|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management Strategy And Governance [Abstract]
|Cybersecurity Risk Management Processes For Assessing Identifying And Managing Threats [Text Block]
|
Our Cybersecurity program is managed by our Chief Information Security Officer (CISO). The CISO is responsible for developing and managing the overall strategy, leading the response to cybersecurity incidents and reporting to the Board. The Audit Committee of the Board monitors our information security programs, including our cybersecurity risk management program, and receives updates quarterly, or more frequently as determined appropriate, from management on our cybersecurity program and systems protection.
Our CISO has over twenty-five years of experience in cybersecurity and holds active Certified Information Systems Security Professional and Certified Information Security Manager certifications. Our policies require teammates, contractors, service providers and suppliers who become aware of a cybersecurity incident or the individual’s supervisor to immediately report the cybersecurity incident to the appropriate reporting channels, which include the CISO. In the event of a cybersecurity incident, in addition to the standing members, teammates would be selected to serve on the Cybersecurity Incident Response Team (CIRT) based on the facts and circumstances of the particular cybersecurity incident. Additionally, our outside legal counsel is held on retainer to assist with our response to cybersecurity incidents.
We model our cybersecurity program to align with the practices and standards referenced within the National Institute of Standards and Technology cybersecurity framework. Our information security program is integrated within our larger enterprise risk management program and includes, but is not limited to:
We maintain a Cybersecurity Incident Response Plan (CIRP) to assist in promptly responding to, resolving, and recovering from cybersecurity incidents. The CIRP includes guidelines for assessing, identifying, managing, reporting, including disclosure of material breaches with the SEC, and remediating cybersecurity incidents. Following a cybersecurity incident, external subject matter experts, including legal counsel are consulted to reduce the risk of further compromise to our information and to ensure proper reporting and documentation. The Audit Committee would be informed promptly of material cybersecurity incidents in the event that they arise. If a material cybersecurity incident were to occur, it could have a material effect on our business strategy, results of operations and financial condition. For more information see Item 1A. “Risk Factors” for the Risk Factor entitled “Our operations depend on the proper functioning of information systems, and our business or results of operations could be adversely affected if we experience a cyberattack or other systems breach or failure.”
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|. Our information security program is integrated within our larger enterprise risk management program and includes, but is not limited to:
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight And Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected Or Reasonably Likely To Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board Of Directors Oversight [Text Block]
|Our Cybersecurity program is managed by our Chief Information Security Officer (CISO). The CISO is responsible for developing and managing the overall strategy, leading the response to cybersecurity incidents and reporting to the Board. The Audit Committee of the Board monitors our information security programs, including our cybersecurity risk management program, and receives updates quarterly, or more frequently as determined appropriate, from management on our cybersecurity program and systems protection.
|Cybersecurity Risk Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process For Informing Board Committee Or Subcommittee Responsible For Oversight [Text Block]
|
We maintain a Cybersecurity Incident Response Plan (CIRP) to assist in promptly responding to, resolving, and recovering from cybersecurity incidents. The CIRP includes guidelines for assessing, identifying, managing, reporting, including disclosure of material breaches with the SEC, and remediating cybersecurity incidents. Following a cybersecurity incident, external subject matter experts, including legal counsel are consulted to reduce the risk of further compromise to our information and to ensure proper reporting and documentation. The Audit Committee would be informed promptly of material cybersecurity incidents in the event that they arise. If a material cybersecurity incident were to occur, it could have a material effect on our business strategy, results of operations and financial condition. For more information see Item 1A. “Risk Factors” for the Risk Factor entitled “Our operations depend on the proper functioning of information systems, and our business or results of operations could be adversely affected if we experience a cyberattack or other systems breach or failure.”
|Cybersecurity Risk Role Of Management [Text Block]
|Our Cybersecurity program is managed by our Chief Information Security Officer (CISO). The CISO is responsible for developing and managing the overall strategy, leading the response to cybersecurity incidents and reporting to the Board.
|Cybersecurity Risk Management Positions Or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions Or Committees Responsible [Text Block]
|Chief Information Security Officer (CISO)
|Cybersecurity Risk Management Expertise Of Management Responsible [Text Block]
|Our CISO has over twenty-five years of experience in cybersecurity and holds active Certified Information Systems Security Professional and Certified Information Security Manager certifications.
|Cybersecurity Risk Process For Informing Management Or Committees Responsible [Text Block]
|Our policies require teammates, contractors, service providers and suppliers who become aware of a cybersecurity incident or the individual’s supervisor to immediately report the cybersecurity incident to the appropriate reporting channels, which include the CISO. In the event of a cybersecurity incident, in addition to the standing members, teammates would be selected to serve on the Cybersecurity Incident Response Team (CIRT) based on the facts and circumstances of the particular cybersecurity incident.
|Cybersecurity Risk Management Positions Or Committees Responsible Report To Board [Flag]
|true
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.
|X
- References
+ Details
No definition available.