|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Imperial recognizes the importance of cybersecurity in achieving its business objectives, safeguarding its assets, and managing its daily operations. Accordingly, the company integrates cybersecurity risks into its overall enterprise risk management system. The board of directors oversees the company’s risk management approach and structure, which includes an annual review of the company’s cybersecurity program.
The company’s cybersecurity program is managed by the Canada Information Technology (IT) Manager, with support from cross-functional teams led by IT and operational technology cybersecurity operations managers in the company and in Exxon Mobil Corporation and its affiliates (collectively, Cybersecurity Operations Managers). The Cybersecurity Operations Managers are responsible for the day-to-day management and effective functioning of the cybersecurity program, including the prevention, detection, investigation, and response to cybersecurity threats and incidents. The Cybersecurity Operations Managers collectively have many years of experience in cybersecurity operations.
IT management provides updates to the company’s senior management throughout the year, covering, as appropriate, the company’s cybersecurity strategy, initiatives, key security metrics, penetration testing and benchmarking learnings, and business response plans, as well as the evolving cybersecurity threat landscape.
The company’s cybersecurity program includes multi-layered technological capabilities designed to prevent and detect cybersecurity disruptions and leverages industry standard frameworks, including the National Institute of Standards and Technology Cybersecurity Framework. The cybersecurity program incorporates an incident response plan to engage cross-functionally and report cybersecurity incidents to appropriate levels of management based on potential impact. The company conducts annual cybersecurity awareness training and routinely tests cybersecurity awareness and business preparedness for response and recovery, which are developed based on real-world threats. In addition, IT management exchanges threat information with governmental and industry groups and proactively engages independent, third-party cybersecurity experts to test, evaluate, and recommend improvements on the effectiveness and resiliency of its cybersecurity program through penetration testing, breach assessments, regular cybersecurity incident drill testing, threat information sharing, and industry benchmarking. The company takes a risk-based approach with respect to its third-party service providers, tailoring processes according to the nature and sensitivity of the data or systems accessed by such third-party service providers and performing additional risk screenings and procedures, as appropriate.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|the company integrates cybersecurity risks into its overall enterprise risk management system
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Imperial recognizes the importance of cybersecurity in achieving its business objectives, safeguarding its assets, and managing its daily operations. Accordingly, the company integrates cybersecurity risks into its overall enterprise risk management system. The board of directors oversees the company’s risk management approach and structure, which includes an annual review of the company’s cybersecurity program.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The company’s cybersecurity program is managed by the Canada Information Technology (IT) Manager, with support from cross-functional teams led by IT and operational technology cybersecurity operations managers in the company and in Exxon Mobil Corporation and its affiliates (collectively, Cybersecurity Operations Managers).IT management provides updates to the company’s senior management throughout the year, covering, as appropriate, the company’s cybersecurity strategy, initiatives, key security metrics, penetration testing and benchmarking learnings, and business response plans, as well as the evolving cybersecurity threat landscape.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
The company’s cybersecurity program is managed by the Canada Information Technology (IT) Manager, with support from cross-functional teams led by IT and operational technology cybersecurity operations managers in the company and in Exxon Mobil Corporation and its affiliates (collectively, Cybersecurity Operations Managers). The Cybersecurity Operations Managers are responsible for the day-to-day management and effective functioning of the cybersecurity program, including the prevention, detection, investigation, and response to cybersecurity threats and incidents. The Cybersecurity Operations Managers collectively have many years of experience in cybersecurity operations.IT management provides updates to the company’s senior management throughout the year, covering, as appropriate, the company’s cybersecurity strategy, initiatives, key security metrics, penetration testing and benchmarking learnings, and business response plans, as well as the evolving cybersecurity threat landscape.
|Cybersecurity Risk Role of Management [Text Block]
|
The company’s cybersecurity program is managed by the Canada Information Technology (IT) Manager, with support from cross-functional teams led by IT and operational technology cybersecurity operations managers in the company and in Exxon Mobil Corporation and its affiliates (collectively, Cybersecurity Operations Managers). The Cybersecurity Operations Managers are responsible for the day-to-day management and effective functioning of the cybersecurity program, including the prevention, detection, investigation, and response to cybersecurity threats and incidents. The Cybersecurity Operations Managers collectively have many years of experience in cybersecurity operations.IT management provides updates to the company’s senior management throughout the year, covering, as appropriate, the company’s cybersecurity strategy, initiatives, key security metrics, penetration testing and benchmarking learnings, and business response plans, as well as the evolving cybersecurity threat landscape.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The company’s cybersecurity program is managed by the Canada Information Technology (IT) Manager, with support from cross-functional teams led by IT and operational technology cybersecurity operations managers in the company and in Exxon Mobil Corporation and its affiliates (collectively, Cybersecurity Operations Managers).
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Cybersecurity Operations Managers collectively have many years of experience in cybersecurity operations.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|IT management provides updates to the company’s senior management throughout the year, covering, as appropriate, the company’s cybersecurity strategy, initiatives, key security metrics, penetration testing and benchmarking learnings, and business response plans, as well as the evolving cybersecurity threat landscape.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef