|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy
We have developed and implemented a cybersecurity risk management policy intended to protect the confidentiality, integrity and availability of our critical systems and information. Our policy establishes the framework for managing cybersecurity risks and outlines the measures and protocols to protect our information systems. Our risk management and strategy is managed by our third-party IT Management Service Provider, Network Center, Inc. (“Network Center”) with oversight by our VP of Operations. Our policy applies to all employees, contractors, and all third-party partners who have access to our information systems. Our cybersecurity risk management policy is integrated into our overall enterprise risk management processes.
Our risk management policy includes continual monitoring by Network Center, as they manage our technical defenses. Risk assessments and penetration testing are performed on a quarterly basis to identify and mitigate potential threats. Procedures have been implemented for identifying, evaluating and addressing vulnerabilities. Additionally, vulnerability assessments are performed monthly by Network Center. An additional part of our risk management strategy is having a clear process for reporting cybersecurity incidents and the development and maintenance of an incident response plan to address and mitigate the impact of cybersecurity incidents.
A key component of our risk management and strategy surrounds data protection. We have implemented strict access controls for each individual employee to ensure only authorized personnel can access sensitive and confidential data. All digital communication is pre-screened for potentially malicious actions through a dedicated email security provider. For additional protection, we have implemented multi-factor authentication along with email encryption to ensure data is protected while at rest and in transit. We are also protected through a multilayered approach to security through the ESET Protection Platform, which provides formidable defense through cyber threat prevention, detection and response.
In addition, we provide regular cybersecurity training to all employees on a quarterly basis and conduct ongoing awareness programs to keep employees informed about cybersecurity best practices. Employees have been trained, enabling them to detect and report on any malicious intrusions or social engineering attempts to infiltrate our systems. They are also regularly trained, tested and reported on through KnowB4 spear-phishing email campaigns to ensure our training is effective.
We are fully insured for cyber risk through our insurance provider.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We have developed and implemented a cybersecurity risk management policy intended to protect the confidentiality, integrity and availability of our critical systems and information. Our policy establishes the framework for managing cybersecurity risks and outlines the measures and protocols to protect our information systems. Our risk management and strategy is managed by our third-party IT Management Service Provider, Network Center, Inc. (“Network Center”) with oversight by our VP of Operations. Our policy applies to all employees, contractors, and all third-party partners who have access to our information systems. Our cybersecurity risk management policy is integrated into our overall enterprise risk management processes.
Our risk management policy includes continual monitoring by Network Center, as they manage our technical defenses. Risk assessments and penetration testing are performed on a quarterly basis to identify and mitigate potential threats. Procedures have been implemented for identifying, evaluating and addressing vulnerabilities. Additionally, vulnerability assessments are performed monthly by Network Center. An additional part of our risk management strategy is having a clear process for reporting cybersecurity incidents and the development and maintenance of an incident response plan to address and mitigate the impact of cybersecurity incidents.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Our board of directors is responsible for overseeing our policies and practices related to corporate governance including cybersecurity risks. On an annual basis, management receives a report from Operations Management on our cybersecurity threat risk, management processes, and strategies. In addition to annual meetings, our board of directors, management and Audit Committee are notified of any cybersecurity incident, its threat level and the response. The threat level and response are evaluated and documented in a report by Operations leadership and our IT Services Provider. Based on our board of directors and Audit Committee review of the incident report, they determine if the findings require disclosure to the SEC
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|In addition to annual meetings, our board of directors, management and Audit Committee are notified of any cybersecurity incident, its threat level and the response.
|Cybersecurity Risk Role of Management [Text Block]
|
Our board of directors is responsible for overseeing our policies and practices related to corporate governance including cybersecurity risks. On an annual basis, management receives a report from Operations Management on our cybersecurity threat risk, management processes, and strategies. In addition to annual meetings, our board of directors, management and Audit Committee are notified of any cybersecurity incident, its threat level and the response. The threat level and response are evaluated and documented in a report by Operations leadership and our IT Services Provider. Based on our board of directors and Audit Committee review of the incident report, they determine if the findings require disclosure to the SEC.
Our cyber security policies and procedures are reviewed and updated annually or as needed to address any emerging threats and changes in regulatory requirements.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Operations leadership and our IT Services Provider
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|In addition to annual meetings, our board of directors, management and Audit Committee are notified of any cybersecurity incident, its threat level and the response. The threat level and response are evaluated and documented in a report by Operations leadership and our IT Services Provider.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef