|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management Approach
We have documented cybersecurity policies and standards, and we assess risks from cybersecurity threats and monitor information systems for potential cybersecurity issues. These processes are managed and monitored by a dedicated cybersecurity team, including third-party service providers, and led by our Head of IT, and include mechanisms, controls, technologies, systems, and other processes designed to help prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and help maintain a stable information technology environment. For example, we use processes, tools and external services to conduct regular vulnerability testing, penetration testing, data recovery testing, security audits, and ongoing risk assessments, including due diligence on and audits of our key technology vendors, CROs, and other contractors and suppliers.
We work to maintain a strong cybersecurity posture through a multi-layered approach. Our endpoint detection and response (“EDR”) system helps monitor and analyze endpoint devices, and is designed to assist us in quickly identifying and responding to emerging threats. Complementing our EDR capabilities, our managed detection and response service assists with threat monitoring, proactive threat hunting, and rapid incident response. Furthermore, we employ data loss prevention tools to help enforce strict data security policies, prevent unauthorized access and protect the transmission of sensitive information. These integrated technologies help us to detect, mitigate, and respond to cyber threats, with the goal of minimizing potential disruptions to our business operations.
We have an incident response plan designed to help quickly detect, contain and remediate cybersecurity incidents. This plan outlines clear escalation procedures, roles and responsibilities to help us respond in a timely manner to potential threats. We also conduct regular employee training on matters such as phishing and email security best practices, among other topics. In addition, we consult with outside advisors and experts when appropriate to assist with assessing, identifying, and managing cybersecurity risks, including to help anticipate future threats and trends, and their impact on our risk environment.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have documented cybersecurity policies and standards, and we assess risks from cybersecurity threats and monitor information systems for potential cybersecurity issues. These processes are managed and monitored by a dedicated cybersecurity team, including third-party service providers, and led by our Head of IT, and include mechanisms, controls, technologies, systems, and other processes designed to help prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and help maintain a stable information technology environment. For example, we use processes, tools and external services to conduct regular vulnerability testing, penetration testing, data recovery testing, security audits, and ongoing risk assessments, including due diligence on and audits of our key technology vendors, CROs, and other contractors and suppliers.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board as a whole has oversight for the most significant risks facing us and for our processes to help identify, prioritize, assess, manage, and mitigate those risks, including oversight of cybersecurity risks. Our Board receives at least two updates each year on cybersecurity and information technology matters and related risk exposures from our Head of IT as well as other members of our senior leadership team.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board receives at least two updates each year on cybersecurity and information technology matters and related risk exposures from our Head of IT as well as other members of our senior leadership team.
|Cybersecurity Risk Role of Management [Text Block]
|Our current Head of IT reports directly to our Chief Financial Officer and has over twenty years of experience managing information technology and cybersecurity matters, holds a Master of Science degree in Telecommunications and Computer Networks and is Project Management Professional, Certified Scrum Master and IT Infrastructure Library certified. We have established a cybersecurity council, facilitated by the Head of IT, which includes senior leadership from various departments. The council meets quarterly to review cybersecurity strategies, assess emerging threats, and receive updates on regulatory and industry best practices.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Head of IT
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our current Head of IT reports directly to our Chief Financial Officer and has over twenty years of experience managing information technology and cybersecurity matters, holds a Master of Science degree in Telecommunications and Computer Networks and is Project Management Professional, Certified Scrum Master and IT Infrastructure Library certified.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The council meets quarterly to review cybersecurity strategies, assess emerging threats, and receive updates on regulatory and industry best practices
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef