|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.
We design and assess our program based on the FedRAMP framework. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the FedRAMP requirements as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
Our cybersecurity risk management program is part of our overall risk management program. Key elements of our cybersecurity risk management program include but are not limited to the following:
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations, or financial condition. We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. For more information, see the section titled “Risk Factor — Our business and operations may suffer in the event of information technology system failures, cyberattacks or deficiencies in our cybersecurity.”
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.
We design and assess our program based on the FedRAMP framework. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the FedRAMP requirements as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
Our cybersecurity risk management program is part of our overall risk management program. Key elements of our cybersecurity risk management program include but are not limited to the following:
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (the “Committee”) oversight of cybersecurity risks, including oversight of management’s implementation of our cybersecurity risk management program.
The Committee receives periodic reports from management on our cybersecurity risks. In addition, management updates the Committee, where it deems appropriate, regarding any cybersecurity incidents it considers to be significant or potentially significant, as well as any incidents with lesser impact potential.
The Committee reports to the full Board regarding its activities, including those related to cybersecurity. The full Board also receives briefings from management on our cyber risk management program.
Our management team takes steps to stay informed about and supervises efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents. Mercedes Soria, EVP and Chief Intelligence Officer / Chief Information Security Officer (“CISO”) has primary responsibility for our overall cybersecurity program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Ms. Soria has over four years of cyber risk management experience, and is primarily responsible for assessing
and managing our material risks from cybersecurity threats. Ms. Soria actively leads her team’s efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal personnel, threat intelligence and other information obtained from governmental, public or private sources, including external vendors and consultants engaged by us, and alerts and reports produced by security tools deployed in our information technology environment and our products. As part of her responsibilities, Ms. Soria and her team will continue to monitor our systems for vulnerabilities, implement required updates, and undergo periodic reassessments thus ensuring that our cybersecurity practices remain effective over time.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
The Committee receives periodic reports from management on our cybersecurity risks. In addition, management updates the Committee, where it deems appropriate, regarding any cybersecurity incidents it considers to be significant or potentially significant, as well as any incidents with lesser impact potential.
The Committee reports to the full Board regarding its activities, including those related to cybersecurity. The full Board also receives briefings from management on our cyber risk management program.
|Cybersecurity Risk Role of Management [Text Block]
|
Our management team takes steps to stay informed about and supervises efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents. Mercedes Soria, EVP and Chief Intelligence Officer / Chief Information Security Officer (“CISO”) has primary responsibility for our overall cybersecurity program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Ms. Soria has over four years of cyber risk management experience, and is primarily responsible for assessing
and managing our material risks from cybersecurity threats. Ms. Soria actively leads her team’s efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal personnel, threat intelligence and other information obtained from governmental, public or private sources, including external vendors and consultants engaged by us, and alerts and reports produced by security tools deployed in our information technology environment and our products. As part of her responsibilities, Ms. Soria and her team will continue to monitor our systems for vulnerabilities, implement required updates, and undergo periodic reassessments thus ensuring that our cybersecurity practices remain effective over time.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|EVP and Chief Intelligence Officer / Chief Information Security Officer (“CISO”)
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Mercedes Soria, EVP and Chief Intelligence Officer / Chief Information Security Officer (“CISO”) has primary responsibility for our overall cybersecurity program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Ms. Soria has over four years of cyber risk management experience, and is primarily responsible for assessing and managing our material risks from cybersecurity threats.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (the “Committee”) oversight of cybersecurity risks, including oversight of management’s implementation of our cybersecurity risk management program.
The Committee receives periodic reports from management on our cybersecurity risks. In addition, management updates the Committee, where it deems appropriate, regarding any cybersecurity incidents it considers to be significant or potentially significant, as well as any incidents with lesser impact potential.
The Committee reports to the full Board regarding its activities, including those related to cybersecurity. The full Board also receives briefings from management on our cyber risk management program.
Our management team takes steps to stay informed about and supervises efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents. Mercedes Soria, EVP and Chief Intelligence Officer / Chief Information Security Officer (“CISO”) has primary responsibility for our overall cybersecurity program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Ms. Soria has over four years of cyber risk management experience, and is primarily responsible for assessing
and managing our material risks from cybersecurity threats. Ms. Soria actively leads her team’s efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal personnel, threat intelligence and other information obtained from governmental, public or private sources, including external vendors and consultants engaged by us, and alerts and reports produced by security tools deployed in our information technology environment and our products. As part of her responsibilities, Ms. Soria and her team will continue to monitor our systems for vulnerabilities, implement required updates, and undergo periodic reassessments thus ensuring that our cybersecurity practices remain effective over time.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef