that is independent of both our Company and the cybersecurity vendor that provides guidance on our overall cybersecurity program, and results are reported to the Audit Committee. In addition, management has a formal incident response plan and our cybersecurity vendor provides 24x7 monitoring/management of our infrastructure and systems. The incident response plan addresses the lifecycle of incidents including identification, response and recovery, and the plan is tested at least annually. In addition, we carry insurance that provides protection against the potential losses arising from cybersecurity incidents.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We have a cybersecurity risk management program to identify, monitor, and mitigate cybersecurity risks. The program consists of formal roles and responsibilities for information security and incident response, and is overseen by our IT Steering Committee, which consists of key executives and employees with guidance from our third-party cybersecurity vendor. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. In addition to continuous cyber monitoring,
the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
We have a cybersecurity risk management program to identify, monitor, and mitigate cybersecurity risks. The program consists of formal roles and responsibilities for information security and incident response, and is overseen by our IT Steering Committee, which consists of key executives and employees with guidance from our third-party cybersecurity vendor. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. In addition to continuous cyber monitoring,
the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee has ultimate oversight of cybersecurity risks and our cybersecurity risk management program.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Management provides cybersecurity program briefings to the Audit Committee on at least an annual basis, and more frequently if circumstances warrant.
Cybersecurity Risk Role of Management [Text Block]
We have a cybersecurity risk management program to identify, monitor, and mitigate cybersecurity risks. The program consists of formal roles and responsibilities for information security and incident response, and is overseen by our IT Steering Committee, which consists of key executives and employees with guidance from our third-party cybersecurity vendor. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. In addition to continuous cyber monitoring,
the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.

The Audit Committee has ultimate oversight of cybersecurity risks and our cybersecurity risk management program. Management provides cybersecurity program briefings to the Audit Committee on at least an annual basis, and more frequently if circumstances warrant. These briefings include assessments of cyber risks, the threat landscape, updates on any incidents, and reports on our investments in cybersecurity risk mitigation and governance. Management utilizes the National Institute of Standards and Technology (NIST) Cybersecurity Framework as a guideline to manage our cybersecurity risks and inform the Audit Committee on the overall progress of our information security program.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The program consists of formal roles and responsibilities for information security and incident response, and is overseen by our IT Steering Committee, which consists of key executives and employees with guidance from our third-party cybersecurity vendor.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] In addition to continuous cyber monitoring, the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true