|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Mar. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
Our cybersecurity program, guided by industry standards, encompasses processes for the identification, assessment, and management of cybersecurity risks. We carry out regular risk assessments, supported by external vendors, to evaluate our cybersecurity program, pinpoint areas for enhancement and devise strategies to mitigate cybersecurity risks. We perform ongoing security testing and have implemented a vulnerability management process to address identified security risks based on severity. An external vendor provides us with quarterly vulnerability scans, annual penetration tests, security tabletops, and an enterprise-wide annual security assessment to assess and validate our physical, technical, external, and administrative controls. Third parties that access, process, store or transmit our information or that have access to our systems may have and be subject to additional cybersecurity controls.
We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness expectations, and event and incident management. Consistent with our position that cybersecurity is the responsibility of every Mesa team member, we regularly educate and share best practices to raise awareness of cybersecurity threats. Every year, associates in applicable job categories are required to take information security and protection training, and we conduct ongoing simulated testing to educate employees on phishing.
Our Information Security Manager and Business Information Services team oversee the day-to-day prevention, detection, mitigation, and resolution of cybersecurity risks, utilizing-party security software and services. We also deploy processes and technologies to monitor security alerts from both internal and external sources, including information security research. In case of a confirmed security incident, we have a full incident response plan that includes engaging an incident handling team, guidance for determining materiality, and steps to respond, remediate, and recover from the security incident.
To date, risks from cybersecurity threats have not materially affected our business strategy, results of operations or financial condition. We can provide no assurance that there will not be cybersecurity incidents in the future or that such incidents will not materially affect us; however, based on available information as of the date of this annual report, we do not believe that such threats are reasonably likely to materially affect our business. We maintain a cybersecurity insurance policy and a retainer for third-party incident response services which may mitigate certain financial impacts of a cybersecurity incident, should one occur.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness expectations, and event and incident management.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|To date, risks from cybersecurity threats have not materially affected our business strategy, results of operations or financial condition. We can provide no assurance that there will not be cybersecurity incidents in the future or that such incidents will not materially affect us; however, based on available information as of the date of this annual report, we do not believe that such threats are reasonably likely to materially affect our business. We maintain a cybersecurity insurance policy and a retainer for third-party incident response services which may mitigate certain financial impacts of a cybersecurity incident, should one occur.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance Related to Cybersecurity Risks
We recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.
Our Board of Directors has delegated its responsibility for oversight of cybersecurity risks to our Audit Committee. In accordance with its charter, our Audit Committee is responsible for governing management’s review and assessment of our cybersecurity and other information technology risks, controls and procedures. Management's Business Information Services team provides the Audit Committee with quarterly updates on our cybersecurity program, detailing our monitoring and mitigation efforts. Mesa’s Audit Committee has two members with prior work experience overseeing or assessing a cybersecurity function. The Audit Committee informs the full Board of pertinent cybersecurity matters regularly. We have established policies and procedures to keep management and the Audit Committee informed about security incidents that could significantly impact our business.
Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience, and who in turn reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry. The Information Security Manager regularly meets with our Business Information Services team, and as applicable, appropriate executives and directors, to review our cybersecurity posture, the broader cybersecurity landscape, any identified cybersecurity incidents, our monitoring of cybersecurity risks through continuous mitigation efforts, and any anticipated enhancements to our policies, procedures and controls.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors has delegated its responsibility for oversight of cybersecurity risks to our Audit Committee.
|Cybersecurity Risk Role of Management [Text Block]
|In accordance with its charter, our Audit Committee is responsible for governing management’s review and assessment of our cybersecurity and other information technology risks, controls and procedures. Management's Business Information Services team provides the Audit Committee with quarterly updates on our cybersecurity program, detailing our monitoring and mitigation efforts. Mesa’s Audit Committee has two members with prior work experience overseeing or assessing a cybersecurity function. The Audit Committee informs the full Board of pertinent cybersecurity matters regularly. We have established policies and procedures to keep management and the Audit Committee informed about security incidents that could significantly impact our business.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience, and who in turn reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Information Security Manager regularly meets with our Business Information Services team, and as applicable, appropriate executives and directors, to review our cybersecurity posture, the broader cybersecurity landscape, any identified cybersecurity incidents, our monitoring of cybersecurity risks through continuous mitigation efforts, and any anticipated enhancements to our policies, procedures and controls.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef