|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Assessment, Identification and Management of Material Risks from Cybersecurity Threats
We rely on the cybersecurity strategy and policies implemented by Ares, the parent company of our Advisor. Ares’ cybersecurity strategy prioritizes the detection and analysis of and response to known, anticipated or unexpected threats, effective management of security risks and resilience against cyber incidents. Ares’ enterprise-wide cybersecurity program is aligned to the National Institute of Standards and Technology Cybersecurity Framework. Ares’ cybersecurity risk management processes include technical security controls, policy enforcement mechanisms, monitoring systems, tools and related services, which include tools and services from third-party providers, and management oversight to assess, identify and manage risks from cybersecurity threats. Ares has implemented and continues to implement risk-based controls designed to prevent, detect and respond to information security threats and we rely on those controls to help us protect our information, our information systems, and the information of our investors, and other third parties who entrust us with their sensitive information.
Ares’ cybersecurity program includes physical, administrative and technical safeguards, as well as plans and procedures designed to help Ares prevent and timely and effectively respond to cybersecurity threats and incidents, including threats or incidents that may impact us, our Advisor or Ares. Ares’ cybersecurity risk management process seeks to monitor cybersecurity vulnerabilities and potential attack vectors, evaluate the potential operational and financial effects of any threat and mitigate such threats. The assessment of cybersecurity threats, including those which may impact us, our Advisor or Ares, is integrated into Ares’ Enterprise Risk Management program, which is overseen by the Ares Enterprise Risk Committee (the “Ares ERC”), as discussed below. In addition, Ares periodically engages with third-party consultants and key vendors to assist it in assessing, enhancing, implementing, and monitoring its cybersecurity risk management programs and responding to incidents.
The Ares cybersecurity risk management and awareness programs include periodic identification and testing of vulnerabilities, regular phishing simulations and annual general cybersecurity awareness and data protection training, including for all of the employees of Ares. Ares’ cybersecurity training programs also include annual certification requirements for employees of Ares with respect to certain policies supporting the cybersecurity program including the Information Security and Electronic Communications policy, Data Protection policy and Privacy Policy. Ares undertakes periodic internal security reviews of its information systems and related controls, including systems affecting personal data and the cybersecurity risks of Ares’ and our critical third-party service providers and other partners. Ares also completes periodic external reviews of its cybersecurity program and practices, which include assessments of relevant data protection practices and targeted attack simulations.
In the event of a cybersecurity incident impacting us, our Advisor or Ares, Ares has developed an incident response plan that provides guidelines for responding to such an incident and facilitates coordination across multiple operational functions of Ares, including coordinating with the relevant members of our Advisor. The incident response plan includes notification to the applicable members of cybersecurity leadership, including Ares’ Chief Information Security Officer (“CISO”), and, as appropriate, escalation to the full Ares ERC and/or an internal ad-hoc group of senior employees, tasked with helping to manage the cybersecurity incident. Depending on their nature, incidents may also be reported to the audit committee or full board of directors of Ares, as well as to the audit committee of our board of directors and to our full board of directors, if appropriate.
Material Impact of Risks from Cybersecurity Threats
In the last three fiscal years, we have not experienced a material information security breach incident that has materially affected our business strategy, results of operations or financial conditions. The expenses we have incurred from information security breach incidents have been immaterial, and we are not aware of any cybersecurity risks that are reasonably likely to materially affect our business. However, future incidents could have a material impact on our business strategy, results of operations, or financial condition. For additional discussion of the risks posed by cybersecurity threats, see “Item 1A. Risk Factors—General Risk Factors—Security incidents or cyber-attacks could adversely affect our business by causing a disruption to our operations or the operations of the Advisor, the Dealer Manager, our transfer agent or any other party that provides us with services essential to our operations… which could negatively impact our business, financial condition and operating results.”
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Ares’ cybersecurity program includes physical, administrative and technical safeguards, as well as plans and procedures designed to help Ares prevent and timely and effectively respond to cybersecurity threats and incidents, including threats or incidents that may impact us, our Advisor or Ares. Ares’ cybersecurity risk management process seeks to monitor cybersecurity vulnerabilities and potential attack vectors, evaluate the potential operational and financial effects of any threat and mitigate such threats. The assessment of cybersecurity threats, including those which may impact us, our Advisor or Ares, is integrated into Ares’ Enterprise Risk Management program, which is overseen by the Ares Enterprise Risk Committee (the “Ares ERC”), as discussed below. In addition, Ares periodically engages with third-party consultants and key vendors to assist it in assessing, enhancing, implementing, and monitoring its cybersecurity risk management programs and responding to incidents.
The Ares cybersecurity risk management and awareness programs include periodic identification and testing of vulnerabilities, regular phishing simulations and annual general cybersecurity awareness and data protection training, including for all of the employees of Ares. Ares’ cybersecurity training programs also include annual certification requirements for employees of Ares with respect to certain policies supporting the cybersecurity program including the Information Security and Electronic Communications policy, Data Protection policy and Privacy Policy. Ares undertakes periodic internal security reviews of its information systems and related controls, including systems affecting personal data and the cybersecurity risks of Ares’ and our critical third-party service providers and other partners. Ares also completes periodic external reviews of its cybersecurity program and practices, which include assessments of relevant data protection practices and targeted attack simulations.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Oversight of Cybersecurity Risks
Our cybersecurity program is managed by Ares’ dedicated internal cybersecurity team, which is responsible for enterprise-wide cybersecurity strategy, policies, standards, engineering, architecture and processes. The team is led by Ares’ CISO, who has a Master’s degree in Cybersecurity from Brown University and over 25 years of experience advising on and managing risks from cybersecurity threats as well as developing and implementing cybersecurity policies and procedures. The Ares CISO reports cybersecurity updates to the Ares ERC. The Ares ERC is a committee that governs and oversees the Ares Enterprise Risk Program, including cybersecurity. The Ares ERC includes members of Ares’ senior executive management, including its CEO, Co-Presidents, CFO, General Counsel, Global Chief Compliance Officer and Head of Enterprise Risk, who acts as chairperson of the Ares ERC. The Ares ERC, through regular consultation with the Ares internal cybersecurity team and representatives from our Advisor, assesses, discusses, and prioritizes Ares’ approach to high-level risks, mitigating controls, and ongoing cybersecurity efforts.
Our audit committee has primary responsibility for oversight and review of guidelines and policies with respect to risk assessment and risk management, including cybersecurity. Periodically, reports are provided to our audit committee as well as our full board of directors, as appropriate, on cybersecurity matters, primarily through presentations by the CISO and the Ares Head of Enterprise Risk. Such reporting includes updates on Ares’ cybersecurity program as it impacts us, the external threat environment, and Ares’ programs to address and mitigate the risks associated with the evolving cybersecurity threat environment. These reports also include updates on our and Ares’ preparedness, prevention, detection, responsiveness, and recovery with respect to cyber incidents.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|audit committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our audit committee has primary responsibility for oversight and review of guidelines and policies with respect to risk assessment and risk management, including cybersecurity. Periodically, reports are provided to our audit committee as well as our full board of directors, as appropriate, on cybersecurity matters, primarily through presentations by the CISO and the Ares Head of Enterprise Risk. Such reporting includes updates on Ares’ cybersecurity program as it impacts us, the external threat environment, and Ares’ programs to address and mitigate the risks associated with the evolving cybersecurity threat environment. These reports also include updates on our and Ares’ preparedness, prevention, detection, responsiveness, and recovery with respect to cyber incidents.
|Cybersecurity Risk Role of Management [Text Block]
|Our cybersecurity program is managed by Ares’ dedicated internal cybersecurity team, which is responsible for enterprise-wide cybersecurity strategy, policies, standards, engineering, architecture and processes. The team is led by Ares’ CISO, who has a Master’s degree in Cybersecurity from Brown University and over 25 years of experience advising on and managing risks from cybersecurity threats as well as developing and implementing cybersecurity policies and procedures. The Ares CISO reports cybersecurity updates to the Ares ERC. The Ares ERC is a committee that governs and oversees the Ares Enterprise Risk Program, including cybersecurity. The Ares ERC includes members of Ares’ senior executive management, including its CEO, Co-Presidents, CFO, General Counsel, Global Chief Compliance Officer and Head of Enterprise Risk, who acts as chairperson of the Ares ERC. The Ares ERC, through regular consultation with the Ares internal cybersecurity team and representatives from our Advisor, assesses, discusses, and prioritizes Ares’ approach to high-level risks, mitigating controls, and ongoing cybersecurity efforts.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Ares ERC
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The team is led by Ares’ CISO, who has a Master’s degree in Cybersecurity from Brown University and over 25 years of experience advising on and managing risks from cybersecurity threats as well as developing and implementing cybersecurity policies and procedures.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Ares ERC, through regular consultation with the Ares internal cybersecurity team and representatives from our Advisor, assesses, discusses, and prioritizes Ares’ approach to high-level risks, mitigating controls, and ongoing cybersecurity efforts.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef