|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
We have developed, implemented, and integrated a cybersecurity program, or the Cybersecurity Program, into our broader risk management structure to protect our information systems by using physical, technical, and administrative safeguards. This includes assessing, identifying, monitoring, reporting, managing and remediating cybersecurity threats. The Cybersecurity Program aims to prevent data ex-filtration, manipulation, and destruction, as well as system and transactional disruption. The Cybersecurity Program utilizes a threat-centric and risk-based approach to identify and assess cybersecurity threats that could affect our business and information systems based on the National Institute of Standards and Technology Cybersecurity Framework, or the NIST Framework.
Our Cybersecurity Program includes the following processes:
•Annual control reviews, annual policy reviews and annual investments in our security infrastructure;
•Periodic testing of our information systems to assess our vulnerability to cyber risk, which includes targeted penetration testing and vulnerability scanning;
•Collaborating with our internal audit team to evaluate the effectiveness of our information technology security program and communicating results to our executive officers;
•Conducting a comprehensive information security and training program for our employees, including mandatory computer-based training, regular internal communications, and ongoing end-user testing to measure the effectiveness of our information security program. As part of this commitment, we require our employees to acknowledge our Information Security policy each year. In addition, we have an established schedule and process for regular phishing awareness campaigns that are designed to emulate real-world contemporary threats and provide immediate feedback (and, if necessary, additional training or remedial action) to employees;
•Annually assess the Cybersecurity Program against the NIST Framework;
•Maintaining business continuity, contingency and recovery plans to quickly react to cybersecurity incidents;
•Conducting security assessments of all third-party service providers with access to personal, confidential or proprietary information before engagement and maintaining ongoing monitoring by reviewing system and organization controls reports, relevant cyber attestations, and other independent cyber ratings;
•Retaining a third-party cybersecurity provider for emergency incident response services in the event of a serious information security breach; and
•Maintaining cybersecurity risk insurance that could help defray the costs of an information security breach as a backstop to the Cybersecurity Program.
Through our incident response plan, we have designated a cybersecurity management team, or the Cybersecurity Management Team, composed of our executive officers and management representatives. Led by our Vice President of Information Technology & Corporate Facilities, our Cybersecurity Management Team is responsible for the management of the Cybersecurity Program and for the day-to-day investigation of and response to potential information security-related incidents. Pursuant to our incident response plan, incidents meeting specified severity levels are required to be escalated to the Cybersecurity Management Team for review and response. The goals of the incident response plan are to prevent, detect and react to information security incidents, determine their scope and risk, respond appropriately to the incident, communicate the results and risk to relevant stakeholders, and reduce the likelihood of the incident from reoccurring.
Our Vice President of Information Technology & Corporate Facilities has served in this role since 2018. In this role, he manages and oversees the Company's network and information systems. Additionally, he works with the executive officers, management representatives and third-party experts to maintain the Company's Cybersecurity Program. Our Vice President of Information Technology & Corporate Facilities possesses extensive experience in technology and cybersecurity gained over his career spanning more than 25 years, including service as the executive director of Business Applications as well as a senior implementer and business consultant.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We have developed, implemented, and integrated a cybersecurity program, or the Cybersecurity Program, into our broader risk management structure to protect our information systems by using physical, technical, and administrative safeguards. This includes assessing, identifying, monitoring, reporting, managing and remediating cybersecurity threats.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Board plays a role in overseeing risks associated with cybersecurity threats and has delegated to the Audit Committee primary oversight of the Cybersecurity Program. Our executive officers report on our Cybersecurity Program to the Audit Committee at least four times per year (including as part of our discussions regarding enterprise risk management). Our
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Board plays a role in overseeing risks associated with cybersecurity threats and has delegated to the Audit Committee primary oversight of the Cybersecurity Program.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board plays a role in overseeing risks associated with cybersecurity threats and has delegated to the Audit Committee primary oversight of the Cybersecurity Program. Our executive officers report on our Cybersecurity Program to the Audit Committee at least four times per year (including as part of our discussions regarding enterprise risk management). Our quarterly updates to the Audit Committee include a discussion of our information security programs and controls, including our internal auditor's review and our internal monitoring of cybersecurity risks.
|Cybersecurity Risk Role of Management [Text Block]
|
Through our incident response plan, we have designated a cybersecurity management team, or the Cybersecurity Management Team, composed of our executive officers and management representatives. Led by our Vice President of Information Technology & Corporate Facilities, our Cybersecurity Management Team is responsible for the management of the Cybersecurity Program and for the day-to-day investigation of and response to potential information security-related incidents. Pursuant to our incident response plan, incidents meeting specified severity levels are required to be escalated to the Cybersecurity Management Team for review and response. The goals of the incident response plan are to prevent, detect and react to information security incidents, determine their scope and risk, respond appropriately to the incident, communicate the results and risk to relevant stakeholders, and reduce the likelihood of the incident from reoccurring.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Through our incident response plan, we have designated a cybersecurity management team, or the Cybersecurity Management Team, composed of our executive officers and management representatives. Led by our Vice President of Information Technology & Corporate Facilities, our Cybersecurity Management Team is responsible for the management of the Cybersecurity Program and for the day-to-day investigation of and response to potential information security-related incidents.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
Our Vice President of Information Technology & Corporate Facilities has served in this role since 2018. In this role, he manages and oversees the Company's network and information systems. Additionally, he works with the executive officers, management representatives and third-party experts to maintain the Company's Cybersecurity Program. Our Vice President of Information Technology & Corporate Facilities possesses extensive experience in technology and cybersecurity gained over his career spanning more than 25 years, including service as the executive director of Business Applications as well as a senior implementer and business consultant.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our executive officers report on our Cybersecurity Program to the Audit Committee at least four times per year (including as part of our discussions regarding enterprise risk management). Our quarterly updates to the Audit Committee include a discussion of our information security programs and controls, including our internal auditor's review and our internal monitoring of cybersecurity risks.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef