|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
We have implemented a cybersecurity program to assess, identify, mitigate and manage risks from cybersecurity threats that may result in material adverse effects on the confidentiality, integrity, and availability of our information systems. As part of this program, we have processes in place that include a variety of controls, systems, and technologies designed to prevent or mitigate data loss, theft, misuse, or other cybersecurity incidents affecting the data we collect, process, store, and transmit as part of our business. We conduct penetration testing and cybersecurity audits, and require all employees to undertake data
protection and cybersecurity training on an annual basis. We also use systems and processes designed to oversee and identify risks associated with our use of third-party service providers, including with respect to the occurrence of a cybersecurity incident at a third-party service provider or that otherwise implicates a third-party technology or system we use. We contract cybersecurity specialists to review and implement controls and structural mechanisms in order to enhance our cybersecurity program, and protect against and detect cybersecurity threats.
To our knowledge, we have not experienced any risks from cybersecurity threats or incidents through the date of this annual report that have materially affected or are reasonably likely to materially affect the Company, its business strategy, results of operation or financial condition. This does not guarantee that future incidents or threats will not have a material impact or that we are not currently the subject of an undetected incident or threat that may have such an impact. In particular, sophisticated nation state actors have targeted critical infrastructure, and may continue to do so in the future.
Additional information on cybersecurity risks we face is discussed in “Risk Factors” in Item 1A, which should be read in conjunction with the foregoing information.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have implemented a cybersecurity program to assess, identify, mitigate and manage risks from cybersecurity threats that may result in material adverse effects on the confidentiality, integrity, and availability of our information systems. As part of this program, we have processes in place that include a variety of controls, systems, and technologies designed to prevent or mitigate data loss, theft, misuse, or other cybersecurity incidents affecting the data we collect, process, store, and transmit as part of our business. We conduct penetration testing and cybersecurity audits, and require all employees to undertake dataprotection and cybersecurity training on an annual basis.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Board of Directors
The Board of Directors (“the Board”) has delegated the primary responsibility to oversee risks from cybersecurity threats to the Audit Committee. The Board and Audit Committee periodically review the measures implemented by the Company to identify and mitigate data protection and cybersecurity risks. The Board and Audit Committee are updated on a quarterly basis by Vice President, Corporate Services on the Company’s internal information technology (“IT”) security testing, any unauthorized attempts to access the Company’s network, any significant developments in cyber security risks and threats, and updates on the Company’s policies and procedures for protecting the Company’s data. We also have processes by which certain cybersecurity incidents are escalated within the Company and, where appropriate, reported in a timely manner to the Board and Audit Committee. All incidents are reported to the Executive Officers (including the President and Chief Executive Officer, Chief Financial Officer and the Chief Operating Officer) who assess the severity and what measures and procedures are necessary.
As part of the Company’s enterprise risk management, the Board of the Company receives, reviews and assesses reports from the Board’s committees and from management relating to enterprise-level risks. The Audit Committee reports its cybersecurity risk assessments to the full Board at each regularly scheduled Board meeting.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board of Directors (“the Board”) has delegated the primary responsibility to oversee risks from cybersecurity threats to the Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Executive Officers and Executive Vice President, Corporate Services are involved in all significant and appropriate cybersecurity decisions on the implementation and design of our IT architecture. Executive Vice President, Corporate Services, along with support from the Director of IT, is responsible for the assessment and management of risks from cybersecurity threats and oversees the implementation of IT processes, which includes cybersecurity, into the core business of the Company. The Director of IT has extensive cybersecurity knowledge and skills gained from over 20 years of relevant work experience. The Director of IT discusses all potential changes to the Company’s controls or detection systems with the Executive Vice President, Corporate Services prior to implementation. The Executive Vice President, Corporate Services is updated by the Director of IT on a periodic basis regarding trends in technology and cybersecurity threats or any potential changes to the Company’s cybersecurity program.
|Cybersecurity Risk Role of Management [Text Block]
|
ManagementThe Executive Officers and Executive Vice President, Corporate Services are involved in all significant and appropriate cybersecurity decisions on the implementation and design of our IT architecture. Executive Vice President, Corporate Services, along with support from the Director of IT, is responsible for the assessment and management of risks from cybersecurity threats and oversees the implementation of IT processes, which includes cybersecurity, into the core business of the Company. The Director of IT has extensive cybersecurity knowledge and skills gained from over 20 years of relevant work experience. The Director of IT discusses all potential changes to the Company’s controls or detection systems with the Executive Vice President, Corporate Services prior to implementation. The Executive Vice President, Corporate Services is updated by the Director of IT on a periodic basis regarding trends in technology and cybersecurity threats or any potential changes to the Company’s cybersecurity program. The Director of IT is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents through a number of experienced direction systems and third party cybersecurity providers. The Executive Vice President, Corporate Services also attends certain meetings of the Audit Committee to report information on material risks from cybersecurity threats. None of our critical core business activities that impact production, transportation or sales of oil and gas are remotely controlled.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Executive Officers and Executive Vice President, Corporate Services are involved in all significant and appropriate cybersecurity decisions on the implementation and design of our IT architecture. Executive Vice President, Corporate Services, along with support from the Director of IT, is responsible for the assessment and management of risks from cybersecurity threats and oversees the implementation of IT processes, which includes cybersecurity, into the core business of the Company.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Director of IT has extensive cybersecurity knowledge and skills gained from over 20 years of relevant work experience.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
ManagementThe Executive Officers and Executive Vice President, Corporate Services are involved in all significant and appropriate cybersecurity decisions on the implementation and design of our IT architecture. Executive Vice President, Corporate Services, along with support from the Director of IT, is responsible for the assessment and management of risks from cybersecurity threats and oversees the implementation of IT processes, which includes cybersecurity, into the core business of the Company. The Director of IT has extensive cybersecurity knowledge and skills gained from over 20 years of relevant work experience. The Director of IT discusses all potential changes to the Company’s controls or detection systems with the Executive Vice President, Corporate Services prior to implementation. The Executive Vice President, Corporate Services is updated by the Director of IT on a periodic basis regarding trends in technology and cybersecurity threats or any potential changes to the Company’s cybersecurity program. The Director of IT is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents through a number of experienced direction systems and third party cybersecurity providers. The Executive Vice President, Corporate Services also attends certain meetings of the Audit Committee to report information on material risks from cybersecurity threats. None of our critical core business activities that impact production, transportation or sales of oil and gas are remotely controlled.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef