|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|Lafayette Square maintains a cybersecurity program which includes processes for assessing, identifying, and managing
material risks from cybersecurity threats in the form of unauthorized occurrences that could result in adverse effects on the
confidentiality, integrity, or availability of the Company’s information systems (any such occurrence, a “Cybersecurity
Incident”). The Company’s business is dependent on the communications and information systems of the Adviser and other
third-party service providers. The Adviser manages the Company’s day-to-day operations and has implemented a
cybersecurity program that applies to the Company and its operations.
Cybersecurity Program Overview
The Adviser has instituted a cybersecurity program designed to identify, assess, and mitigate cyber risks applicable to the
Company. The cyber risk management program involves risk assessments, implementation of security measures, and
ongoing monitoring of systems and networks, including networks on which the Company relies. The Adviser actively
monitors the current threat landscape in an effort to identify material risks arising from new and evolving cybersecurity
threats, including material risks faced by the Company. The Adviser maintains a comprehensive information security
policy to manage risk which details procedures such as incident response, business continuity and disaster recovery
management plans, penetration testing and quarterly cybersecurity training for all employees. The Adviser (through the
Staffing Agreement with the Administrator) employs a Chief Technology Officer (“CTO”), Bobby Patnaik. Mr. Patnaik
has more than twenty years of experience, including fourteen years in financial services. Prior to joining Lafayette, Mr.
Patnaik worked at Goldman Sachs Asset Management rising to the Global Head of Institutional/Fund Reporting and
Reference Data Technology after spending several years developing and leading middle and back-office technologies. Mr.
Patnaik began his career working for several technology and telecommunication companies, including AT&T and
Verizon.
The Company relies on the Adviser to engage external experts, including cybersecurity assessors, consultants, and auditors
to evaluate cybersecurity measures and risk management processes, including those applicable to the Company. The
Adviser has contracted with Salt Cybersecurity, LLC to serve as a virtual Chief Information Security Officer (“vCISO”)
and perform an annual information security program risk assessment and gap analysis based on the International
Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) standard (ISO/IEC
27001:2013). In addition, our vCISO conducts due diligence on each vendor we utilize to assess their levels of security
when working with Lafayette Square data. The Adviser has also engaged a third-party cybersecurity firm, AG1, Inc. (dba
AgileBlue), to act as Lafayette Square’s outsourced security operation center (“SOC”) and provide continuous monitoring
of Lafayette Square issued devices for potential vulnerabilities with any threats escalated to the CTO.
Management's Role in Cybersecurity Risk Management
The Company’s management, including the Company’s CCO, is responsible for assessing and managing material risks
from cybersecurity threats. Lafayette Square’s information security policy includes an incident response plan which
specifies procedures for elevating, remediating, monitoring and communicating about Cybersecurity Incidents. A dedicated
team of executive level leaders at the Adviser (the “Incident Response Team”) including the Chief Risk Officer, Chief
People Officer, Chief Compliance Officer and led by the Chief Technology Officer ensure Cybersecurity Incident
containment, eradication, recovery and notification that is integrated in Lafayette Square’s overall risk management. If a
Cybersecurity Incident is detected, whether by way of penetration testing, a vulnerability scan conducted by the SOC, or
otherwise, it will be reported to the Chief Technology Officer and Chief Compliance Officer who mobilize the Incident
Response Team. The Incident Response Team will prepare the communications including alerting the Board of any
material risks and any additional required reporting. The Chief Technology Officer is designated as the leader of the
Incident Response Team and is designated to interface with key stakeholders including the Board.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The Adviser has instituted a cybersecurity program designed to identify, assess, and mitigate cyber risks applicable to the
Company. The cyber risk management program involves risk assessments, implementation of security measures, and
ongoing monitoring of systems and networks, including networks on which the Company relies. The Adviser actively
monitors the current threat landscape in an effort to identify material risks arising from new and evolving cybersecurity
threats, including material risks faced by the Company. The Adviser maintains a comprehensive information security
policy to manage risk which details procedures such as incident response, business continuity and disaster recovery
management plans, penetration testing and quarterly cybersecurity training for all employees. The Adviser (through the
Staffing Agreement with the Administrator) employs a Chief Technology Officer (“CTO”), Bobby Patnaik. Mr. Patnaik
has more than twenty years of experience, including fourteen years in financial services. Prior to joining Lafayette, Mr.
Patnaik worked at Goldman Sachs Asset Management rising to the Global Head of Institutional/Fund Reporting and
Reference Data Technology after spending several years developing and leading middle and back-office technologies. Mr.
Patnaik began his career working for several technology and telecommunication companies, including AT&T andVerizon.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Board provides strategic oversight on cybersecurity matters, including risks associated with cybersecurity threats. The
Board receives periodic updates from the Company’s Chief Compliance Officer regarding the overall state of the Adviser’s
cybersecurity program, information on the current threat landscape, and risks from cybersecurity threats and cybersecurityincidents impacting the Company.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Company’s management, including the Company’s CCO, is responsible for assessing and managing material risks
from cybersecurity threats. Lafayette Square’s information security policy includes an incident response plan which
specifies procedures for elevating, remediating, monitoring and communicating about Cybersecurity Incidents. A dedicated
team of executive level leaders at the Adviser (the “Incident Response Team”) including the Chief Risk Officer, Chief
People Officer, Chief Compliance Officer and led by the Chief Technology Officer ensure Cybersecurity Incident
containment, eradication, recovery and notification that is integrated in Lafayette Square’s overall risk management. If a
Cybersecurity Incident is detected, whether by way of penetration testing, a vulnerability scan conducted by the SOC, or
otherwise, it will be reported to the Chief Technology Officer and Chief Compliance Officer who mobilize the Incident
Response Team. The Incident Response Team will prepare the communications including alerting the Board of any
material risks and any additional required reporting. The Chief Technology Officer is designated as the leader of the
Incident Response Team and is designated to interface with key stakeholders including the Board.
Board Oversight of Cybersecurity Risks
The Board provides strategic oversight on cybersecurity matters, including risks associated with cybersecurity threats. The
Board receives periodic updates from the Company’s Chief Compliance Officer regarding the overall state of the Adviser’s
cybersecurity program, information on the current threat landscape, and risks from cybersecurity threats and cybersecurityincidents impacting the Company.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|In addition, our vCISO conducts due diligence on each vendor we utilize to assess their levels of security
when working with Lafayette Square data. The Adviser has also engaged a third-party cybersecurity firm, AG1, Inc. (dba
AgileBlue), to act as Lafayette Square’s outsourced security operation center (“SOC”) and provide continuous monitoringof Lafayette Square issued devices for potential vulnerabilities with any threats escalated to the CTO.
|Cybersecurity Risk Role of Management [Text Block]
|The Incident Response Team will prepare the communications including alerting the Board of any
material risks and any additional required reporting. The Chief Technology Officer is designated as the leader of the
Incident Response Team and is designated to interface with key stakeholders including the Board.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Company’s management, including the Company’s CCO, is responsible for assessing and managing material risks
from cybersecurity threats. Lafayette Square’s information security policy includes an incident response plan which
specifies procedures for elevating, remediating, monitoring and communicating about Cybersecurity Incidents. A dedicated
team of executive level leaders at the Adviser (the “Incident Response Team”) including the Chief Risk Officer, Chief
People Officer, Chief Compliance Officer and led by the Chief Technology Officer ensure Cybersecurity Incident
containment, eradication, recovery and notification that is integrated in Lafayette Square’s overall risk management. If a
Cybersecurity Incident is detected, whether by way of penetration testing, a vulnerability scan conducted by the SOC, or
otherwise, it will be reported to the Chief Technology Officer and Chief Compliance Officer who mobilize the Incident
Response Team. The Incident Response Team will prepare the communications including alerting the Board of any
material risks and any additional required reporting. The Chief Technology Officer is designated as the leader of the
Incident Response Team and is designated to interface with key stakeholders including the Board.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The
Adviser has contracted with Salt Cybersecurity, LLC to serve as a virtual Chief Information Security Officer (“vCISO”)
and perform an annual information security program risk assessment and gap analysis based on the International
Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) standard (ISO/IEC
27001:2013). In addition, our vCISO conducts due diligence on each vendor we utilize to assess their levels of security
when working with Lafayette Square data. The Adviser has also engaged a third-party cybersecurity firm, AG1, Inc. (dba
AgileBlue), to act as Lafayette Square’s outsourced security operation center (“SOC”) and provide continuous monitoringof Lafayette Square issued devices for potential vulnerabilities with any threats escalated to the CTO.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Company’s management, including the Company’s CCO, is responsible for assessing and managing material risks
from cybersecurity threats. Lafayette Square’s information security policy includes an incident response plan which
specifies procedures for elevating, remediating, monitoring and communicating about Cybersecurity Incidents. A dedicated
team of executive level leaders at the Adviser (the “Incident Response Team”) including the Chief Risk Officer, Chief
People Officer, Chief Compliance Officer and led by the Chief Technology Officer ensure Cybersecurity Incident
containment, eradication, recovery and notification that is integrated in Lafayette Square’s overall risk management. If a
Cybersecurity Incident is detected, whether by way of penetration testing, a vulnerability scan conducted by the SOC, or
otherwise, it will be reported to the Chief Technology Officer and Chief Compliance Officer who mobilize the Incident
Response Team. The Incident Response Team will prepare the communications including alerting the Board of any
material risks and any additional required reporting. The Chief Technology Officer is designated as the leader of the
Incident Response Team and is designated to interface with key stakeholders including the Board.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef