|
Cybersecurity Risk Management, Strategy, and Governance
|12 Months Ended
Mar. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
The Company’s Audit Committee is responsible for overseeing the Company’s internal controls including oversight over our risk management program and cybersecurity. Management is responsible for the day-to-day administration of the Company’s risk management program and its cybersecurity policies, processes, and practices. The Company’s cybersecurity policies, standards, processes, and practices are based on recognized frameworks established by the National Institute of Standards and Technology and the International Organization for Standardization and are standalone from the Company’s overall risk management system and processes. The Company seeks to address all material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of the Company’s information systems or the information that the Company collects and stores, by assessing, identifying and managing cybersecurity issues as they occur.
Cybersecurity Risk Management and Strategy
The Company’s cybersecurity risk management strategy focuses on several areas:
•
Identification and Reporting: The Company has implemented a comprehensive, cross-functional approach to identifying, and managing material cybersecurity threats and incidents. The Company’s program includes controls and procedures to properly alert, identify, scope, triage, escalate, contain, eradicate mitigate and recover from cybersecurity incidents by providing management visibility and to enable management to take action with respect to reporting of material incidents in a timely manner.
•
Technical Safeguards: Our program consists of layered defenses to enhance resiliency within the system to prevent, detect and respond to any incidents. Our perimeter security includes but is not limited to, proactive threat intelligence via our security partners, firewalls, end-point security agents, email security, vulnerability assessments and scans, proactive patching, and privileged access management. Our detection capabilities include event logging and monitoring such as unsuccessful login attempts, escalated privilege attempts, anomaly detection. Our response capabilities are supplemented by a 3rd party breach response process through our insurer’s cyber panel, which includes access to a breach coach and forensic experts under a tripartite agreement to ensure coordinated response and maintain privilege; security playbooks setting forth a tactical guide to respond to cybersecurity events and threats as they occur; and recovery procedures. We have also implemented various technical safeguards that are designed to protect the Company’s information systems from cybersecurity threats, including: firewalls, intrusion prevention and detection systems, anti-malware functionality, and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence, as well as outside audits and certifications.
•
Incident Response and Recovery Planning: The Company has established and maintains a comprehensive incident response, business continuity, and disaster recovery plans designed to address the Company’s response to a cybersecurity incident. The Company conducts regular tabletop exercises to test these plans and ensure personnel are familiar with their roles in a response scenario.
•
Third-Party Risk Management: The Company maintains a comprehensive, risk-based approach to identifying and overseeing material cybersecurity threats presented by third parties, including vendors, service providers, and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business in the event of a material cybersecurity incident affecting those third-party systems.
•
Education and Awareness: The Company provides regular, mandatory training for all levels of employees regarding cybersecurity threats as a means to equip the Company’s employees with effective tools to address cybersecurity threats, and to communicate the Company’s evolving information security policies, standards, processes, and practices.
The Company conducts periodic assessment and testing of the Company’s policies, standards, processes, and practices in a manner intended to address cybersecurity threats and events. The results of such assessments, audits, and reviews are published in monthly cybersecurity dashboards that are shared with our CFO. Based on the monthly reports, the CFO, with support from the VP of Information Technology, evaluates and provides a summary report to the Audit Committee on an annual basis. We review and train our employees on our cybersecurity policies, standards, processes, and practices annually or more frequently depending on needs identified within the monthly cybersecurity dashboards.
Governance
The Audit Committee oversees the Company’s risk management program, including the management of cybersecurity threats. The Audit Committee receives prompt and timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well as ongoing updates regarding any such risk. On an annual basis, the Audit Committee discusses the Company’s approach to overseeing cybersecurity threats with the Company’s CFO and other members of senior management.
The VP of Information Technology, in coordination with our senior management team, including the CFO, work collaboratively to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans. To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents. Through ongoing communications with these teams, senior management are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
The VP of Information Technology has been with our Company for over six years, previously serving as Director and subsequently Senior Director of Global IT Engineering. Prior to joining our organization, he was the Founder, President, and CEO of RjR Innovations, a recognized North American leader in IT Service Management. Over the course of his 27-year career within the Information Technology industry, he has established himself as a subject matter expert and thought leader, having served as both an ITIL Best Practice Conference and Keynote Speaker at various industry events. Supporting the VP of Information Technology is the Director of Cybersecurity & IT Engineering, a seasoned IT professional with more than 25 years of comprehensive experience spanning infrastructure, cybersecurity, architecture, and operations. He has been with our Company for over five years, during which he has held key roles including Senior Solutions Architect, Global IT Engineering and Network Engineer, Global IT Operations. He has also successfully completed advanced executive programs in cybersecurity leadership, including CISO and CISM certifications.
Material Effects of Cybersecurity Incidents
Risks from cybersecurity threats, have not materially affected and are not reasonably likely to materially impact our operations materially, including our business strategy, results of operations, or financial condition.
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance
The Audit Committee oversees the Company’s risk management program, including the management of cybersecurity threats. The Audit Committee receives prompt and timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well as ongoing updates regarding any such risk. On an annual basis, the Audit Committee discusses the Company’s approach to overseeing cybersecurity threats with the Company’s CFO and other members of senior management.
The VP of Information Technology, in coordination with our senior management team, including the CFO, work collaboratively to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans. To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents. Through ongoing communications with these teams, senior management are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
The VP of Information Technology has been with our Company for over six years, previously serving as Director and subsequently Senior Director of Global IT Engineering. Prior to joining our organization, he was the Founder, President, and CEO of RjR Innovations, a recognized North American leader in IT Service Management. Over the course of his 27-year career within the Information Technology industry, he has established himself as a subject matter expert and thought leader, having served as both an ITIL Best Practice Conference and Keynote Speaker at various industry events. Supporting the VP of Information Technology is the Director of Cybersecurity & IT Engineering, a seasoned IT professional with more than 25 years of comprehensive experience spanning infrastructure, cybersecurity, architecture, and operations. He has been with our Company for over five years, during which he has held key roles including Senior Solutions Architect, Global IT Engineering and Network Engineer, Global IT Operations. He has also successfully completed advanced executive programs in cybersecurity leadership, including CISO and CISM certifications.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
The VP of Information Technology, in coordination with our senior management team, including the CFO, work collaboratively to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans. To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents. Through ongoing communications with these teams, senior management are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Based on the monthly reports, the CFO, with support from the VP of Information Technology, evaluates and provides a summary report to the Audit Committee on an annual basis.
|Cybersecurity Risk Role of Management [Text Block]
|
The VP of Information Technology, in coordination with our senior management team, including the CFO, work collaboratively to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans. To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents. Through ongoing communications with these teams, senior management are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
The VP of Information Technology has been with our Company for over six years, previously serving as Director and subsequently Senior Director of Global IT Engineering. Prior to joining our organization, he was the Founder, President, and CEO of RjR Innovations, a recognized North American leader in IT Service Management. Over the course of his 27-year career within the Information Technology industry, he has established himself as a subject matter expert and thought leader, having served as both an ITIL Best Practice Conference and Keynote Speaker at various industry events. Supporting the VP of Information Technology is the Director of Cybersecurity & IT Engineering, a seasoned IT professional with more than 25 years of comprehensive experience spanning infrastructure, cybersecurity, architecture, and operations. He has been with our Company for over five years, during which he has held key roles including Senior Solutions Architect, Global IT Engineering and Network Engineer, Global IT Operations. He has also successfully completed advanced executive programs in cybersecurity leadership, including CISO and CISM certifications.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
The Audit Committee oversees the Company’s risk management program, including the management of cybersecurity threats. The Audit Committee receives prompt and timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well as ongoing updates regarding any such risk. On an annual basis, the Audit Committee discusses the Company’s approach to overseeing cybersecurity threats with the Company’s CFO and other members of senior management.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
The VP of Information Technology has been with our Company for over six years, previously serving as Director and subsequently Senior Director of Global IT Engineering. Prior to joining our organization, he was the Founder, President, and CEO of RjR Innovations, a recognized North American leader in IT Service Management. Over the course of his 27-year career within the Information Technology industry, he has established himself as a subject matter expert and thought leader, having served as both an ITIL Best Practice Conference and Keynote Speaker at various industry events. Supporting the VP of Information Technology is the Director of Cybersecurity & IT Engineering, a seasoned IT professional with more than 25 years of comprehensive experience spanning infrastructure, cybersecurity, architecture, and operations. He has been with our Company for over five years, during which he has held key roles including Senior Solutions Architect, Global IT Engineering and Network Engineer, Global IT Operations. He has also successfully completed advanced executive programs in cybersecurity leadership, including CISO and CISM certifications.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The VP of Information Technology, in coordination with our senior management team, including the CFO, work collaboratively to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef