XML 56 R31.htm IDEA: XBRL DOCUMENT v3.25.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We invest in information security and data privacy measures to safeguard our systems and data. This includes organizational investments, incident response plans, technical defenses, and employee training. We also utilize a third party to conduct vulnerability scans. Our approach to cyber-security risk management is designed to identify, assess, prioritize and manage major risk exposures that could affect our ability to execute our corporate strategy and fulfill our business objectives.
For instance, we utilize our existing information security measures to oversee operational landscapes, address suspicious events, and generate necessary reports shared during our monthly meetings. Additionally, as deemed necessary,
we request third-party service providers to furnish System and Organization Controls (“SOC”) reports. Simultaneously, we are in the process of revising and formulating new IT policies, standards, and procedures in harmony with certain measures from the National Institute of Standards and Technology Cybersecurity framework and security requirements that may be applicable under privacy law, such as the General Data Protection Regulation (GDPR).
In 2024, we continued to mature our enterprise-wide communication initiative, focusing on cyber threats. This ongoing effort educates employees on recognizing and responding to potential cyber threats effectively, while continuously exploring new ways to engage and inform stakeholders about evolving threats. It serves as a reminder of the critical role each individual plays in safeguarding our organization's security.
We maintain the availability of cybersecurity consultants as required and regularly conduct vulnerability scans within our environment to identify areas for ongoing enhancements. Additionally, our IT General Controls (ITGC) undergo audits, encompassing processes that overlap with cybersecurity concerns such as access control, permissions, and robust password management. The insights derived from these and other assessments guide us in refining our information security practices, procedures, and technologies.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company is committed to developing robust governance and oversight of cybersecurity risks and to implementing processes, controls and technologies designed to help assess, identify, and manage material risks.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Additionally, as part of its broader risk oversight, the Board of Directors of the Company oversees risks from information security threats both directly and through the Audit Committee of the Board of Directors of the Company. As reflected in its charter, the Audit Committee is required to periodically review and receive reports from management regarding risks and exposures related to information technology and cyber security.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Cybersecurity Steering Committee convenes no less than quarterly to evaluate and address significant risks stemming from cybersecurity threats.
Additionally, as part of its broader risk oversight, the Board of Directors of the Company oversees risks from information security threats both directly and through the Audit Committee of the Board of Directors of the Company. As reflected in its charter, the Audit Committee is required to periodically review and receive reports from management regarding risks and exposures related to information technology and cyber security.
The Vice President of IT submits reports to the Audit Committee and other senior management members as appropriate. These reports provide insights into the evolving threat landscape, updates on the organization's cyber risks and threats, evaluations of the information security program, and the status of initiatives aimed at improving the information security program and its systems.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Vice President of IT submits reports to the Audit Committee and other senior management members as appropriate. These reports provide insights into the evolving threat landscape, updates on the organization's cyber risks and threats, evaluations of the information security program, and the status of initiatives aimed at improving the information security program and its systems.
Cybersecurity Risk Role of Management [Text Block]
The Vice President of IT is responsible for Li-Cycle's information security program. In this capacity, the executive oversees the enterprise-wide cybersecurity strategy, ensuring the development of policies and standards, the implementation of processes, and the management of architectural elements. The Vice President of IT is responsible for assessing and managing material risks from cybersecurity threats, and is supported in delivering this function with a dedicated internal IT team. The Vice President of IT has over nine years of leadership experience as a Chief Information Officer and Chief Technology Officer, with experience overseeing information security, risk management, and compliance functions.
The Cybersecurity Steering Committee convenes no less than quarterly to evaluate and address significant risks stemming from cybersecurity threats.
Additionally, as part of its broader risk oversight, the Board of Directors of the Company oversees risks from information security threats both directly and through the Audit Committee of the Board of Directors of the Company. As reflected in its charter, the Audit Committee is required to periodically review and receive reports from management regarding risks and exposures related to information technology and cyber security.
The Vice President of IT submits reports to the Audit Committee and other senior management members as appropriate. These reports provide insights into the evolving threat landscape, updates on the organization's cyber risks and threats, evaluations of the information security program, and the status of initiatives aimed at improving the information security program and its systems.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Vice President of IT is responsible for Li-Cycle's information security program. In this capacity, the executive oversees the enterprise-wide cybersecurity strategy, ensuring the development of policies and standards, the implementation of processes, and the management of architectural elements. The Vice President of IT is responsible for assessing and managing material risks from cybersecurity threats, and is supported in delivering this function with a dedicated internal IT team.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Vice President of IT has over nine years of leadership experience as a Chief Information Officer and Chief Technology Officer, with experience overseeing information security, risk management, and compliance functions.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Cybersecurity Steering Committee convenes no less than quarterly to evaluate and address significant risks stemming from cybersecurity threats.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true