|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Under the guidance of our Chief Information Officer and Director of Enterprise Information Security, we have adopted cybersecurity risk management processes that are informed by the ISO 27000 framework and take a risk based approach to improving capabilities, addressing vulnerability, and performing detection and response activities against cyber events.
We have also implemented a process to require our employees, contractors, and consultants to complete annual cybersecurity training that is designed to raise awareness of cybersecurity threats and risks through training and simulations. Our cybersecurity risk management processes also include dedicated teams, tools, and processes focused on the reduction of vulnerability and exposures, risk management, and incident detection, investigation, and remediation. We have also engaged in reviews of vendor cybersecurity risk, including through review of certain vendor certifications.We also rely on a managed detection and response service provider that helps us manage cybersecurity risks, monitors our environment, and is retained to provide incident response services. We have also engaged other third-party cybersecurity experts to conduct periodic audits and testing of our processes and systems.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Under the guidance of our Chief Information Officer and Director of Enterprise Information Security, we have adopted cybersecurity risk management processes that are informed by the ISO 27000 framework and take a risk based approach to improving capabilities, addressing vulnerability, and performing detection and response activities against cyber events
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The Board has overall oversight responsibility for our risk management, and delegates its oversight of cybersecurity risk assessment and management guidelines to the Audit Committee. The Audit Committee reviews and makes recommendations to management or the Board on matters relating to cybersecurity. Management provides quarterly updates to the Audit Committee and an annual update to the Board. These discussions may include updates on threat focus, roadmaps covering planned improvements, status updates on key improvements efforts, overview information on any recent incidents or significant vulnerabilities (if any), and the status of key information security initiatives. Three of our Board members have received cybersecurity training and certification from the National Association of Corporate Directors (NACD).
Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security. The CIO is responsible for the management of cybersecurity risks and the associated capabilities are developed and operated under the Director of Enterprise Information Security. The Director of Enterprise Information Security has a Masters degree in Information Security Engineering. Other leaders and contributors on the cybersecurity team have experience in information assurance, digital forensics, network security, and information technology. Several members of the team hold over 15 years of cybersecurity experience and over 20 years of information technology experience, and hold cybersecurity and vendor certifications. The Director of Enterprise Information Security provides regular updates on the cybersecurity program to key executives including the CIO and CFO.
As of this filing, we have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us. However, like other companies in our industry, we and our third-party vendors have from time to time experienced threats to and security incidents relating to information systems. For more information, please see the section entitled "Item 1A. Risk Factors—Risks Related to Our Business Operations."
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security. The CIO is responsible for the management of cybersecurity risks and the associated capabilities are developed and operated under the Director of Enterprise Information Security.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security. The CIO is responsible for the management of cybersecurity risks and the associated capabilities are developed and operated under the Director of Enterprise Information Security. The Director of Enterprise Information Security has a Masters degree in Information Security Engineering. Other leaders and contributors on the cybersecurity team have experience in information assurance, digital forensics, network security, and information technology. Several members of the team hold over 15 years of cybersecurity experience and over 20 years of information technology experience, and hold cybersecurity and vendor certifications. The Director of Enterprise Information Security provides regular updates on the cybersecurity program to key executives including the CIO and CFO.
|Cybersecurity Risk Role of Management [Text Block]
|Management provides quarterly updates to the Audit Committee and an annual update to the Board. These discussions may include updates on threat focus, roadmaps covering planned improvements, status updates on key improvements efforts, overview information on any recent incidents or significant vulnerabilities (if any), and the status of key information security initiatives. Three of our Board members have received cybersecurity training and certification from the National Association of Corporate Directors (NACD).
Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security. The CIO is responsible for the management of cybersecurity risks and the associated capabilities are developed and operated under the Director of Enterprise Information Security. The Director of Enterprise Information Security has a Masters degree in Information Security Engineering. Other leaders and contributors on the cybersecurity team have experience in information assurance, digital forensics, network security, and information technology. Several members of the team hold over 15 years of cybersecurity experience and over 20 years of information technology experience, and hold cybersecurity and vendor certifications. The Director of Enterprise Information Security provides regular updates on the cybersecurity program to key executives including the CIO and CFO.
As of this filing, we have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us. However, like other companies in our industry, we and our third-party vendors have from time to time experienced threats to and security incidents relating to information systems. For more information, please see the section entitled "Item 1A. Risk Factors—Risks Related to Our Business Operations."
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Director of Enterprise Information Security has a Masters degree in Information Security Engineering. Other leaders and contributors on the cybersecurity team have experience in information assurance, digital forensics, network security, and information technology. Several members of the team hold over 15 years of cybersecurity experience and over 20 years of information technology experience, and hold cybersecurity and vendor certifications.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Management provides quarterly updates to the Audit Committee and an annual update to the Board. These discussions may include updates on threat focus, roadmaps covering planned improvements, status updates on key improvements efforts, overview information on any recent incidents or significant vulnerabilities (if any), and the status of key information security initiatives. Three of our Board members have received cybersecurity training and certification from the National Association of Corporate Directors (NACD).
Our cybersecurity program is led by our Chief Information Officer (CIO) and Director of Enterprise Information Security. The CIO is responsible for the management of cybersecurity risks and the associated capabilities are developed and operated under the Director of Enterprise Information Security. The Director of Enterprise Information Security has a Masters degree in Information Security Engineering. Other leaders and contributors on the cybersecurity team have experience in information assurance, digital forensics, network security, and information technology. Several members of the team hold over 15 years of cybersecurity experience and over 20 years of information technology experience, and hold cybersecurity and vendor certifications. The Director of Enterprise Information Security provides regular updates on the cybersecurity program to key executives including the CIO and CFO.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef