|
Cybersecutity Risk Management, Strategy, and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
Cybersecurity Risk Management and Strategy
In an effort to protect our business from cybersecurity threats, we maintain and utilize various tools and processes that are designed to identify, assess, and manage cybersecurity risks. Our cybersecurity risk management program, which has been integrated into our enterprise risk management program, is based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework. Our cybersecurity risk management program focuses on monitoring the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents.
There are a number of components of our risk management program. We leverage external third parties for security testing on an annual basis, including penetration testing. We consistently monitor critical risks from cybersecurity threats using automated tools and have a process to implement mitigation plans. Our Security Committee, headed by the Vice President of IT and the Chief Legal Counsel, assesses and monitors any identified security incidents that impact us or our external partners. Furthermore, we assess and review the cybersecurity practices of third parties who have access to our systems and/or process our sensitive information. This assessment may involve requesting Systems and Organization Controls Type 2 reports (SOC2 reports), conversations with our Vice President of IT, and the inclusion of contractual requirements to maintain data protection safeguards and timely notification if the third party experiences a security incident which may have a critical impact on our business or our data. Additionally, we conduct cybersecurity awareness training for employees during onboarding and throughout the year, and we conduct regular phishing simulations in an effort to raise awareness of spoofed or manipulated electronic communications and other cybersecurity threats.
We face a number of cybersecurity risks in connection with our business. Although such risks have not materially affected us, and we do not believe they are reasonably likely to materially affect us, our business strategy, results of operations or financial condition, we could from time to time, experience threats to and security incidents related to our third-party vendors’ information systems. For more information about the cybersecurity risks we face, see the risk factor entitled “We may be unable to adequately protect our information technology systems from cyberattacks, cyber intrusions or otherwise which could result in damage to our information technology systems and unauthorized disclosure or use of confidential or proprietary information, including personal data” in Item 1A- Risk Factors.
Cybersecurity Governance
Our Board of Directors has delegated responsibility for overseeing our policies, practices and assessments with respect to cybersecurity and other information technology risks to the Audit Committee. Our Vice President of IT, under the supervision of our Chief Financial Officer, is responsible for the establishment and maintenance of our cybersecurity risk management program, including the day-to-day oversight of the assessment and management of cybersecurity risks. The Vice President of IT will regularly consult with outside security experts and management to evaluate certain aspects of the cybersecurity risk management program. The Vice President of IT has approximately 15 years of experience in information security and cybersecurity risk management. The IT team also institutes and maintains controls for our systems, applications, and databases.
The Vice President of IT reports on the status of our cybersecurity risk management program to management and our Audit Committee on a periodic basis, which may include a discussion of the results of our annual third party cybersecurity risk assessments and critical updates to our mitigation and remediation efforts.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|cybersecurity risk management program, which has been integrated into our enterprise risk management program, is based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework. Our cybersecurity risk management program focuses on monitoring the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Our Board of Directors has delegated responsibility for overseeing our policies, practices and assessments with respect to cybersecurity and other information technology risks to the Audit Committee.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors has delegated responsibility for overseeing our policies, practices and assessments with respect to cybersecurity and other information technology risks to the Audit Committee. Our Vice President of IT, under the supervision of our Chief Financial Officer, is responsible for the establishment and maintenance of our cybersecurity risk management program, including the day-to-day oversight of the assessment and management of cybersecurity risks.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Vice President of IT reports on the status of our cybersecurity risk management program to management and our Audit Committee on a periodic basis, which may include a discussion of the results of our annual third party cybersecurity risk assessments and critical updates to our mitigation and remediation efforts.
|Cybersecurity Risk Role of Management [Text Block]
|
Our Board of Directors has delegated responsibility for overseeing our policies, practices and assessments with respect to cybersecurity and other information technology risks to the Audit Committee. Our Vice President of IT, under the supervision of our Chief Financial Officer, is responsible for the establishment and maintenance of our cybersecurity risk management program, including the day-to-day oversight of the assessment and management of cybersecurity risks. The Vice President of IT will regularly consult with outside security experts and management to evaluate certain aspects of the cybersecurity risk management program. The Vice President of IT has approximately 15 years of experience in information security and cybersecurity risk management. The IT team also institutes and maintains controls for our systems, applications, and databases.
The Vice President of IT reports on the status of our cybersecurity risk management program to management and our Audit Committee on a periodic basis, which may include a discussion of the results of our annual third party cybersecurity risk assessments and critical updates to our mitigation and remediation efforts.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Board of Directors has delegated responsibility for overseeing our policies, practices and assessments with respect to cybersecurity and other information technology risks to the Audit Committee. Our Vice President of IT, under the supervision of our Chief Financial Officer, is responsible for the establishment and maintenance of our cybersecurity risk management program, including the day-to-day oversight of the assessment and management of cybersecurity risks. The Vice President of IT will regularly consult with outside security experts and management to evaluate certain aspects of the cybersecurity risk management program. The Vice President of IT has approximately 15 years of experience in information security and cybersecurity risk management. The IT team also institutes and maintains controls for our systems, applications, and databases.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Vice President of IT has approximately 15 years of experience in information security and cybersecurity risk management.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Vice President of IT reports on the status of our cybersecurity risk management program to management and our Audit Committee on a periodic basis, which may include a discussion of the results of our annual third party cybersecurity risk assessments and critical updates to our mitigation and remediation efforts.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef