|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy
We recognize the paramount importance of cybersecurity in preserving the integrity, confidentiality, and availability of our systems, data, and operations. Our cybersecurity program is designed to identify, assess, monitor, and manage material risks from cybersecurity threats. We have developed a comprehensive approach based on recognized frameworks including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and industry best practices.
Our cybersecurity program employs a defense-in-depth strategy that implements multiple layers of controls to protect our digital assets:
We conduct regular risk assessments of our infrastructure, applications, and processes to identify vulnerabilities and implement appropriate controls. These assessments incorporate:
All employees undergo mandatory security awareness training upon hiring and annually thereafter. This training covers best practices, emerging threats such as phishing and social engineering, and incident response procedures. We also conduct regular phishing simulation exercises to reinforce training and identify areas for improvement.
Industry Engagement and Staying Current
We maintain current with evolving cybersecurity threats, technologies, and best practices through:
Third-Party Risk Management
Our-party risk management program is integrated into our overall cybersecurity strategy. We recognize the significant challenges posed by the need to govern -party service providers and vendors, and have implemented robust processes to oversee and manage these risks:
Before sharing or allowing the hosting of sensitive data in computing environments managed by third parties, we conduct thorough information security assessments. All third parties with access to our information systems must review and acknowledge our acceptable use policy before access is granted.
Incident Response and Business Continuity
We maintain a formal incident response plan with clearly defined roles, responsibilities, and procedures for:
Our incident response procedures include escalation protocols to notify appropriate members of senior and executive management, the Board, and regulatory authorities in a timely manner based on the criticality of the cybersecurity incident. We conduct regular tabletop exercises and simulations to test the effectiveness of our response capabilities.
We also maintain business continuity and disaster recovery plans to ensure operational resilience in the event of a significant cybersecurity incident. These plans are regularly tested and updated based on lessons learned from exercises and actual incidents.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We recognize the paramount importance of cybersecurity in preserving the integrity, confidentiality, and availability of our systems, data, and operations. Our cybersecurity program is designed to identify, assess, monitor, and manage material risks from cybersecurity threats. We have developed a comprehensive approach based on recognized frameworks including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and industry best practices.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|As of December 31, 2024, we have not experienced any cybersecurity incidents that have materially affected our operations, business strategy, financial condition, or financial results. Our management has assessed known cybersecurity incidents for potential materiality and disclosure using formal documented processes.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance and Personnel
The Audit Committee of our Board of Directors provides oversight of our cybersecurity program. The committee receives annual briefings from IT management on:
Primary responsibility for assessing, monitoring, and managing our cybersecurity risks rests with our Senior Vice-President of IT, who has over 20 years of experience in information technology and cybersecurity, including a Bachelor of Science degree. Our SVP of IT reports directly to our Chief Executive Officer on a monthly basis and is responsible for updates to the Audit Committee regarding our cybersecurity posture and initiatives.
Our IT department includes staff members who hold certifications in security, networking, and systems administration. This team of qualified professionals works collaboratively to implement and maintain our comprehensive cybersecurity program. Their specialized expertise is supplemented by strategic partnerships with third-party security providers who hold additional industry-recognized certifications such as CISSP, CISM, CEH, and CompTIA Security+.
Our IT team is responsible for:
In the event of a material cybersecurity incident, our SVP of IT is responsible for promptly reporting to the CEO and the Audit Committee. A special meeting of the Audit Committee or full Board may be convened as necessary to address significant cybersecurity matters.
Material Incidents
As of December 31, 2024, we have not experienced any cybersecurity incidents that have materially affected our operations, business strategy, financial condition, or financial results. Our management has assessed known cybersecurity incidents for potential materiality and disclosure using formal documented processes.
While we have implemented extensive measures to fortify our defenses against cyber threats, it is important to acknowledge that the cybersecurity landscape is constantly evolving, with threat actors employing increasingly sophisticated tactics. Despite our best efforts, we cannot guarantee that our systems will be completely immune to cyber attacks. We remain vigilant in our efforts to protect our systems and data and continue to invest in our cybersecurity program to address emerging threats.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee of our Board of Directors provides oversight of our cybersecurity program. The committee receives annual briefings from IT management on:
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Primary responsibility for assessing, monitoring, and managing our cybersecurity risks rests with our Senior Vice-President of IT, who has over 20 years of experience in information technology and cybersecurity, including a Bachelor of Science degree. Our SVP of IT reports directly to our Chief Executive Officer on a monthly basis and is responsible for updates to the Audit Committee regarding our cybersecurity posture and initiatives.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef