|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management Strategy And Governance [Abstract]
|Cybersecurity Risk Management Processes For Assessing Identifying And Managing Threats [Text Block]
|
Risk Management and Strategy
We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats, including risks relating to disruption of business operations or financial reporting systems, intellectual property theft, fraud, extortion harm to employees or customers, violation of privacy laws and other litigation and legal risk, and reputational risk, as part of our overall risk management system and processes. Cybersecurity risks are considered in the risk management annual reports submitted to the Audit Committee.
Key components of our cybersecurity risk management processes include the following:
Additionally, in connection with our cybersecurity risk management processes, our internal experts perform several tests aimed to validate the effectiveness of the cybersecurity risk management processes.
We engage with external legal counsel on any matters relating to cybersecurity risk management, and also engage third-parties to provide trainings or to facilitate tabletop exercises.
Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previous cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks and any future material incidents See “Risk Factors” in Item 3 of this Annual Report on Form 20-F for more information on our cybersecurity related risks.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats, including risks relating to disruption of business operations or financial reporting systems, intellectual property theft, fraud, extortion harm to employees or customers, violation of privacy laws and other litigation and legal risk, and reputational risk, as part of our overall risk management system and processes. Cybersecurity risks are considered in the risk management annual reports submitted to the Audit Committee.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight And Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected Or Reasonably Likely To Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board Of Directors Oversight [Text Block]
|
Board of Directors
The board of director’s Audit Committee is primarily responsible for the oversight of risks from cybersecurity threats, as well as for the review and approval of cybersecurity-related policies. The Audit Committee has decided to retain the oversight of risks in connection with cybersecurity threats, due to the importance of cybersecurity-related risks to our stakeholders.
To fulfill this responsibility, the Audit Committee receives reports about cybersecurity incidents. Additionally, on a quarterly basis the Audit Manager and the external audit associate report to the Audit Committee any relevant cybersecurity risks and incidents identified during the relevant period. Finally, as part of the annual risk assessment, the Audit Committee reviews and approves the cybersecurity processes.
|Cybersecurity Risk Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process For Informing Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|To fulfill this responsibility, the Audit Committee receives reports about cybersecurity incidents. Additionally, on a quarterly basis the Audit Manager and the external audit associate report to the Audit Committee any relevant cybersecurity risks and incidents identified during the relevant period.
|Cybersecurity Risk Role Of Management [Text Block]
|
The cybersecurity risk management processes described above are conducted by the IT Manager and Chief Information Security Officer CISO, who is graduated in computer science and has a masters in information technology. Additionally, he has obtained several international certifications, including Certified Information Systems Auditor (CISA) from ISACA, Certified Information Systems Security Professional (CISSP) from ISC2, and Certified Ethical Hacker (C|EH) and Certified Hacking Forensic Investigator (CHFI) from EC-Council. He has more than 30 years of experience in information technology areas, focused on cybersecurity and systems auditing.
|Cybersecurity Risk Management Positions Or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions Or Committees Responsible [Text Block]
|IT Manager and Chief Information Security Officer CISO, who is graduated in computer science and has a masters in information technology. Additionally, he has obtained several international certifications, including Certified Information Systems Auditor (CISA) from ISACA, Certified Information Systems Security Professional (CISSP) from ISC2, and Certified Ethical Hacker (C|EH) and Certified Hacking Forensic Investigator (CHFI) from EC-Council. He has more than 30 years of experience in information technology areas, focused on cybersecurity and systems auditing.
|Cybersecurity Risk Management Expertise Of Management Responsible [Text Block]
|Chief Information Security Officer
|Cybersecurity Risk Process For Informing Management Or Committees Responsible [Text Block]
|
Additionally, there is a cybersecurity committee comprised of the Chief Executive Officer, Legal director, Audit Manager and IT Manager. This committee meets every time there is a cybersecurity incident that impacts the Company and is in charge of performing a materiality analysis of such cybersecurity incidents, taking into consideration the scope, cost, operational/commercial impact, regulatory compliance, legal and reputational impact, among others.
|Cybersecurity Risk Management Positions Or Committees Responsible Report To Board [Flag]
|true
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.