|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk management and strategy
The Company’s risk management process includes assessing, identifying and managing material risks from various sources, including those related to cybersecurity. The Company uses information from incident history, industry publications and analysis centers, public news, government information sharing and recognized information security frameworks to inform its risk management program. Management employs a suite of detective and preventative cybersecurity measures including, but not limited to
•Maintaining a vulnerability management program,
•implementing and operating controls over logical access provisioning,
•maintaining an enterprise-wide security awareness program and
•administering periodic trainings.
The Company engages multiple vendors with subject matter and technological expertise in various aspects of cybersecurity management, including continuous threat detection and response coverage, endpoint detection, anti-malware, penetration testing and suspicious activity alerting, among others. When the Company engages third parties, management retains responsibility for the security and resiliency of its information assets. The Company maintains an incident response plan that includes escalation criteria and preliminary materiality assessments to guide business continuity and disclosure objectives.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|
We describe risks related to cybersecurity threats that could materially impact our business strategy, results of operations or financial condition under the heading “Risk Factors.” Material impacts could include loss of access to systems and data, financial costs and reputational harm, among others.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Audit Committee of the Board of Directors (the "Audit Committee") is responsible for receiving periodic updates on cybersecurity and information security risks, reviewing and discussing with management the quality and effectiveness of the Company’s efforts to mitigate such risks and reporting such findings to the Board of Directors. Management informs the Audit Committee about prevention, detection, mitigation and remediation of cybersecurity incidents at least semi-annually and monitors such matters continuously.
In 2025, the oversight over the Company's cybersecurity risk will transition from the Audit Committee to the Board of Directors ("the Board") to align with the Board's oversight of operational risks.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee of the Board of Directors (the "Audit Committee") is responsible for receiving periodic updates on cybersecurity and information security risks, reviewing and discussing with management the quality and effectiveness of the Company’s efforts to mitigate such risks and reporting such findings to the Board of Directors. Management informs the Audit Committee about prevention, detection, mitigation and remediation of cybersecurity incidents at least semi-annually and monitors such matters continuously.
|Cybersecurity Risk Role of Management [Text Block]
|Our Chief Executive Officer ("CEO") is responsible for assessing and managing overall material risks to the Company. With respect to cybersecurity risks, our CEO leverages the collective expertise of the Company’s information security function which reports to our CEO through the Company’s Chief Information Officer. The information security function is staffed with individuals with extensive information security employment experience, including in the financial services sector, educational experience and relevant credentials.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|With respect to cybersecurity risks, our CEO leverages the collective expertise of the Company’s information security function which reports to our CEO through the Company’s Chief Information Officer. The information security function is staffed with individuals with extensive information security employment experience, including in the financial services sector, educational experience and relevant credentials.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Management informs the Audit Committee about prevention, detection, mitigation and remediation of cybersecurity incidents at least semi-annually and monitors such matters continuously.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef