|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy
We maintain a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats. The underlying processes and controls of our program incorporate recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”). The program is subject to annual risk assessment by a third-party consultant to ensure compliance with the standards of the NIST CSF and to identify, quantify and categorize material cyber risks. In addition, with the assistance of the consultant, we have developed a risk mitigation plan to address cyber risks, and where necessary, remediate potential vulnerabilities.
Under this program, we employ additional key practices including, but not limited to, maintenance of an information technology (“IT”) assets inventory, quarterly vulnerability testing, identity access management controls including restricted access of privileged accounts, physical security measures at our offices, maintenance of firewalls and anti-malware tools, ongoing cybersecurity user awareness training, industry-standard encryption protocols, and critical data backups.
Our cybersecurity partners, including a technology consultant and other relevant third-party service providers, are a key part of our cybersecurity risk management strategy and infrastructure. We partner with industry recognized cybersecurity providers leveraging third-party technology and expertise and engage with these partners to maintain the performance and effectiveness of IT assets, data, and services. The cybersecurity partners provide services including, but not limited to, systems inventory management, vulnerability testing, user management, capacity monitoring, network protection, remote access management, data backups management, infrastructure maintenance, and cyber risk advisory, assessment and remediation. We also maintain a disaster recovery plan to help us quickly recover from an incident during a disruption and help mitigate the impact of certain cybersecurity risks.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We maintain a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats. The underlying processes and controls of our program incorporate recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”). The program is subject to annual risk assessment by a third-party consultant to ensure compliance with the standards of the NIST CSF and to identify, quantify and categorize material cyber risks. In addition, with the assistance of the consultant, we have developed a risk mitigation plan to address cyber risks, and where necessary, remediate potential vulnerabilities.
Under this program, we employ additional key practices including, but not limited to, maintenance of an information technology (“IT”) assets inventory, quarterly vulnerability testing, identity access management controls including restricted access of privileged accounts, physical security measures at our offices, maintenance of firewalls and anti-malware tools, ongoing cybersecurity user awareness training, industry-standard encryption protocols, and critical data backups.
Our cybersecurity partners, including a technology consultant and other relevant third-party service providers, are a key part of our cybersecurity risk management strategy and infrastructure. We partner with industry recognized cybersecurity providers leveraging third-party technology and expertise and engage with these partners to maintain the performance and effectiveness of IT assets, data, and services. The cybersecurity partners provide services including, but not limited to, systems inventory management, vulnerability testing, user management, capacity monitoring, network protection, remote access management, data backups management, infrastructure maintenance, and cyber risk advisory, assessment and remediation. We also maintain a disaster recovery plan to help us quickly recover from an incident during a disruption and help mitigate the impact of certain cybersecurity risks.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
We are in the process of formalizing the Audit Committee’s responsibilities to oversee our cybersecurity risk exposure and the steps taken by management to monitor and mitigate cybersecurity risks. Once these responsibilities have been established, the cybersecurity stakeholders, including member(s) of management assigned with cybersecurity oversight responsibility and/or third-party consultants providing cyber risk advisory services will brief the Audit Committee on cyber vulnerabilities identified through the risk management process, the effectiveness of our cyber risk management program, the emerging threat landscape, and new cyber risks on at least an annual basis. This will include updates on our processes to prevent, detect, and mitigate cyber incidents. In addition, material cybersecurity risks and/or events, should they occur, will be reviewed by the Board, at least annually, as part of our corporate risk oversight processes.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
We are in the process of formalizing the Audit Committee’s responsibilities to oversee our cybersecurity risk exposure and the steps taken by management to monitor and mitigate cybersecurity risks. Once these responsibilities have been established, the cybersecurity stakeholders, including member(s) of management assigned with cybersecurity oversight responsibility and/or third-party consultants providing cyber risk advisory services will brief the Audit Committee on cyber vulnerabilities identified through the risk management process, the effectiveness of our cyber risk management program, the emerging threat landscape, and new cyber risks on at least an annual basis. This will include updates on our processes to prevent, detect, and mitigate cyber incidents. In addition, material cybersecurity risks and/or events, should they occur, will be reviewed by the Board, at least annually, as part of our corporate risk oversight processes.
|Cybersecurity Risk Role of Management [Text Block]
|
Our management team, including the IT Manager, in conjunction with third-party IT and cybersecurity service providers is responsible for oversight and administration of our cyber risk management program. Our management team has prior experience selecting, deploying, and overseeing cybersecurity technologies, initiatives, and processes directly or via selection of strategic third-party partners, and relies on threat intelligence as well as other information obtained from governmental, public, or private sources, including external consultants engaged by us for strategic cyber risk management, advisory and decision making.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|management team
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our management team has prior experience selecting, deploying, and overseeing cybersecurity technologies, initiatives, and processes directly or via selection of strategic third-party partners, and relies on threat intelligence as well as other information obtained from governmental, public, or private sources, including external consultants engaged by us for strategic cyber risk management, advisory and decision making.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Once these responsibilities have been established, the cybersecurity stakeholders, including member(s) of management assigned with cybersecurity oversight responsibility and/or third-party consultants providing cyber risk advisory services will brief the Audit Committee on cyber vulnerabilities identified through the risk management process, the effectiveness of our cyber risk management program, the emerging threat landscape, and new cyber risks on at least an annual basis. This will include updates on our processes to prevent, detect, and mitigate cyber incidents. In addition, material cybersecurity risks and/or events, should they occur, will be reviewed by the Board, at least annually, as part of our corporate risk oversight processes.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef