|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our information security program, including cybersecurity risk management is integrated into our overall Enterprise Risk Management Program (“ERMP”) framework. Our ERMP assesses strategic, operational, and environmental factors to identify key and emerging risks across the organization including cybersecurity risks. A key risk matrix is maintained to evaluate the potential impact of key risks and monitor the effectiveness of mitigation and controls. We, our customers, suppliers, and subcontractors face cybersecurity risks such as phishing, ransomware, zero-day exploits, malware attacks, and social engineering attacks. A cybersecurity incident impacting us or our subcontractors could materially adversely affect our performance and results of operations. For more information on about the cybersecurity risks we face, see the factors set forth under the caption “Risk Factors” in Part I, Item 1A of this Annual Report on Form 10-K.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Enterprise Risk Management Committee (ERMC), which includes certain associates with data privacy, information security, and cybersecurity experience, supports our Board of Directors in this oversight. The ERMC reports to the Audit Committee of the Board of Directors. The ERMC manages the ERMP and provides regular updates to the Audit Committee regarding our key risks and ERMP developments. Our Vice President of Privacy Compliance also reports to the Audit Committee on a regular basis, providing an Information Security Report, which includes information such as our information system risk profile, our top risk challenges, and security initiatives and strategies. Additionally, the ERMC communicates emerging risks and the mitigation of those risks to the Audit Committee, among other things. Significant cybersecurity matters, and strategic risk management decisions are elevated to the overall Board of Directors to enable oversight and guidance on critical cybersecurity issues.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Enterprise Risk Management Committee (ERMC), which includes certain associates with data privacy, information security, and cybersecurity experience, supports our Board of Directors in this oversight. The ERMC reports to the Audit Committee of the Board of Directors. The ERMC manages the ERMP and provides regular updates to the Audit Committee regarding our key risks and ERMP developments. Our Vice President of Privacy Compliance also reports to the Audit Committee on a regular basis, providing an Information Security Report, which includes information such as our information system risk profile, our top risk challenges, and security initiatives and strategies. Additionally, the ERMC communicates emerging risks and the mitigation of those risks to the Audit Committee, among other things. Significant cybersecurity matters, and strategic risk management decisions are elevated to the overall Board of Directors to enable oversight and guidance on critical cybersecurity issues.
|Cybersecurity Risk Role of Management [Text Block]
|Our Enterprise Risk Management Committee (ERMC), which includes certain associates with data privacy, information security, and cybersecurity experience, supports our Board of Directors in this oversight. The ERMC reports to the Audit Committee of the Board of Directors. The ERMC manages the ERMP and provides regular updates to the Audit Committee regarding our key risks and ERMP developments. Our Vice President of Privacy Compliance also reports to the Audit Committee on a regular basis, providing an Information Security Report, which includes information such as our information system risk profile, our top risk challenges, and security initiatives and strategies. Additionally, the ERMC communicates emerging risks and the mitigation of those risks to the Audit Committee, among other things. Significant cybersecurity matters, and strategic risk management decisions are elevated to the overall Board of Directors to enable oversight and guidance on critical cybersecurity issues.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our Vice President of Privacy Compliance, Jen Spencer, is an ERMC member and has primary responsibility for our Information Security Program, including the maintenance and enforcement of our security policies. Ms. Spencer serves as an advisor to our leadership team, assisting them in optimizing security measures, mitigating risk, fortifying defenses, and minimizing vulnerabilities. Ms. Spencer develops written policies and procedures and conducts training to ensure our entire organization is well-protected. She is responsible for overseeing and executing the strategic plan for our data protection program, information security systems, compliance, computer networks and business continuance/disaster recovery. Additionally, Ms. Spencer actively participates in project management duties and manages information security integration efforts, working closely with internal teams, vendors, subcontractors, and clients. Ms. Spencer has over twenty years in cybersecurity, privacy, and compliance. Her primary job responsibilities include security, privacy, and compliance including AI data governance. Ms. Spencer works on several working groups through H-ISAC, Women in Bio, and Women in AI Governance. Prior to NRC she was the CIO/CISO/CPO for the Rochester RHIO and Manager of Information Security and GRC with Excellus Health Plan. She graduated from Rochester Institute of Technology (RIT) with an eMBA and a master’s in science in IT Security. She earned her paralegal certificate from Stony Brook University and holds several industry certifications. Ms. Spencer is also an adjunct professor at RIT, the University of Virginia and the Blue Ridge Virginia Governor's School.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our Vice President of Privacy Compliance, Jen Spencer, is an ERMC member and has primary responsibility for our Information Security Program, including the maintenance and enforcement of our security policies. Ms. Spencer serves as an advisor to our leadership team, assisting them in optimizing security measures, mitigating risk, fortifying defenses, and minimizing vulnerabilities. Ms. Spencer develops written policies and procedures and conducts training to ensure our entire organization is well-protected. She is responsible for overseeing and executing the strategic plan for our data protection program, information security systems, compliance, computer networks and business continuance/disaster recovery. Additionally, Ms. Spencer actively participates in project management duties and manages information security integration efforts, working closely with internal teams, vendors, subcontractors, and clients. Ms. Spencer has over twenty years in cybersecurity, privacy, and compliance. Her primary job responsibilities include security, privacy, and compliance including AI data governance. Ms. Spencer works on several working groups through H-ISAC, Women in Bio, and Women in AI Governance. Prior to NRC she was the CIO/CISO/CPO for the Rochester RHIO and Manager of Information Security and GRC with Excellus Health Plan. She graduated from Rochester Institute of Technology (RIT) with an eMBA and a master’s in science in IT Security. She earned her paralegal certificate from Stony Brook University and holds several industry certifications. Ms. Spencer is also an adjunct professor at RIT, the University of Virginia and the Blue Ridge Virginia Governor's School.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our Enterprise Risk Management Committee (ERMC), which includes certain associates with data privacy, information security, and cybersecurity experience, supports our Board of Directors in this oversight. The ERMC reports to the Audit Committee of the Board of Directors. The ERMC manages the ERMP and provides regular updates to the Audit Committee regarding our key risks and ERMP developments. Our Vice President of Privacy Compliance also reports to the Audit Committee on a regular basis, providing an Information Security Report, which includes information such as our information system risk profile, our top risk challenges, and security initiatives and strategies. Additionally, the ERMC communicates emerging risks and the mitigation of those risks to the Audit Committee, among other things. Significant cybersecurity matters, and strategic risk management decisions are elevated to the overall Board of Directors to enable oversight and guidance on critical cybersecurity issues.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef