XML 63 R38.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Identifying, assessing and managing cybersecurity risks is an important component of White Mountains’s overall enterprise risk management program. As with the management of risks generally, given our holding company structure, the management of cybersecurity risks involves coordination between the Company and its consolidated subsidiaries/affiliates.
The Company and each of its consolidated subsidiaries/affiliates are responsible for developing a cybersecurity program appropriate for their respective businesses. The design of these cybersecurity programs is informed by the ISO 27001 standards and the Center for Internet Security Critical Security Controls framework (“CISCSC”). This does not imply that these programs meet all specifications of ISO 27001 and CISCSC, but rather that we use them as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. The cybersecurity programs developed by the Company and its consolidated subsidiaries/affiliates include, among other things, (i) advanced threat protection and detection systems; (ii) vulnerability scanning and testing of network defenses; (iii) user authentication, role-based access and privileged access management; (iv) data encryption, loss prevention, backup and recovery mechanisms; (v) employee testing and training; (vi) technical and business team-focused incident response tabletop exercises; (vii) disaster recovery testing and (viii) security assessments of third-party service providers. White Mountains engages both its internal auditors and third-party information security experts to assist management in assessing the effectiveness of these cybersecurity programs.
Risks from cybersecurity threats may cause material disruptions to our operations and reputational harm, which could materially adversely affect our results of operations and financial condition. See Item 1.A Risk Factors, “We may be unable to adequately maintain our systems and safeguard the security of our data, which could adversely impact our ability to operate our business and cause reputational harm and, consequently, could materially adversely affect our results of operations and financial condition.” on page 41 for more information about these risks.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Identifying, assessing and managing cybersecurity risks is an important component of White Mountains’s overall enterprise risk management program. As with the management of risks generally, given our holding company structure, the management of cybersecurity risks involves coordination between the Company and its consolidated subsidiaries/affiliates.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Company’s Board of Directors has assigned oversight of White Mountains’s cybersecurity risk management to the Audit Committee. The Audit Committee receives periodic reports on White Mountains’s cybersecurity risks and any material cybersecurity incidents at the direction of White Mountains’s senior management. In addition, the Audit Committee receives reports addressing cybersecurity risks as part of the Company’s overall enterprise risk management program.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Company’s Board of Directors has assigned oversight of White Mountains’s cybersecurity risk management to the Audit Committee. The Audit Committee receives periodic reports on White Mountains’s cybersecurity risks and any material cybersecurity incidents at the direction of White Mountains’s senior management. In addition, the Audit Committee receives reports addressing cybersecurity risks as part of the Company’s overall enterprise risk management program.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee receives periodic reports on White Mountains’s cybersecurity risks and any material cybersecurity incidents at the direction of White Mountains’s senior management. In addition, the Audit Committee receives reports addressing cybersecurity risks as part of the Company’s overall enterprise risk management program.
Cybersecurity Risk Role of Management [Text Block]
White Mountains’s Information Technology (“IT”) Steering Committee, which includes its Chief Information Security Officer, Chief Technology Officer and various members of senior management, as well as the senior IT leadership at each of its consolidated subsidiaries/affiliates are responsible for assessing and managing White Mountains’s cybersecurity risk. These individuals include IT and cybersecurity professionals with relevant education, including degrees and/or certifications, and prior work experience. These individuals also monitor the prevention, detection, mitigation and remediation of cybersecurity incidents as part of the cybersecurity programs described above.
Senior IT leadership at our consolidated subsidiaries/affiliates communicate information regarding cybersecurity risks to Company personnel through a variety of channels, including discussions between or among subsidiary/affiliate management and the Company, reports made to subsidiary/affiliate boards and direct updates to the Company’s senior management and/or IT Steering Committee.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
White Mountains’s Information Technology (“IT”) Steering Committee, which includes its Chief Information Security Officer, Chief Technology Officer and various members of senior management, as well as the senior IT leadership at each of its consolidated subsidiaries/affiliates are responsible for assessing and managing White Mountains’s cybersecurity risk. These individuals include IT and cybersecurity professionals with relevant education, including degrees and/or certifications, and prior work experience. These individuals also monitor the prevention, detection, mitigation and remediation of cybersecurity incidents as part of the cybersecurity programs described above.
Senior IT leadership at our consolidated subsidiaries/affiliates communicate information regarding cybersecurity risks to Company personnel through a variety of channels, including discussions between or among subsidiary/affiliate management and the Company, reports made to subsidiary/affiliate boards and direct updates to the Company’s senior management and/or IT Steering Committee.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] White Mountains’s Information Technology (“IT”) Steering Committee, which includes its Chief Information Security Officer, Chief Technology Officer and various members of senior management, as well as the senior IT leadership at each of its consolidated subsidiaries/affiliates are responsible for assessing and managing White Mountains’s cybersecurity risk. These individuals include IT and cybersecurity professionals with relevant education, including degrees and/or certifications, and prior work experience.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee receives periodic reports on White Mountains’s cybersecurity risks and any material cybersecurity incidents at the direction of White Mountains’s senior management. In addition, the Audit Committee receives reports addressing cybersecurity risks as part of the Company’s overall enterprise risk management program.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true