XML 57 R27.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We have established processes and policies for assessing, identifying and remediating material risks posed by cybersecurity threats. Our processes and policies are based upon the National Institute of Standards and Technology Cybersecurity Framework. Our processes are focused on: (i) effecting organizational education on how to manage cybersecurity risks, (ii) implementing safeguards to protect our systems, (iii) detecting the occurrence of a cybersecurity incident, (iv) responding to a cybersecurity incident and (v) recovering from a cybersecurity incident. Additionally, we have a cybersecurity incident response plan including specific responsive protocols administered by an incident response team, led by our Vice President of Information Technology and comprised of other members of management.

As a part of our organizational education on risk management, we require that employees annually complete information and privacy training. We also administer employee awareness training around phishing, malware, and other cyber risks on an ad hoc basis as necessary to enhance our protection efforts. We actively engage with key vendors and industry participants as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures. For example, our incident response team conducts periodic tabletop exercises with outside consultants to ensure adherence to our cybersecurity incident response plan. Additionally, we maintain insurance coverage for cybersecurity insurance as part of our overall insurance portfolio.

As of December 31, 2025, we have not identified any risks from cybersecurity threats (including any previous cybersecurity incidents) that have materially affected the Company, our business strategy, our results of operations or our financial condition. For a discussion of risks from cybersecurity threats that could be reasonably likely to materially affect us, please see “Risk Factors - An information security breach of our systems or our data centers operated by third-party providers, the loss of, or unauthorized access to, client information, or a system disruption could have a material adverse effect on our business, market brand, financial condition and results of operations.”
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We have established processes and policies for assessing, identifying and remediating material risks posed by cybersecurity threats. Our processes and policies are based upon the National Institute of Standards and Technology Cybersecurity Framework. Our processes are focused on: (i) effecting organizational education on how to manage cybersecurity risks, (ii) implementing safeguards to protect our systems, (iii) detecting the occurrence of a cybersecurity incident, (iv) responding to a cybersecurity incident and (v) recovering from a cybersecurity incident. Additionally, we have a cybersecurity incident response plan including specific responsive protocols administered by an incident response team, led by our Vice President of Information Technology and comprised of other members of management.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Our information security program is managed by a dedicated Senior Vice President of Information Technology (“SVP of IT”), whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The SVP of IT has the relevant expertise in understanding risks from cybersecurity threats and has extensive experience managing cybersecurity risk management programs. Additionally, the SVP of IT has served in various leadership roles in information technology and information security for over 20 years. The SVP of IT provides quarterly reports to the Audit Committee as well as our Chief Executive Officer and other members of our senior management, as appropriate. These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the current threat landscape. Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and
senior management. We also actively engage with key vendors and industry participants as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and senior management.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The SVP of IT provides quarterly reports to the Audit Committee as well as our Chief Executive Officer and other members of our senior management, as appropriate. These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the current threat landscape. Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and
senior management. We also actively engage with key vendors and industry participants as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures.
Cybersecurity Risk Role of Management [Text Block] The SVP of IT provides quarterly reports to the Audit Committee as well as our Chief Executive Officer and other members of our senior management, as appropriate. These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the current threat landscape. Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and senior management.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Our information security program is managed by a dedicated Senior Vice President of Information Technology (“SVP of IT”), whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The SVP of IT has the relevant expertise in understanding risks from cybersecurity threats and has extensive experience managing cybersecurity risk management programs. Additionally, the SVP of IT has served in various leadership roles in information technology and information security for over 20 years. The SVP of IT provides quarterly reports to the Audit Committee as well as our Chief Executive Officer and other members of our senior management, as appropriate. These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the current threat landscape. Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and
senior management. We also actively engage with key vendors and industry participants as part of our continuing efforts to evaluate and enhance the effectiveness of our information security policies and procedures.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The SVP of IT has the relevant expertise in understanding risks from cybersecurity threats and has extensive experience managing cybersecurity risk management programs. Additionally, the SVP of IT has served in various leadership roles in information technology and information security for over 20 years.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The SVP of IT provides quarterly reports to the Audit Committee as well as our Chief Executive Officer and other members of our senior management, as appropriate. These reports include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the current threat landscape. Our program is regularly evaluated by internal and external experts, with the results of those reviews reported quarterly to the Audit Committee and senior management.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true