|
Cybersecurity Risk Management, Strategy, and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
ITEM 1C. CYBERSECURITY
Risk Management Approach and Strategy
Our corporate information technology, accounting and financial reporting platforms, and related systems (our “Information Systems”) are necessary for our business. We use these systems, among others, to manage key aspects of our business, including relationships with our tenants and vendors, accounting, acquisitions, internal and external communications and property and asset management. We also rely on the secure collection, storage, transmission and processing of proprietary, confidential and sensitive data related to our business (our “Sensitive Data”). We engage a third-party managed information technology service provider (the “MSP”) for cybersecurity services, including threat detection and response, vulnerability assessment and monitoring, security incident response and recovery and general cybersecurity education and awareness. Our cybersecurity risk management is integrated into our overall enterprise risk management efforts and shares common methodologies, reporting channels and governance processes that apply across our overall enterprise risk management.
We and our MSP identify, assess and manage material cybersecurity threats and risks to our Information Systems and Sensitive Data through the following, among others:
•
a multidisciplinary team, including a dedicated technology committee (the “Technology Committee”) comprising members from senior management, asset management and accounting and legal functions, in conjunction with our MSP and other third-party service vendors, to identify, assess and manage cybersecurity threats and risks;
•
various internal processes and procedures to monitor and evaluate threat environment and our risk profile using methods such as manual and automated tools, subscribing to reports and services that identify and analyze cybersecurity threats, conducting scans of the threat environment, evaluating our industry’s risk profile, utilizing internal and external audits and conducting threat and vulnerability assessments;
•
various technical, physical and organizational processes and policies to manage and mitigate material cybersecurity risks, such as risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, vendor risk management program, employee training and penetration testing; and
•
working with third-party vendors from time to time that assist us to identify, assess and manage cybersecurity risks, such as professional services firms and penetration testing firms.
•
The Governance Committee is responsible for cybersecurity oversight, we bring any threat to the committee as needed and they review our cybersecurity insurance, incidences, if any, and responses, if any, on an annual or as needed basis.
•
The Director of Operations, has provided oversight of technology efforts for the Company since 2021, and is responsible for notifying the Governance Committee upon receiving cybersecurity incidences immediately, via email.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our cybersecurity risk management is integrated into our overall enterprise risk management efforts and shares common methodologies, reporting channels and governance processes that apply across our overall enterprise risk management.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
We and our MSP identify, assess and manage material cybersecurity threats and risks to our Information Systems and Sensitive Data through the following, among others:
•
a multidisciplinary team, including a dedicated technology committee (the “Technology Committee”) comprising members from senior management, asset management and accounting and legal functions, in conjunction with our MSP and other third-party service vendors, to identify, assess and manage cybersecurity threats and risks;
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
•
a multidisciplinary team, including a dedicated technology committee (the “Technology Committee”) comprising members from senior management, asset management and accounting and legal functions, in conjunction with our MSP and other third-party service vendors, to identify, assess and manage cybersecurity threats and risks;
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|various internal processes and procedures to monitor and evaluate threat environment and our risk profile using methods such as manual and automated tools, subscribing to reports and services that identify and analyze cybersecurity threats
|Cybersecurity Risk Role of Management [Text Block]
|
•
various internal processes and procedures to monitor and evaluate threat environment and our risk profile using methods such as manual and automated tools, subscribing to reports and services that identify and analyze cybersecurity threats, conducting scans of the threat environment, evaluating our industry’s risk profile, utilizing internal and external audits and conducting threat and vulnerability assessments;
•
various technical, physical and organizational processes and policies to manage and mitigate material cybersecurity risks, such as risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, vendor risk management program, employee training and penetration testing; and
•
working with third-party vendors from time to time that assist us to identify, assess and manage cybersecurity risks, such as professional services firms and penetration testing firms.
•
The Governance Committee is responsible for cybersecurity oversight, we bring any threat to the committee as needed and they review our cybersecurity insurance, incidences, if any, and responses, if any, on an annual or as needed basis.
•
The Director of Operations, has provided oversight of technology efforts for the Company since 2021, and is responsible for notifying the Governance Committee upon receiving cybersecurity incidences immediately, via email.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|a multidisciplinary team, including a dedicated technology committee (the “Technology Committee”) comprising members from senior management, asset management and accounting and legal functions
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|various technical, physical and organizational processes and policies to manage and mitigate material cybersecurity risks, such as risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, vendor risk management program, employee training and penetration testing;
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
•
The Governance Committee is responsible for cybersecurity oversight, we bring any threat to the committee as needed and they review our cybersecurity insurance, incidences, if any, and responses, if any, on an annual or as needed basis.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef