|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
The Company has no employees and is externally managed by our Manager, which is a wholly owned subsidiary of CTO, a publicly traded diversified REIT. Pursuant to the terms of the Management Agreement, our Manager manages, operates and administers our day-to-day operations, business and affairs, subject to the direction and supervision of the Board. The Board recognizes the critical importance of maintaining the trust and confidence of our tenants and business partners. The Board plays an active role in overseeing management of our risks, and cybersecurity represents an important component of the Company’s overall approach to risk management and oversight.
As an externally managed company, the Company relies on CTO’s information systems in connection with the Company’s day-to-day operations. Consequently, the Company also relies on the processes for assessing, identifying, and managing material risks from cybersecurity threats undertaken by CTO. All of the Company’s executive officers are executive officers and employees of CTO, and one of the Company’s officers (John P. Albright) is also a member of CTO’s board of directors.
CTO’s cybersecurity processes and practices are integrated into CTO’s risk management and oversight program. In general, CTO seeks to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that CTO collects and stores by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur. CTO utilizes a third-party managed IT service provider (the “MSP”) to provide comprehensive cybersecurity services for the Company, including threat detection and response, vulnerability assessment and monitoring, security incident response and recovery, and cybersecurity education and awareness. The Company has adopted a written information security incident response plan, which, as discussed below, is overseen by the Audit Committee of the Board (the “Audit Committee”).
Risk Management and Strategy
The Company’s cybersecurity program is focused on the following key areas:
CTO and the MSP engage in the periodic assessment and testing of CTO’s policies, standards, processes and practices that are designed to address cybersecurity threats and incidents. These efforts include a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of CTO’s cybersecurity measures and planning. The MSP regularly assesses CTO’s cybersecurity measures, including information security maturity, and regularly reviews CTO’s information security control environment and operating effectiveness. The results of such assessments, audits and reviews will be reported to the Audit Committee and the Board, and CTO will adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
CTO’s cybersecurity processes and practices are integrated into CTO’s risk management and oversight program. In general, CTO seeks to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that CTO collects and stores by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur. CTO utilizes a third-party managed IT service provider (the “MSP”) to provide comprehensive cybersecurity services for the Company, including threat detection and response, vulnerability assessment and monitoring, security incident response and recovery, and cybersecurity education and awareness. The Company has adopted a written information security incident response plan, which, as discussed below, is overseen by the Audit Committee of the Board (the “Audit Committee”).
Risk Management and Strategy
The Company’s cybersecurity program is focused on the following key areas:
CTO and the MSP engage in the periodic assessment and testing of CTO’s policies, standards, processes and practices that are designed to address cybersecurity threats and incidents. These efforts include a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of CTO’s cybersecurity measures and planning. The MSP regularly assesses CTO’s cybersecurity measures, including information security maturity, and regularly reviews CTO’s information security control environment and operating effectiveness. The results of such assessments, audits and reviews will be reported to the Audit Committee and the Board, and CTO will adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance
The Board, in coordination with the Audit Committee, oversees the Company’s cybersecurity risk management process. The Audit Committee has adopted a charter that provides that the Audit Committee must review and discuss with the Company’s management team the Company’s privacy and cybersecurity risk exposures, including:
The charter of the Audit Committee also provides that the Audit Committee may receive additional training in cybersecurity and data privacy matters to enable its oversight of such risks and that the Audit Committee will regularly
report to the Board the substance of such reviews and discussions and, as necessary, recommend to the Board such actions as the Audit Committee deems appropriate.
As noted above, the Company relies on CTO’s information systems and the MSP in connection with the Company’s day-to-day operations. Consequently, the Company also relies on the processes for assessing, identifying, and managing material risks from cybersecurity threats undertaken by CTO. All of the Company’s executive officers are executive officers and employees of CTO, and one of the Company’s officers (John P. Albright) is also a member of CTO’s board of directors.
CTO’s Senior Vice President, Chief Financial Officer and Treasurer, Senior Vice President, General Counsel and Corporate Secretary, and Senior Vice President, Chief Accounting Officer work collaboratively with the MSP to implement a program designed to protect CTO’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with written information security incident response plans adopted by CTO and the Company. These members of CTO’s management team, together with the MSP, monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and will report such threats and incidents to the Audit Committee when appropriate.
CTO’s Senior Vice President, Chief Financial Officer and Treasurer, Senior Vice President, General Counsel and Corporate Secretary, and Senior Vice President, Chief Accounting Officer each hold degrees in their respective fields, and have approximately 20 years or more of experience managing risks at CTO, the Company and similar companies, including risks arising from cybersecurity threats.
Cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to affect the Company, including its business strategy, results of operations or financial condition.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
The Board, in coordination with the Audit Committee, oversees the Company’s cybersecurity risk management process. The Audit Committee has adopted a charter that provides that the Audit Committee must review and discuss with the Company’s management team the Company’s privacy and cybersecurity risk exposures, including:
The charter of the Audit Committee also provides that the Audit Committee may receive additional training in cybersecurity and data privacy matters to enable its oversight of such risks and that the Audit Committee will regularly
report to the Board the substance of such reviews and discussions and, as necessary, recommend to the Board such actions as the Audit Committee deems appropriate.
|Cybersecurity Risk Role of Management [Text Block]
|
The Company’s cybersecurity program is focused on the following key areas:
CTO and the MSP engage in the periodic assessment and testing of CTO’s policies, standards, processes and practices that are designed to address cybersecurity threats and incidents. These efforts include a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of CTO’s cybersecurity measures and planning. The MSP regularly assesses CTO’s cybersecurity measures, including information security maturity, and regularly reviews CTO’s information security control environment and operating effectiveness. The results of such assessments, audits and reviews will be reported to the Audit Committee and the Board, and CTO will adjust its cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|CTO
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
CTO’s Senior Vice President, Chief Financial Officer and Treasurer, Senior Vice President, General Counsel and Corporate Secretary, and Senior Vice President, Chief Accounting Officer each hold degrees in their respective fields, and have approximately 20 years or more of experience managing risks at CTO, the Company and similar companies, including risks arising from cybersecurity threats.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
CTO’s Senior Vice President, Chief Financial Officer and Treasurer, Senior Vice President, General Counsel and Corporate Secretary, and Senior Vice President, Chief Accounting Officer work collaboratively with the MSP to implement a program designed to protect CTO’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with written information security incident response plans adopted by CTO and the Company. These members of CTO’s management team, together with the MSP, monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and will report such threats and incidents to the Audit Committee when appropriate.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef