XML 63 R35.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Aquestive’s cybersecurity program is built on four key pillars: Governance, Process, Compliance and Audit. While we face risks from cybersecurity threats that could have a material adverse effect on our business, financial condition, and results of operations, Aquestive’s cybersecurity program is built upon a set of policies, procedures, and standards supported by training and awareness. In addition, cybersecurity risks are also reviewed as part of our overall Enterprise Risk Management program.
The cybersecurity team has significant experience in managing cybersecurity programs and has engaged with a MSSP to deploy state of the art cybersecurity technologies and gather threat intelligence and cyber risk trends. The cybersecurity program is executed with the MSSP, which provides active threat monitoring, risk assessment and incident response capabilities to timely assess and address any material cyber risk that could impact our business operations.
On occasion, we engage other external experts, including cybersecurity assessors, consultants, and auditors to evaluate cybersecurity measures and risk management processes, including those applicable to Aquestive. We depend on and engage various third parties, including suppliers, vendors, and service providers, to operate. We rely on the expertise of our risk management, legal, information technology, and compliance personnel, as well as our MSSP, when identifying and overseeing risks from cybersecurity threats associated with our use of such entities.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Aquestive’s cybersecurity program is built on four key pillars: Governance, Process, Compliance and Audit. While we face risks from cybersecurity threats that could have a material adverse effect on our business, financial condition, and results of operations, Aquestive’s cybersecurity program is built upon a set of policies, procedures, and standards supported by training and awareness. In addition, cybersecurity risks are also reviewed as part of our overall Enterprise Risk Management program.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Audit Committee of the Board provides strategic oversight of Aquestive’s cybersecurity matters, including risks associated with cybersecurity threats.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee of the Board provides strategic oversight of Aquestive’s cybersecurity matters, including risks associated with cybersecurity threats
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Senior Vice President of Information Technology (the “IT Officer”), along with the broader Information Technology function, is responsible for assessing and managing Aquestive’s cybersecurity risk and informing senior management and the Audit Committee of the Board regarding cybersecurity risks and the prevention, detection, mitigation, and remediation of cybersecurity incidents. The IT Officer reports to the Chief Executive Officer and leads our cybersecurity program. Our IT Officer has been responsible for this function at Aquestive for 10 years and has over eleven years of experience in information security strategy and the management of cybersecurity risk. The internal Aquestive IT team has over fifteen years of technical experience, program management and architecture experience in managing cyber risk and information security.
Cybersecurity Risk Role of Management [Text Block] The Senior Vice President of Information Technology (the “IT Officer”), along with the broader Information Technology function, is responsible for assessing and managing Aquestive’s cybersecurity risk and informing senior management and the Audit Committee of the Board regarding cybersecurity risks and the prevention, detection, mitigation, and remediation of cybersecurity incidents. The IT Officer reports to the Chief Executive Officer and leads our cybersecurity program. Our IT Officer has been responsible for this function at Aquestive for 10 years and has over eleven years of experience in information security strategy and the management of cybersecurity risk. The internal Aquestive IT team has over fifteen years of technical experience, program management and architecture experience in managing cyber risk and information security.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Senior Vice President of Information Technology (the “IT Officer”), along with the broader Information Technology function, is responsible for assessing and managing Aquestive’s cybersecurity risk and informing senior management and the Audit Committee of the Board regarding cybersecurity risks and the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our IT Officer has been responsible for this function at Aquestive for 10 years and has over eleven years of experience in information security strategy and the management of cybersecurity risk. The internal Aquestive IT team has over fifteen years of technical experience, program management and architecture experience in managing cyber risk and information security.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Senior Vice President of Information Technology (the “IT Officer”), along with the broader Information Technology function, is responsible for assessing and managing Aquestive’s cybersecurity risk and informing senior management and the Audit Committee of the Board regarding cybersecurity risks and the prevention, detection, mitigation, and remediation of cybersecurity incidents. The IT Officer reports to the Chief Executive Officer and leads our cybersecurity program. Our IT Officer has been responsible for this function at Aquestive for 10 years and has over eleven years of experience in information security strategy and the management of cybersecurity risk. The internal Aquestive IT team has over fifteen years of technical experience, program management and architecture experience in managing cyber risk and information security.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true