|
Cybersecurity Risk Management, Strategy, and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
We maintain a cybersecurity program that is reasonably designed to protect our information, and our customers’ information, from cybersecurity threats against us, our third-party vendors, and services providers, that may result in a material adverse effect on the confidentiality, integrity, and availability of our information systems.
Governance
Management
Our Technology Team is responsible for the implementation, monitoring, and maintenance of cybersecurity and data protection practices across the Company. The Technology Team includes members who have experience in network security, server integration and data protection. In conjunction with a cross-functional team, our Technology Team regularly reviews risk management measures implemented by the Company to identify and mitigate data protection and cybersecurity risks. In addition to our internal cybersecurity capabilities, we also regularly engage consultants and other third parties to assist with assessing, identifying, and managing cybersecurity risks and to participate in tabletop and other training exercises. The Technology Team monitors and is informed about cybersecurity incidents through firewalls that are triggered in our information technology systems.
Board of Directors
Our board of directors, in coordination with the audit committee of our board of directors, oversees the Company’s enterprise risk management process, including the management of risks arising from cybersecurity threats. Our audit committee regularly receives reports and presentations from the Technology Team regarding cybersecurity. The Technology Team also reports to our board of directors at least annually on cybersecurity matters. We have established protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, are reported to our board of directors and/or our audit committee.
Risk Management and Strategy
We employ a defense-in-depth approach with systems and processes designed to oversee, identify, and reduce the potential impact of a security incident against us or a third-party vendor or service provider. These include but are not limited to: multi-factor authentication, Endpoint, email, immutable backups, third party risk assessments, and other applicable controls.
Incident Response
We have adopted a Cybersecurity Incident Response Plan (the “IRP”) that applies in the event of a cybersecurity incident that provides a standardized framework for responding to cybersecurity incidents. The IRP is expected to be integrated into our overall risk management system and applies to all Company personnel (including third-party contractors, vendors and partners) that perform functions or services require access to secure Company information, and to all devices and network services that are owned or managed by the Company.
As of the date of this report, we are not aware of any material risks from cybersecurity threats and have materially affected or could materially affect us, including our business strategy, results of operations, or financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have adopted a Cybersecurity Incident Response Plan (the “IRP”) that applies in the event of a cybersecurity incident that provides a standardized framework for responding to cybersecurity incidents. The IRP is expected to be integrated into our overall risk management system and applies to all Company personnel (including third-party contractors, vendors and partners) that perform functions or services require access to secure Company information, and to all devices and network services that are owned or managed by the Company.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|
As of the date of this report, we are not aware of any material risks from cybersecurity threats and have materially affected or could materially affect us, including our business strategy, results of operations, or financial condition.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Board of Directors
Our board of directors, in coordination with the audit committee of our board of directors, oversees the Company’s enterprise risk management process, including the management of risks arising from cybersecurity threats. Our audit committee regularly receives reports and presentations from the Technology Team regarding cybersecurity. The Technology Team also reports to our board of directors at least annually on cybersecurity matters. We have established protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, are reported to our board of directors and/or our audit committee.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our board of directors, in coordination with the audit committee of our board of directors, oversees the Company’s enterprise risk management process, including the management of risks arising from cybersecurity threats.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our audit committee regularly receives reports and presentations from the Technology Team regarding cybersecurity. The Technology Team also reports to our board of directors at least annually on cybersecurity matters.
|Cybersecurity Risk Role of Management [Text Block]
|
Risk Management and Strategy
We employ a defense-in-depth approach with systems and processes designed to oversee, identify, and reduce the potential impact of a security incident against us or a third-party vendor or service provider. These include but are not limited to: multi-factor authentication, Endpoint, email, immutable backups, third party risk assessments, and other applicable controls.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef