|
Cybersecurity Risk Management, Strategy, and Governance Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity.
Cybersecurity Risk Management and Strategy
We continuously monitor our information systems to assess, identify, and manage risks from vulnerabilities and assess cybersecurity threats. Our process for identifying and assessing material risks from cybersecurity threats operates alongside our broader overall risk assessment process. We monitor risks through routine security assessments and implementation of enhancements to security measures used to protect our systems and data. We address system alerts on an ongoing basis. We maintain an Incident Response Plan Policy ("IRP") that sets forth processes we will follow to address incidents defined therein to include actual or reasonably suspected cyber incidents. Our information technology team promptly responds to system alerts and reported incidents that indicate the suspected presence of an incident and escalates in accordance with the IRP. The IRP, among other things, provides for a cross-functional team consisting of representatives from informational technology, risk management, legal, and communications, an Incident Response Team ("IRT"), that collaborates to quickly assess the impact, mitigate risks to information systems, and resolve incidents while improving information systems. Depending on the incident, we may utilize third-parties for assistance in investigating and addressing cybersecurity incidents.
We also utilize certain third-party service providers to perform a variety of critical business functions and recognize that we are exposed to cybersecurity threats associated with our use of third-party service providers. We have certain vendor management processes designed to help manage cybersecurity risks associated with our use of certain of these providers. Additionally, we strive to minimize cybersecurity risks when we first select or renew a vendor by including cybersecurity risk as part of our overall vendor evaluation and due diligence process.
We have not had cyber incidents that have materially affected our business or financial condition. For details about our risks associated with cybersecurity threats, see “—Computer system interruptions or security breaches of our information systems could significantly disrupt our product development programs and our ability to operate our business.” in the section titled “Risk Factors” in Part I, Item 1A in this Annual Report on Form 10-K.
Governance Related to Cybersecurity Risks
Management is responsible for identifying and assessing material risks for the business on an ongoing basis, including in relation to cybersecurity. As part of this process, our IRT is tasked with implementing and maintaining our cybersecurity programs, including establishing processes to ensure that potential cybersecurity risk exposures are monitored and putting in place appropriate mitigation measures. Our Chief Financial and Business Officer oversees our information technology department which monitors the prevention, detection, mitigation, and remediation of cyber incidents, if any, and reports all potential incidents and an initial assessment of such incident to the IRT. Our Chief Financial and Business Officer has over 7 years of experience with overseeing risk, compliance, and information technology functions.
Our Board of Directors (the "Board") oversees our risk management program as part of its general oversight function. The Board’s Audit Committee is delegated the responsibility for reviewing and discussing with management our program to identify, assess, manage, and monitor significant business risks, including financial, operational, privacy, business continuity, legal and regulatory, reputation risks, and security, including cybersecurity. The Audit Committee receives quarterly updates from management regarding investigated incidents and periodic updates from management regarding cybersecurity matters (including the current threat landscape and cybersecurity risks). The Audit Committee may provide updates to the Board on the substance of these reports and any recommendations for improvements that the Audit Committee deems appropriate.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board of Directors (the "Board") oversees our risk management program as part of its general oversight function. The Board’s Audit Committee is delegated the responsibility for reviewing and discussing with management our program to identify, assess, manage, and monitor significant business risks, including financial, operational, privacy, business continuity, legal and regulatory, reputation risks, and security, including cybersecurity. The Audit Committee receives quarterly updates from management regarding investigated incidents and periodic updates from management regarding cybersecurity matters (including the current threat landscape and cybersecurity risks). The Audit Committee may provide updates to the Board on the substance of these reports and any recommendations for improvements that the Audit Committee deems appropriate.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board’s Audit Committee is delegated the responsibility for reviewing and discussing with management our program to identify, assess, manage, and monitor significant business risks, including financial, operational, privacy, business continuity, legal and regulatory, reputation risks, and security, including cybersecurity. The Audit Committee receives quarterly updates from management regarding investigated incidents and periodic updates from management regarding cybersecurity matters (including the current threat landscape and cybersecurity risks).
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee may provide updates to the Board on the substance of these reports and any recommendations for improvements that the Audit Committee deems appropriate.
|Cybersecurity Risk Role of Management [Text Block]
|
Management is responsible for identifying and assessing material risks for the business on an ongoing basis, including in relation to cybersecurity. As part of this process, our IRT is tasked with implementing and maintaining our cybersecurity programs, including establishing processes to ensure that potential cybersecurity risk exposures are monitored and putting in place appropriate mitigation measures. Our Chief Financial and Business Officer oversees our information technology department which monitors the prevention, detection, mitigation, and remediation of cyber incidents, if any, and reports all potential incidents and an initial assessment of such incident to the IRT. Our Chief Financial and Business Officer has over 7 years of experience with overseeing risk, compliance, and information technology functions.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our Chief Financial and Business Officer oversees our information technology department which monitors the prevention, detection, mitigation, and remediation of cyber incidents
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our Chief Financial and Business Officer has over 7 years of experience with overseeing risk, compliance, and information technology functions.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|As part of this process, our IRT is tasked with implementing and maintaining our cybersecurity programs, including establishing processes to ensure that potential cybersecurity risk exposures are monitored and putting in place appropriate mitigation measures. Our Chief Financial and Business Officer oversees our information technology department which monitors the prevention, detection, mitigation, and remediation of cyber incidents, if any, and reports all potential incidents and an initial assessment of such incident to the IRT.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef