XML 39 R25.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Item 1C. Cybersecurity.

 

We are increasingly dependent on sophisticated software applications and computing infrastructure to conduct key operations. We depend on both our own systems, networks, and technology as well as the systems, networks and technology of our contractors, consultants, vendors and other business partners.

 

Cybersecurity Program

 

Given the importance of cybersecurity to our business, we maintain a robust cybersecurity program to support both the effectiveness of our systems and our preparedness for information security risks. This program includes several safeguards, such as: password protection; multi-factor authentication; code security standards; continuous monitoring and alerting systems for internal and external threats using industry leading platforms; regular evaluations of our cybersecurity program, including periodic internal and external audits, penetration tests, and incident response simulations; and industry benchmarking. We also require cybersecurity trainings when onboarding new employees and contractors, as well as annual cybersecurity awareness training for our employees and contractors. Our program leverages industry frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) to strengthen our program effectiveness and reduce cybersecurity risks.

 

We use a risk-based approach with respect to our use and oversight of third-party service providers, tailoring processes according to the nature and sensitivity of the data accessed, processed, or stored by such third-party service provider and performing additional risk screenings and procedures, as appropriate. We use several means to assess cyber risks related to our third-party service providers, including maintaining a vendor code of conduct and vendor questionnaires, conducting due diligence in connection with onboarding new vendors and annual due diligence with key third-party vendors. We also seek to collect and assess cybersecurity audit reports and other supporting documentation when available and include appropriate security terms in our contracts where applicable as part of our oversight of third-party providers.

 

Process for Assessing, Identifying and Managing Material Risks from Cybersecurity Threats

 

In the event of a cybersecurity incident, we maintain a regularly tested incident response program. Pursuant to the program and its escalation protocols, designated personnel are responsible for assessing the severity of an incident and associated threat, containing the threat, remediating the threat, including recovery of data and access to systems, analyzing any reporting obligations associated with the incident, and performing post-incident analysis and program enhancements. We maintain an Incident Response Plan (“IRP”) and business continuity and disaster recovery plans in the event of a significant cybersecurity incident.

 

We have relationships with several third-party service providers to assist with cybersecurity containment and remediation efforts, including a forensic investigation firm, insurance providers and various law firms.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

Our cybersecurity risk management processes are integrated into our overall Enterprise Risk Management (“ERM”) process. As part of our ERM process, department leaders identify, assess and evaluate risks impacting our operations across the Company, including those risks related to cybersecurity.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]

As of December 31, 2025, we have not experienced any material risks from cybersecurity threats, including as a result of any previous cybersecurity incidents or threats, that have materially affected our business strategy, results of operations or financial condition or are reasonably likely to have such a material effect.

Cybersecurity Risk Board of Directors Oversight [Text Block]

Governance

 

Management Oversight

 

The controls and processes employed to assess, identify, and manage material risks from cybersecurity threats are implemented and overseen by our Chief Information Security Officer (“CISO”). Our CISO leverages their over 20 years of experience in cybersecurity, compliance and risk management. Our CISO is responsible for the day-to-day management of the cybersecurity program, including the prevention, detection, investigation, response to, and recovery from cybersecurity threats and incidents, and are regularly engaged to help ensure the cybersecurity program functions effectively in the face of evolving cybersecurity threats. The CISO provides quarterly briefings for our senior management team on cybersecurity matters, including threats, events, and program enhancements.

 

Board Oversight

 

While the Board has overall responsibility for risk oversight, our Audit Committee oversees cybersecurity risk matters. The Audit Committee is responsible for reviewing, discussing with management, and overseeing the Company’s data privacy, information technology and security and cybersecurity risk exposures, including: (i) the potential impact of those exposures on the Company’s business, financial results, operations and reputation; (ii) the programs and steps implemented by management to monitor and mitigate any exposures; (iii) the Company’s information governance and cybersecurity policies and programs; and (iv) major legislative and regulatory developments that could materially impact the Company’s privacy, data security and cybersecurity risk exposure. On a quarterly basis, the CISO reports to the Audit Committee on cybersecurity matters, including a detailed threat assessment relating to information technology risks, the programs and steps implemented by management to monitor and mitigate exposures, the Company’s information governance and cybersecurity policies and programs, and significant legal/regulatory developments that could materially impact the Company’s cybersecurity risk exposure. The CISO also apprises the Audit Committee of cybersecurity incidents promptly for high priority incidents and in aggregate for low priority incidents. The Audit Committee updates the full Board annually concerning the Company’s cybersecurity matters.

 

Cybersecurity Risks

 

Our cybersecurity risk management processes are integrated into our overall Enterprise Risk Management (“ERM”) process. As part of our ERM process, department leaders identify, assess and evaluate risks impacting our operations across the Company, including those risks related to cybersecurity.

 

While we maintain a robust cybersecurity program, the techniques used to infiltrate information technology systems continue to evolve. Accordingly, we may not be able to timely detect threats or anticipate and implement adequate security measures. For additional information, see “Item 1A—Risk Factors.”

 

We also maintain cybersecurity insurance providing coverage for certain costs related to cybersecurity-related incidents that impact our own systems, networks, and technology or the systems, networks and technology of our contractors, consultants, vendors, and other business partners.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee is responsible for reviewing, discussing with management, and overseeing the Company’s data privacy, information technology and security and cybersecurity risk exposures, including: (i) the potential impact of those exposures on the Company’s business, financial results, operations and reputation; (ii) the programs and steps implemented by management to monitor and mitigate any exposures; (iii) the Company’s information governance and cybersecurity policies and programs; and (iv) major legislative and regulatory developments that could materially impact the Company’s privacy, data security and cybersecurity risk exposure.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] On a quarterly basis, the CISO reports to the Audit Committee on cybersecurity matters, including a detailed threat assessment relating to information technology risks, the programs and steps implemented by management to monitor and mitigate exposures, the Company’s information governance and cybersecurity policies and programs, and significant legal/regulatory developments that could materially impact the Company’s cybersecurity risk exposure. The CISO also apprises the Audit Committee of cybersecurity incidents promptly for high priority incidents and in aggregate for low priority incidents. The Audit Committee updates the full Board annually concerning the Company’s cybersecurity matters.
Cybersecurity Risk Role of Management [Text Block]

Management Oversight

 

The controls and processes employed to assess, identify, and manage material risks from cybersecurity threats are implemented and overseen by our Chief Information Security Officer (“CISO”). Our CISO leverages their over 20 years of experience in cybersecurity, compliance and risk management. Our CISO is responsible for the day-to-day management of the cybersecurity program, including the prevention, detection, investigation, response to, and recovery from cybersecurity threats and incidents, and are regularly engaged to help ensure the cybersecurity program functions effectively in the face of evolving cybersecurity threats. The CISO provides quarterly briefings for our senior management team on cybersecurity matters, including threats, events, and program enhancements.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our CISO is responsible for the day-to-day management of the cybersecurity program, including the prevention, detection, investigation, response to, and recovery from cybersecurity threats and incidents, and are regularly engaged to help ensure the cybersecurity program functions effectively in the face of evolving cybersecurity threats. The CISO provides quarterly briefings for our senior management team on cybersecurity matters, including threats, events, and program enhancements.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CISO leverages their over 20 years of experience in cybersecurity, compliance and risk management.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The CISO also apprises the Audit Committee of cybersecurity incidents promptly for high priority incidents and in aggregate for low priority incidents. The Audit Committee updates the full Board annually concerning the Company’s cybersecurity matters.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true