|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Material Cybersecurity Incident Nature [Text Block]
|
Risk Management and Strategy
The success of our business operations depends on the security, confidentiality, integrity and availability, of confidential and sensitive information. Such information includes personal information that we collect and process on our own and using systems and platforms provided by our vendors and other third parties on which we rely. Consequently, we maintain a data protection program, which includes physical, technical, and administrative safeguards, designed to identify, prevent, and mitigate the risks posed by cybersecurity threats, and to identify, analyze, address, mitigate and remediate any cybersecurity incidents that may happen in an efficient and timely manner. As part of our program:
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|Such information includes personal information that we collect and process on our own and using systems and platforms provided by our vendors and other third parties on which we rely. Consequently, we maintain a data protection program, which includes physical, technical, and administrative safeguards, designed to identify, prevent, and mitigate the risks posed by cybersecurity threats, and to identify, analyze, address, mitigate and remediate any cybersecurity incidents that may happen in an efficient and timely manner.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The success of our business operations depends on the security, confidentiality, integrity and availability, of confidential and sensitive information.
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|In addition, our Incident Response process is designed to ensure that the Board receives timely notifications and reports, particularly with respect to any material cybersecurity incident, so that they are aware of any material incident and can provide oversight and direction as part of the response and remediation process.
|Cybersecurity Risk Role of Management [Text Block]
|
Cybersecurity Governance
Our Board actively oversees our risk management activities and considers various risk topics throughout the year, including cybersecurity and information security risk management and controls. As part of its oversight function, the Board oversees the Company’s risk assessment and risk management policies, including related to cybersecurity and the data protection program, and performs an annual review and assessment of the primary operational and regulatory risks facing the Company, their relative magnitude and management’s plan for mitigating these risks.
As appropriate, our CTO and Director of InfoSec report to the Board on a broad range of topics, including any significant cybersecurity risks, the status of ongoing projects, future roadmap planning, updates to the company’s PPP, and other relevant updates to our InfoSec operations and stance. In addition, our Incident Response process is designed to ensure that the Board receives timely notifications and reports, particularly with respect to any material cybersecurity incident, so that they are aware of any material incident and can provide oversight and direction as part of the response and remediation process.
Our senior management is responsible for assessing and managing the Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including the identification of risks through an enterprise risk management framework and the creation of appropriate risk management programs and policies to address such risks. Our Risk Management Committee is responsible for assessing and categorizing any significant identifiable risks and presenting them to senior management in a timely manner along with recommendations on how to manage these identified risks. All potential risks are identified, quantified, and categorized in such a manner that they can be ranked and presented to senior management for appropriate disposition (such as avoidance, acceptance, mitigation, etc.). Our CTO and Director of InfoSec have the primary responsibility for managing our cybersecurity program and efforts. We perform internal audits of our internal information technology controls and implementation, and we carry out a tabletop exercise at least once each year to determine our ability to respond to cybersecurity incidents in an effective and efficient manner.
Our information technology team have decades of operational experience both in private as well as classified government settings, advanced degrees in the information technology field from accredited universities, certifications within their areas of expertise (e.g., Certified Information Systems Security Professional (CISSP), Operating Systems Certifications, Network Engineering certifications, etc.).
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our senior management is responsible for assessing and managing the Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including the identification of risks through an enterprise risk management framework and the creation of appropriate risk management programs and policies to address such risks. Our Risk Management Committee is responsible for assessing and categorizing any significant identifiable risks and presenting them to senior management in a timely manner along with recommendations on how to manage these identified risks. All potential risks are identified, quantified, and categorized in such a manner that they can be ranked and presented to senior management for appropriate disposition (such as avoidance, acceptance, mitigation, etc.).
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef