|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Our Chief Technology Officer is responsible for monitoring and coordinating the Company’s Information Security Program, which is managed on a day-to-day basis by our Information Security Officer. This program has been designed to:
•Ensure appropriate security of all information systems data, equipment and processes;
•Ensure the security and confidentiality of nonpublic customer information;
•Protect against any anticipated threats or hazards; and
•Protect against unauthorized access to, or use of, such information.
Operationally, the information security team employs numerous security tools such as threat detection, alerting and monitoring, data loss prevention, vulnerability remediation, anti-malware and email security protections. Consistent with our Business Continuity and Security Incident Response Policies, the Company engages in annual disaster recovery and information security tabletop exercises to simulate threats and events, and engages third-parties on an annual basis to conduct and report on penetration testing exercises. We administer mandatory annual security awareness training, routine employee email phishing testing, and provide regular updates across the Company to highlight recent examples of risks as they are identified.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Our Chief Technology Officer is responsible for monitoring and coordinating the Company’s Information Security Program, which is managed on a day-to-day basis by our Information Security Officer. This program has been designed to:
•Ensure appropriate security of all information systems data, equipment and processes;
•Ensure the security and confidentiality of nonpublic customer information;
•Protect against any anticipated threats or hazards; and
•Protect against unauthorized access to, or use of, such information.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Our Board of Directors is responsible for overseeing the Company’s cybersecurity strategies and setting the acceptable cybersecurity risk appetite as part of its oversight of the Company’s risk management activities. The Board has designated the Executive and Risk Committee to oversee the Company’s Enterprise Risk Management Program, which includes the framework for identifying, measuring, monitoring and controlling cybersecurity risk.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board has designated the Executive and Risk Committee to oversee the Company’s Enterprise Risk Management Program, which includes the framework for identifying, measuring, monitoring and controlling cybersecurity risk.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Between updates provided by the Chief Technology Officer and Chief Risk Officer, who leads the Company’s Enterprise Risk Management function, the Committee receives quarterly updates over assessed internal and external risks, cyber threats, industry trends in the cyber area, security operations and incident response, threat and vulnerability management activities, identity and access management controls, and the results of third-party audits and examinations.
|Cybersecurity Risk Role of Management [Text Block]
|Between updates provided by the Chief Technology Officer and Chief Risk Officer, who leads the Company’s Enterprise Risk Management function, the Committee receives quarterly updates over assessed internal and external risks, cyber threats, industry trends in the cyber area, security operations and incident response, threat and vulnerability management activities, identity and access management controls, and the results of third-party audits and examinations. To ensure this focus is properly disseminated, the Enterprise Risk Management Program includes a Management Risk Committee, made up of executive officers, to ensure proper oversight of risk-related decision making and communication by executive management.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Board has designated the Executive and Risk Committee to oversee the Company’s Enterprise Risk Management Program, which includes the framework for identifying, measuring, monitoring and controlling cybersecurity risk. Between updates provided by the Chief Technology Officer and Chief Risk Officer, who leads the Company’s Enterprise Risk Management function, the Committee receives quarterly updates over assessed internal and external risks, cyber threats, industry trends in the cyber area, security operations and incident response, threat and vulnerability management activities, identity and access management controls, and the results of third-party audits and examinations.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|To ensure this focus is properly disseminated, the Enterprise Risk Management Program includes a Management Risk Committee, made up of executive officers, to ensure proper oversight of risk-related decision making and communication by executive management.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Between updates provided by the Chief Technology Officer and Chief Risk Officer, who leads the Company’s Enterprise Risk Management function, the Committee receives quarterly updates over assessed internal and external risks, cyber threats, industry trends in the cyber area, security operations and incident response, threat and vulnerability management activities, identity and access management controls, and the results of third-party audits and examinations.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef