|
Cybersecurity Risk Management, Strategy, and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity.
Cybersecurity Risk Management and Strategy
We have policies, procedures, and processes for assessing, identifying, and managing cybersecurity risks, which are built into our overall information technology function and are designed to help protect our information assets and operations from internal and external cyber threats as well as secure our networks and systems. Such processes include procedural and technical safeguards, response plans, and routine review of our policies and procedures to identify risks and improve our practices. Our security incident response plan is designed to help coordinate our response to, and recovery from, any cybersecurity incidents, and includes processes to assess the severity of, escalate, contain, investigate, and remediate such incidents as well as to comply with applicable legal obligations.
In response to the complexity and evolving nature of cybersecurity threats, incidents and risks, we engage with a range of third-party experts, including cybersecurity penetration testers, data protection services, security awareness and training, and AI based security services in evaluating and supporting our risk management. Our collaboration with these third parties includes regular independent audits, threat assessments, and consultation on security enhancements. Depending on the nature of the services provided, the sensitivity and quantity of information processed, and the identity of the service provider, we evaluate the security and risk posture of third-party service providers according to the perceived level of risk and benchmarked against industry standard best practices.
The Audit Committee of the board of directors provides direct oversight over cybersecurity risk and provides regular updates to the board of directors regarding such oversight. The Audit Committee regularly meets with members of
management responsible for data privacy, technology, and information security risks to discuss these risks, risk management activities, incident response plans, best practices, the effectiveness of our security measures, and other related matters.
Our Information Technology and Cyber Security Manager, who reports to our Chief Financial Officer, leads the operational oversight of company-wide cybersecurity strategy, policy, standards, and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks. Specific cybersecurity related responsibilities of the Information Technology and Cyber Security Manager include overseeing our processes and strategies for the detection, mitigation, and remediation of cybersecurity incidents. Our Information Technology and Cyber Security Manager has over 17 years of experience in information technology and cybersecurity, enabling him to effectively oversee cybersecurity risks and threats. He helped design and implement our initial cybersecurity infrastructure.
In an effort to deter and detect cyber threats, we provide all employees, including any part-time employees, with a data protection, cybersecurity, and incident response and prevention training program designed to educate employees on the importance of identifying and reporting all potential data security incidents immediately. The training covers timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use, and mobile security. We also use technology-based tools to mitigate cybersecurity threats and risks and to bolster our employee-based cybersecurity programs.
We do not believe that there are currently any risks from known cybersecurity threats that have materially affected or are reasonably likely to materially affect us or our business strategy, results of operations or financial condition. Despite our cybersecurity efforts, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. See Part I, Item 1A, Risk Factors, in this Annual Report for a discussion of cybersecurity risks. We maintain cyber insurance coverage; however, such insurance may not be sufficient in type or amount to cover us against claims related to security breaches, cyber-attacks, and other related breaches.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have policies, procedures, and processes for assessing, identifying, and managing cybersecurity risks, which are built into our overall information technology function and are designed to help protect our information assets and operations from internal and external cyber threats as well as secure our networks and systems. Such processes include procedural and technical safeguards, response plans, and routine review of our policies and procedures to identify risks and improve our practices. Our security incident response plan is designed to help coordinate our response to, and recovery from, any cybersecurity incidents, and includes processes to assess the severity of, escalate, contain, investigate, and remediate such incidents as well as to comply with applicable legal obligations.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The Audit Committee of the board of directors provides direct oversight over cybersecurity risk and provides regular updates to the board of directors regarding such oversight. The Audit Committee regularly meets with members of
management responsible for data privacy, technology, and information security risks to discuss these risks, risk management activities, incident response plans, best practices, the effectiveness of our security measures, and other related matters.
Our Information Technology and Cyber Security Manager, who reports to our Chief Financial Officer, leads the operational oversight of company-wide cybersecurity strategy, policy, standards, and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks. Specific cybersecurity related responsibilities of the Information Technology and Cyber Security Manager include overseeing our processes and strategies for the detection, mitigation, and remediation of cybersecurity incidents. Our Information Technology and Cyber Security Manager has over 17 years of experience in information technology and cybersecurity, enabling him to effectively oversee cybersecurity risks and threats. He helped design and implement our initial cybersecurity infrastructure.
In an effort to deter and detect cyber threats, we provide all employees, including any part-time employees, with a data protection, cybersecurity, and incident response and prevention training program designed to educate employees on the importance of identifying and reporting all potential data security incidents immediately. The training covers timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use, and mobile security. We also use technology-based tools to mitigate cybersecurity threats and risks and to bolster our employee-based cybersecurity programs.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee of the board of directors provides direct oversight over cybersecurity risk and provides regular updates to the board of directors regarding such oversight.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee regularly meets with members of
management responsible for data privacy, technology, and information security risks to discuss these risks, risk management activities, incident response plans, best practices, the effectiveness of our security measures, and other related matters.
|Cybersecurity Risk Role of Management [Text Block]
|
Our Information Technology and Cyber Security Manager, who reports to our Chief Financial Officer, leads the operational oversight of company-wide cybersecurity strategy, policy, standards, and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks. Specific cybersecurity related responsibilities of the Information Technology and Cyber Security Manager include overseeing our processes and strategies for the detection, mitigation, and remediation of cybersecurity incidents. Our Information Technology and Cyber Security Manager has over 17 years of experience in information technology and cybersecurity, enabling him to effectively oversee cybersecurity risks and threats. He helped design and implement our initial cybersecurity infrastructure.
In an effort to deter and detect cyber threats, we provide all employees, including any part-time employees, with a data protection, cybersecurity, and incident response and prevention training program designed to educate employees on the importance of identifying and reporting all potential data security incidents immediately. The training covers timely and relevant topics, including social engineering, phishing, password protection, confidential data protection, asset use, and mobile security. We also use technology-based tools to mitigate cybersecurity threats and risks and to bolster our employee-based cybersecurity programs.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Information Technology and Cyber Security Manager, who reports to our Chief Financial Officer, leads the operational oversight of company-wide cybersecurity strategy, policy, standards, and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks. Specific cybersecurity related responsibilities of the Information Technology and Cyber Security Manager include overseeing our processes and strategies for the detection, mitigation, and remediation of cybersecurity incidents. Our Information Technology and Cyber Security Manager has over 17 years of experience in information technology and cybersecurity, enabling him to effectively oversee cybersecurity risks and threats. He helped design and implement our initial cybersecurity infrastructure.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our Information Technology and Cyber Security Manager has over 17 years of experience in information technology and cybersecurity, enabling him to effectively oversee cybersecurity risks and threats. He helped design and implement our initial cybersecurity infrastructure.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Specific cybersecurity related responsibilities of the Information Technology and Cyber Security Manager include overseeing our processes and strategies for the detection, mitigation, and remediation of cybersecurity incidents.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef