|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
In the course of our operations, the Company receives and maintains sensitive information from our guests, employees, partners, and business operations. To address cybersecurity threats to this information, the Company uses a risk-based approach to create and implement a detailed set of information security policies and procedures based on frameworks established by the National Institute of Standards and Technology. The Company’s Head of Information Security manages the Company’s cybersecurity efforts and leads the cybersecurity team under the direct oversight of our Chief Technology Officer. These individuals, including all members of the cybersecurity team, have an average of over 16 years of experience involving information technology, including security, auditing, compliance, systems, and programming. Additionally, the Company engages in the cybersecurity experts for training, contingency planning, consultation, and process documentation.
The Company has and has implemented specific processes and controls designed to mitigate those identified risks. Both internal and third-party audits are performed routinely to verify that these controls are effective. Additionally, the Company has implemented companywide security awareness training programs designed to provide best practices for protecting our network and systems, and routinely leads exercises for employees to reinforce the risk and proper handling of targeted emails. The Company’s these controls and training exercises with support from our information technology department.detective and preventative controls designed to ensure the appropriate level of protection for the confidentiality, integrity, and availability of data stored on or transferred through our information technology resources. The Company has a risk assessment
The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks including risks associated with the Company’s use of artificial intelligence. This committee comprises members of management of the Company’s information technology, human resources, marketing, accounting, risk, procurement, training, finance, and legal functions, and is focused on performing risk assessments to identify areas of concern and implement appropriate changes to enhance its cybersecurity and privacy policies and procedures. The internal risk committee is informed of the Company’s risk prevention and mitigation efforts on a regular basis. The committee is also briefed on detection and remediation of cybersecurity incidents in a timely manner following the detection of any potential events.
The Company has a crisis response team comprising senior members of various corporate functions to oversee the response to various crises including potential crises arising from cybersecurity incidents that may impact the Company and/or its vendor partners. This team conducts regular tabletop exercises to simulate responses to cybersecurity incidents. To the extent there is a cybersecurity incident impacting the Company and/or a vendor partner, the crisis response team’s process would be to ensure that our Head of Information Security and Chief Technology Officer are informed immediately and that the potential impact of the incident and remedial measures arising from the incident are communicated to the executive officers of the Company.
There can be no guarantee that our policies and procedures will be effective. Although our risk factors include
further detail about the material cybersecurity risks we face and how a cybersecurity incident may affect our business strategy, results of operations, or financial condition, we believe that risks from prior cybersecurity threats, including as a result of any prior cybersecurity incident, have not materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition to date. We can provide no assurances that there will not be incidents in the future or that they will not materially affect us, including our business strategy, results of operations, or financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The Company has and has implemented specific processes and controls designed to mitigate those identified risks. Both internal and third-party audits are performed routinely to verify that these controls are effective. Additionally, the Company has implemented companywide security awareness training programs designed to provide best practices for protecting our network and systems, and routinely leads exercises for employees to reinforce the risk and proper handling of targeted emails. The Company’s these controls and training exercises with support from our information technology department.detective and preventative controls designed to ensure the appropriate level of protection for the confidentiality, integrity, and availability of data stored on or transferred through our information technology resources. The Company has a risk assessment
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Board has authorized the audit committee to oversee the Company’s risk assessment and risk management practices and strategies. This delegation includes maintaining responsibility for overseeing the Company’s enterprise risk management program. As a part of this oversight role, , which includes benchmarking these risks versus our industry. Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events, receive training specific to cybersecurity risks and threats and regularly discuss any updates to our cybersecurity risk management and strategy programs.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board has authorized the audit committee to oversee the Company’s risk assessment and risk management practices and strategies.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|versus our industry. Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events, receive training specific to cybersecurity risks and threats and regularly discuss any updates to our cybersecurity risk management and strategy programs., which includes benchmarking these risks
|Cybersecurity Risk Role of Management [Text Block]
|
The Company has and has implemented specific processes and controls designed to mitigate those identified risks. Both internal and third-party audits are performed routinely to verify that these controls are effective. Additionally, the Company has implemented companywide security awareness training programs designed to provide best practices for protecting our network and systems, and routinely leads exercises for employees to reinforce the risk and proper handling of targeted emails. The Company’s these controls and training exercises with support from our information technology department.detective and preventative controls designed to ensure the appropriate level of protection for the confidentiality, integrity, and availability of data stored on or transferred through our information technology resources. The Company has a risk assessment
The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks including risks associated with the Company’s use of artificial intelligence. This committee comprises members of management of the Company’s information technology, human resources, marketing, accounting, risk, procurement, training, finance, and legal functions, and is focused on performing risk assessments to identify areas of concern and implement appropriate changes to enhance its cybersecurity and privacy policies and procedures. The internal risk committee is informed of the Company’s risk prevention and mitigation efforts on a regular basis. The committee is also briefed on detection and remediation of cybersecurity incidents in a timely manner following the detection of any potential events.
The Company has a crisis response team comprising senior members of various corporate functions to oversee the response to various crises including potential crises arising from cybersecurity incidents that may impact the Company and/or its vendor partners. This team conducts regular tabletop exercises to simulate responses to cybersecurity incidents. To the extent there is a cybersecurity incident impacting the Company and/or a vendor partner, the crisis response team’s process would be to ensure that our Head of Information Security and Chief Technology Officer are informed immediately and that the potential impact of the incident and remedial measures arising from the incident are communicated to the executive officers of the Company.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Company’s Head of Information Security manages the Company’s cybersecurity efforts and leads the cybersecurity team under the direct oversight of our Chief Technology Officer.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|These individuals, including all members of the cybersecurity team, have an average of over 16 years of experience involving information technology, including security, auditing, compliance, systems, and programming.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|To the extent there is a cybersecurity incident impacting the Company and/or a vendor partner, the crisis response team’s process would be to ensure that our Head of Information Security and Chief Technology Officer are informed immediately and that the potential impact of the incident and remedial measures arising from the incident are communicated to the executive officers of the Company.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef