|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Our Cybersecurity Approach and Integration
We have implemented processes for overseeing and identifying material risks from cybersecurity threats, and our cybersecurity processes are integrated into the Company’s overall risk management system and processes. As part of management’s oversight of cybersecurity, Mark Clancy, our Senior Vice President, Cybersecurity, presents on our cybersecurity practices to the Nominating, Corporate Governance and Compliance Committee of our Board of Directors (the “NCGC Committee”) and to our full Board of Directors on a periodic basis. Our Chief Audit Executive periodically presents enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”). Our Chief Compliance Officer regularly attends meetings of the NCGC Committee to provide insights from the compliance perspective relating to cybersecurity.
Cyber risk management is a core component of the Company's governance structure. We utilize the National Institute of Standards and Technology’s Cybersecurity Framework as a guide in cyber risk management to identify, assess, and assist cybersecurity leadership in managing cybersecurity risks. Cyber risk management encompasses partnerships among teams that are responsible for cyber governance, prevention, detection, and remediation activities within the Company’s cybersecurity environment. As part of our cyber risk management efforts, we conduct periodic reviews and collaborate with enterprise-wide risk assessments to assess and manage cybersecurity risks. Our cybersecurity team also provides enterprise-wide cybersecurity training for employees to continuously improve our mitigation against human-driven vulnerabilities.
Our management also conducts a quarterly enterprise-wide risk assessment that considers a wide spectrum of risks facing the Company, including cybersecurity. Through these quarterly risk assessments, management informs the Audit Committee of the cyber risk landscape facing the Company and the Company’s preparedness to manage such risk. The enterprise-wide risk assessment is a top-down risk assessment that leverages the assessments performed by cyber risk management.
Engagement with External Experts
The Company engages top-tier external cybersecurity firms, as needed, leveraging their expertise as part of our ongoing effort to evaluate and enhance our cybersecurity program. They help with cyber defense capabilities (including staff enhancement of certain functions) and transformation to mitigate associated threats, reduce risk, enhance our cybersecurity posture, and meet the Company's evolving needs.
Oversight of Third-Party Service Providers
Our third-party risk management program includes processes for identifying and managing material cybersecurity risks arising from third-party providers. Our third-party risk management program actively engages with the enterprise-wide risk assessment process and partners with cyber risk management to report relevant risks to the NCGC Committee, the Audit Committee and our internal Enterprise Risk & Compliance Committee. Our third-party risk management program includes cybersecurity as an aspect of its risk assessment of third parties with the objective that key risks are identified and addressed. Moreover, the program also considers risks associated with certain fourth parties, entities that are partners or subcontractors of our direct third-party vendors, through assessments carried out by our third-party service providers.
Cybersecurity Incident Impact
As previously disclosed, in August 2021, we experienced a cybersecurity incident that resulted in numerous lawsuits, including mass arbitration claims and multiple class action lawsuits. In January 2023, we experienced another cybersecurity incident that also resulted in consumer class actions and regulatory inquiries. Legal and other costs related to these proceedings and inquiries, as well as any potential future actions, may be substantial, and losses associated with any adverse judgments, settlements, penalties or other resolutions of such proceedings and inquiries could be material to our business, reputation, financial condition, cash flows and operating results. For additional details regarding the impact of both cybersecurity incidents, see Note 18 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.
We have not identified other known risks from previous cybersecurity threats that have materially affected or are reasonably likely to materially affect us. However, we face ongoing risks from certain cybersecurity threats that, if realized, are reasonably likely to materially affect business strategy, financial condition or operating results. See “Risk Factors – We have experienced cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties whose products and services we rely on in operating our business.”
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We have implemented processes for overseeing and identifying material risks from cybersecurity threats, and our cybersecurity processes are integrated into the Company’s overall risk management system and processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|As previously disclosed, in August 2021, we experienced a cybersecurity incident that resulted in numerous lawsuits, including mass arbitration claims and multiple class action lawsuits. In January 2023, we experienced another cybersecurity incident that also resulted in consumer class actions and regulatory inquiries.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Disclosure of Management’s Responsibilities
Chief Information Officer
The Chief Information Officer is responsible for overseeing the Company’s information technology systems, digital capabilities, and cybersecurity practices. Mark Clancy, our Senior Vice President, Cybersecurity, under the direction of the Chief Information Officer, is responsible for overseeing the cybersecurity organization and promoting a security-centric culture throughout our business and operational functions. The Senior Vice President, Cybersecurity, is at the forefront of enhancing our cybersecurity framework and strengthening the overall cybersecurity program. This involves upgrading tools and capabilities, which are part of a broader, multi-year strategy to continue to enhance security measures. The Senior Vice President, Cybersecurity, oversees the cyber risk management function, which identifies cybersecurity threats, assesses cybersecurity risks and supports the Chief Information Officer and the Company in managing such risks.
As the Company’s Chief Information Officer, Jeff Simon has extensive experience in risk management and information security, including serving as the Chief Information Security Officer at Fidelity National Information Services, Inc. Mr. Simon received his Master of Science in Computer Science, Software Engineering & Artificial Intelligence from the Johns Hopkins Whiting School of Engineering and Bachelor of Science in Business Administration and Applied Economics from Marquette University. Mr. Simon is a Certified Information Systems Security Professional.
As the Company’s Senior Vice President, Cybersecurity, Mark Clancy has over 25 years of experience in information technology, information security, and cybersecurity, including serving as the Chief Information and Security Officer and Vice President of Cybersecurity and Fraud at Sprint Corporation. Mr. Clancy received his Bachelor of Science in Electrical and Electronics Engineering from Drexel University.
Enterprise Risk & Compliance Committee
Our Enterprise Risk & Compliance Committee is comprised of a collective of senior management representatives and subject matter experts from across the Company. The Enterprise Risk & Compliance Committee is chaired by the Chief Financial Officer of the Company, with the Chief Legal Officer and General Counsel as the co-chair and comprises core members including the Chief Information Officer, while the Senior Vice President, Cybersecurity, serves in an advisory capacity. The purpose of the Enterprise Risk & Compliance Committee is to oversee and govern the Company’s risk management, environmental, social, corporate governance, cybersecurity, and operational compliance activities, as well as provide a means of bringing risk issues to the attention of management. Specific to cybersecurity, the Chief Information Officer and the Senior Vice President, Cybersecurity, have the expertise to provide insights into the nature of cyber threats, the Company’s readiness, and actions taken to mitigate such risks.
Disclosure of the Board’s Roles and Responsibilities
Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NCGC Committee and Audit Committee and various executive roles. Additionally, our Chief Information Officer and Senior Vice President, Cybersecurity, report on cybersecurity to the full Board.
Nominating, Corporate Governance and Compliance Committee
The NCGC Committee oversees risks associated with data privacy and information security, which encompasses cybersecurity. Our Senior Vice President, Cybersecurity, and Chief Compliance Officer, among other executives, provide periodic reports to the NCGC Committee and also meet with the NCGC Committee to discuss any material events when they arise. The periodic reports are designed to keep the NCGC Committee abreast of the Company’s cybersecurity practices, risks and trends in cybersecurity threats. The NCGC Committee also has discussions with management focused on evaluating the Company’s exposure to cybersecurity risks and cybersecurity practices in place to mitigate such risks. These discussions enable the NCGC Committee to be informed of the steps management is taking to detect, monitor and manage cybersecurity risks. These reports
to the NCGC Committee typically include information on any significant incidents that have occurred, how they were managed, and any changes to the risk profile of the Company. The NCGC Committee seeks updates to facilitate proactive governance and to allow the NCGC Committee to address emerging cybersecurity issues with management.
Audit Committee
The Audit Committee is integral to overseeing the Company’s overall risk management strategies, including cybersecurity risks and disclosures. To keep the Audit Committee informed, the Chief Audit Executive maintains a direct and open communication channel with the Audit Committee. Regular meetings are held for the Chief Audit Executive to report to the Audit Committee. These include an enterprise-wide risk assessment that highlights cybersecurity risks and cybersecurity risk mitigation actions. Additionally, the Audit Committee receives updates on significant incidents and cybersecurity risks that have been presented to or discussed with the Enterprise Risk & Compliance Committee.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee is integral to overseeing the Company’s overall risk management strategies, including cybersecurity risks and disclosures.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|As part of management’s oversight of cybersecurity, Mark Clancy, our Senior Vice President, Cybersecurity, presents on our cybersecurity practices to the Nominating, Corporate Governance and Compliance Committee of our Board of Directors (the “NCGC Committee”) and to our full Board of Directors on a periodic basis. Our Chief Audit Executive periodically presents enterprise risks, including cybersecurity risks, to the Audit Committee of our Board of Directors (the “Audit Committee”). Our Chief Compliance Officer regularly attends meetings of the NCGC Committee to provide insights from the compliance perspective relating to cybersecurity.To keep the Audit Committee informed, the Chief Audit Executive maintains a direct and open communication channel with the Audit Committee. Regular meetings are held for the Chief Audit Executive to report to the Audit Committee. These include an enterprise-wide risk assessment that highlights cybersecurity risks and cybersecurity risk mitigation actions. Additionally, the Audit Committee receives updates on significant incidents and cybersecurity risks that have been presented to or discussed with the Enterprise Risk & Compliance Committee.
|Cybersecurity Risk Role of Management [Text Block]
|
Disclosure of the Board’s Roles and Responsibilities
Our Board of Directors oversees risks from cybersecurity threats using a multi-faceted approach that involves the NCGC Committee and Audit Committee and various executive roles. Additionally, our Chief Information Officer and Senior Vice President, Cybersecurity, report on cybersecurity to the full Board.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|, under the direction of the Chief Information Officer, is responsible for overseeing the cybersecurity organization and promoting a security-centric culture throughout our business and operational functions.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
As the Company’s Chief Information Officer, Jeff Simon has extensive experience in risk management and information security, including serving as the Chief Information Security Officer at Fidelity National Information Services, Inc. Mr. Simon received his Master of Science in Computer Science, Software Engineering & Artificial Intelligence from the Johns Hopkins Whiting School of Engineering and Bachelor of Science in Business Administration and Applied Economics from Marquette University. Mr. Simon is a Certified Information Systems Security Professional.As the Company’s Senior Vice President, Cybersecurity, Mark Clancy has over 25 years of experience in information technology, information security, and cybersecurity, including serving as the Chief Information and Security Officer and Vice President of Cybersecurity and Fraud at Sprint Corporation. Mr. Clancy received his Bachelor of Science in Electrical and Electronics Engineering from Drexel University.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Nominating, Corporate Governance and Compliance Committee
The NCGC Committee oversees risks associated with data privacy and information security, which encompasses cybersecurity. Our Senior Vice President, Cybersecurity, and Chief Compliance Officer, among other executives, provide periodic reports to the NCGC Committee and also meet with the NCGC Committee to discuss any material events when they arise. The periodic reports are designed to keep the NCGC Committee abreast of the Company’s cybersecurity practices, risks and trends in cybersecurity threats. The NCGC Committee also has discussions with management focused on evaluating the Company’s exposure to cybersecurity risks and cybersecurity practices in place to mitigate such risks. These discussions enable the NCGC Committee to be informed of the steps management is taking to detect, monitor and manage cybersecurity risks. These reports
to the NCGC Committee typically include information on any significant incidents that have occurred, how they were managed, and any changes to the risk profile of the Company. The NCGC Committee seeks updates to facilitate proactive governance and to allow the NCGC Committee to address emerging cybersecurity issues with management.
Audit Committee
The Audit Committee is integral to overseeing the Company’s overall risk management strategies, including cybersecurity risks and disclosures. To keep the Audit Committee informed, the Chief Audit Executive maintains a direct and open communication channel with the Audit Committee. Regular meetings are held for the Chief Audit Executive to report to the Audit Committee. These include an enterprise-wide risk assessment that highlights cybersecurity risks and cybersecurity risk mitigation actions. Additionally, the Audit Committee receives updates on significant incidents and cybersecurity risks that have been presented to or discussed with the Enterprise Risk & Compliance Committee.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef