|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity is at the foundation of the Company's values and the way it approaches its users, professionals, and customers. We face a number of external threats common to companies in the industries we serve, such as ransomware, denial-of-service, phishing, and social engineering. Our customers, suppliers, and professionals face similar threats, and a cybersecurity incident impacting the Company or any of these entities could materially adversely affect the performance of our businesses, our results of operations, and our cash flows.
We maintain cyber event related insurance but we have also instituted an information security structure and process to assess, identify, manage, and, if necessary, report cybersecurity risks. We maintain a cybersecurity incident response process and a tracking system for any incidents in an effort to ensure appropriate actions are taken. Any member of the Company can report a suspected incident and it will be investigated.
We have implemented data security standards in our architecture and system design techniques. Reviews and testing of our systems and subsystems are performed at regular intervals and are designed to ensure our capability to respond to cybersecurity incidents or threats. Our cybersecurity framework is based on the National Institute of Standards and Technology Cybersecurity Framework. In accordance with this framework, risks are analyzed for impact and probability to determine severity level, with classifications of critical, high, medium, or low risk. These processes have been integrated into our overall risk management system and processes and are part of our operating procedures, internal controls and information systems. In addition, we engage in an ongoing improvement process to enhance our cybersecurity posture.
Third parties also play a role in our cybersecurity. We engage third-party services to assist in the scanning and testing of our web properties and cloud infrastructure. We have a retainer with a cybersecurity response organization to immediately respond and provide professional expertise and assistance if necessary. Our process is designed to provide any required notifications in case of a cyber event, including those to federal, state, and local authorities, as well as to our insurance providers and auditors.
We also utilize a supply chain risk management process to assess cybersecurity risks associated with third-party software providers. We perform third-party risk assessments to both identify and mitigate risks from third parties such as vendors, suppliers, and others associated with our use of third-party service providers. Cybersecurity risks are evaluated when determining the selection and oversight of applicable third-party service providers and potential fourth-party risks when handling and/or processing our employee, business or customer data. In addition to new vendor onboarding, we perform risk management during third-party cybersecurity compromise incidents to identify and mitigate risks to us from third-party incidents.
The Company maintains a Security Council that regularly meets to review current or potential threats. The Security Council's membership consists of the following: the Company's Chief Executive Officer, Chief Financial Officer, Chief Legal Officer, Chief Information Officer, Director of Systems Engineering, and Internal Audit Director. We also employ a Security Department responsible for cybersecurity across the organizations. The individuals in this department are vetted for their
experience and expertise before joining the team and maintain continued education and training each year using our enhanced learning program. This department's responsibilities include cyber security risk management, security operations, awareness training, incident response, industry awareness and reporting. The team assesses and maintains awareness of global cyber security threats by using several services and notifications from our vendors. The team then considers each of these threats as applied to our environment, process, operations, vendors and clients. The Security Council is led by the Chief Information Officer, and Director of Systems Engineering, each of whom have a depth of knowledge and experience in the cyber security space.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We have implemented data security standards in our architecture and system design techniques. Reviews and testing of our systems and subsystems are performed at regular intervals and are designed to ensure our capability to respond to cybersecurity incidents or threats. Our cybersecurity framework is based on the National Institute of Standards and Technology Cybersecurity Framework. In accordance with this framework, risks are analyzed for impact and probability to determine severity level, with classifications of critical, high, medium, or low risk. These processes have been integrated into our overall risk management system and processes and are part of our operating procedures, internal controls and information systems. In addition, we engage in an ongoing improvement process to enhance our cybersecurity posture.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board of Directors has ultimate oversight of cybersecurity risk, which it manages as part of our enterprise risk management program, while the Audit Committee is directly responsible for oversight of the Company's cybersecurity and is briefed by the Security Council on a quarterly basis. Members of the Audit Committee receive updates on a quarterly basis from senior management, including leaders from impacted and responsible teams regarding matters of cybersecurity. This includes existing and new cybersecurity risks, status on how management is addressing and/or mitigating those risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives. Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors has ultimate oversight of cybersecurity risk, which it manages as part of our enterprise risk management program, while the Audit Committee is directly responsible for oversight of the Company's cybersecurity and is briefed by the Security Council on a quarterly basis.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Members of the Audit Committee receive updates on a quarterly basis from senior management, including leaders from impacted and responsible teams regarding matters of cybersecurity. This includes existing and new cybersecurity risks, status on how management is addressing and/or mitigating those risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives. Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
|Cybersecurity Risk Role of Management [Text Block]
|
The Company maintains a Security Council that regularly meets to review current or potential threats. The Security Council's membership consists of the following: the Company's Chief Executive Officer, Chief Financial Officer, Chief Legal Officer, Chief Information Officer, Director of Systems Engineering, and Internal Audit Director. We also employ a Security Department responsible for cybersecurity across the organizations. The individuals in this department are vetted for their
experience and expertise before joining the team and maintain continued education and training each year using our enhanced learning program. This department's responsibilities include cyber security risk management, security operations, awareness training, incident response, industry awareness and reporting. The team assesses and maintains awareness of global cyber security threats by using several services and notifications from our vendors. The team then considers each of these threats as applied to our environment, process, operations, vendors and clients. The Security Council is led by the Chief Information Officer, and Director of Systems Engineering, each of whom have a depth of knowledge and experience in the cyber security space.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
The Company maintains a Security Council that regularly meets to review current or potential threats. The Security Council's membership consists of the following: the Company's Chief Executive Officer, Chief Financial Officer, Chief Legal Officer, Chief Information Officer, Director of Systems Engineering, and Internal Audit Director. We also employ a Security Department responsible for cybersecurity across the organizations. The individuals in this department are vetted for their
experience and expertise before joining the team and maintain continued education and training each year using our enhanced learning program. This department's responsibilities include cyber security risk management, security operations, awareness training, incident response, industry awareness and reporting. The team assesses and maintains awareness of global cyber security threats by using several services and notifications from our vendors. The team then considers each of these threats as applied to our environment, process, operations, vendors and clients. The Security Council is led by the Chief Information Officer, and Director of Systems Engineering, each of whom have a depth of knowledge and experience in the cyber security space.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The individuals in this department are vetted for their experience and expertise before joining the team and maintain continued education and training each year using our enhanced learning program. This department's responsibilities include cyber security risk management, security operations, awareness training, incident response, industry awareness and reporting.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The team assesses and maintains awareness of global cyber security threats by using several services and notifications from our vendors. The team then considers each of these threats as applied to our environment, process, operations, vendors and clients.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef