|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
As one of the critical elements of our overall ERM approach, our cybersecurity program is focused on the following key areas:
Governance: As discussed in more detail under the heading “Governance,” the board of directors' oversight of cybersecurity risk management is supported by the Audit Committee of the board of directors, or the Audit Committee, our Chief Information Officer, or CIO, other members of management and relevant management committees as appropriate.
Collaborative Approach: We have implemented a cross-functional approach to identifying, preventing and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
Technical Safeguards: We deploy technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence.
Physical Safeguards: We deploy physical safeguards such as facility access control via keycard access and security cameras. In addition, workstation and device security is controlled with proper logging and identity access controls to protect our physical assets.
Administrative Safeguards: We have implemented policies, security standards and procedures to ensure proper user and protection of our assets. We maintain cybersecurity risk insurance coverage to provide financial protection in the event a cybersecurity breach was to occur.
Education and Awareness: We provide regular, mandatory, and ongoing training and reinforcement for personnel regarding cybersecurity threats to help equip our personnel with tools to address such threats, and to communicate our evolving information security policies, standards, processes and practices.
Incident Response and Recovery Planning: We have established and maintain a cybersecurity incident response plan that addresses our response to a cybersecurity incident.
Third-Party Risk Management: We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems that could adversely impact our business in the event of a cybersecurity incident.
We engage in the periodic assessment and testing of our policies, standards, processes and practices that are designed to address cybersecurity threats and incidents. These efforts include a range of activities, including audits, assessments, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning. We regularly engage third parties to perform assessments on our cybersecurity measures. The results of such assessments, audits and reviews are reported to the Audit Committee and the board of directors, and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Our board of directors recognizes the critical importance of maintaining the trust and confidence of our customers, patients, business partners and employees. Our board of directors is actively involved in oversight of our risk management program, and cybersecurity represents an important component of our overall approach to enterprise risk management, or ERM. Our cybersecurity policies, standards, processes and practices continue to be incorporated into our ERM program and are based on recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards. In general, we seek to address cybersecurity risks through a cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The board of directors, in coordination with the Audit Committee, oversees our management of risks arising from cybersecurity threats. The board of directors and the Audit Committee each receive presentations and reports on cybersecurity risks, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties. The board of directors and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed. On an annual basis, the board of directors and the Audit Committee discuss our approach to cybersecurity risk management with the members of management, including the CIO.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The board of directors, in coordination with the Audit Committee, oversees our management of risks arising from cybersecurity threats.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The board of directors and the Audit Committee each receive presentations and reports on cybersecurity risks, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties. The board of directors and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
|Cybersecurity Risk Role of Management [Text Block]
|
The Cybersecurity Executive Leadership Team is composed of the CIO, in coordination with our Chief Executive Officer, or CEO, Chief Financial Officer, or CFO, Chief Compliance Officer and General Counsel, or GC. The team works collaboratively across our company to design and implement programs to protect our information systems from cybersecurity threats and to appropriately respond to any cybersecurity incidents in accordance with our cybersecurity incident response plan. To facilitate the success of our cybersecurity risk management program, multidisciplinary teams throughout our company are engaged to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, the CIO and the Cybersecurity Executive Leadership Team monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
Our CIO brings more than 20 years of information and operational leadership experience in the life sciences and technology industries to his role at Veracyte. He holds a B.B.A. and an M.B.A from the University of San Diego. Our VP, Global IT Operation oversees IT operations for all sites globally, and has more than 20 years’ of experience. He holds a M.S. in Business Technology Management, and a B.S. in Computer Applications and Networks from Coleman University. Our Director of Cybersecurity has over 25 years’ of experience in enhancing digital security and driving technological innovation. He holds a B.Sc. (Honors) in Computer Information Systems from the National University along with several industry related Cybersecurity certifications.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Cybersecurity Executive Leadership Team is composed of the CIO, in coordination with our Chief Executive Officer, or CEO, Chief Financial Officer, or CFO, Chief Compliance Officer and General Counsel, or GC.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
Our CIO brings more than 20 years of information and operational leadership experience in the life sciences and technology industries to his role at Veracyte. He holds a B.B.A. and an M.B.A from the University of San Diego. Our VP, Global IT Operation oversees IT operations for all sites globally, and has more than 20 years’ of experience. He holds a M.S. in Business Technology Management, and a B.S. in Computer Applications and Networks from Coleman University. Our Director of Cybersecurity has over 25 years’ of experience in enhancing digital security and driving technological innovation. He holds a B.Sc. (Honors) in Computer Information Systems from the National University along with several industry related Cybersecurity certifications.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Cybersecurity Executive Leadership Team is composed of the CIO, in coordination with our Chief Executive Officer, or CEO, Chief Financial Officer, or CFO, Chief Compliance Officer and General Counsel, or GC. The team works collaboratively across our company to design and implement programs to protect our information systems from cybersecurity threats and to appropriately respond to any cybersecurity incidents in accordance with our cybersecurity incident response plan. To facilitate the success of our cybersecurity risk management program, multidisciplinary teams throughout our company are engaged to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, the CIO and the Cybersecurity Executive Leadership Team monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef