|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Our information security program, the framework for how we assess, identify and manage risks from information security and cybersecurity threats, is designed in alignment with the National Institute of Standards and Technology (NIST) Cybersecurity Framework and leverages the International Organization for Standardization 27001 framework. Cybersecurity risk is integrated into our overall strategic risk management (“SRM”) program, which evaluates key risk areas across Paramount by a cross-functional group of risk owners, in close coordination with members of senior management.
Our information security program is overseen by our Chief Technology Officer (“CTO”), in consultation with our Chief Privacy Officer as needed. We employ a layered defense-in-depth system, which includes the use of continually evolving technologies to assess and protect the security of our enterprise-wide applications and Systems, our intellectual property and proprietary and other information and the data and personal information of our customers, partners and employees; monitoring of our technology environment; performing regular security audits and vulnerability assessments; and regular cybersecurity and privacy training for our employees. We engage consultants and other third parties to conduct independent security assessments of our information security program and to provide us with information on new and developing threats and tactics. We have established processes to oversee and identify risks and cybersecurity threats associated with our third-party service providers.
Pursuant to our information security and privacy policies and corresponding training, our employees and third-party vendors are instructed to notify our information security team as soon as they become aware of a suspected
cybersecurity incident. We have a cybersecurity incident response plan to manage our response to potential and actual cybersecurity incidents. The plan includes procedures to assess the potential impact of an incident on the Company. When an incident meets certain criteria, members of the information security team notify members of senior management as soon as reasonably practicable, including our CTO, Acting General Counsel and, under certain circumstances, the Audit Committee. All incidents are reviewed periodically with senior management.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our information security program, the framework for how we assess, identify and manage risks from information security and cybersecurity threats, is designed in alignment with the National Institute of Standards and Technology (NIST) Cybersecurity Framework and leverages the International Organization for Standardization 27001 framework. Cybersecurity risk is integrated into our overall strategic risk management (“SRM”) program, which evaluates key risk areas across Paramount by a cross-functional group of risk owners, in close coordination with members of senior management.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board of Directors has delegated to the Audit Committee the responsibility for reviewing our processes and policies with respect to risk assessment, risk management and risk acceptance, including our processes and policies with respect to information security and cybersecurity. The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our Board of Directors has delegated to the Audit Committee the responsibility for reviewing our processes and policies with respect to risk assessment, risk management and risk acceptance, including our processes and policies with respect to information security and cybersecurity. The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|When an incident meets certain criteria, members of the information security team notify members of senior management as soon as reasonably practicable, including our CTO, Acting General Counsel and, under certain circumstances, the Audit Committee. All incidents are reviewed periodically with senior management.
Our Board of Directors has delegated to the Audit Committee the responsibility for reviewing our processes and policies with respect to risk assessment, risk management and risk acceptance, including our processes and policies with respect to information security and cybersecurity. The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
|Cybersecurity Risk Role of Management [Text Block]
|
Our information security program is overseen by our Chief Technology Officer (“CTO”), in consultation with our Chief Privacy Officer as needed. We employ a layered defense-in-depth system, which includes the use of continually evolving technologies to assess and protect the security of our enterprise-wide applications and Systems, our intellectual property and proprietary and other information and the data and personal information of our customers, partners and employees; monitoring of our technology environment; performing regular security audits and vulnerability assessments; and regular cybersecurity and privacy training for our employees. We engage consultants and other third parties to conduct independent security assessments of our information security program and to provide us with information on new and developing threats and tactics. We have established processes to oversee and identify risks and cybersecurity threats associated with our third-party service providers.
Pursuant to our information security and privacy policies and corresponding training, our employees and third-party vendors are instructed to notify our information security team as soon as they become aware of a suspected
cybersecurity incident. We have a cybersecurity incident response plan to manage our response to potential and actual cybersecurity incidents. The plan includes procedures to assess the potential impact of an incident on the Company. When an incident meets certain criteria, members of the information security team notify members of senior management as soon as reasonably practicable, including our CTO, Acting General Counsel and, under certain circumstances, the Audit Committee. All incidents are reviewed periodically with senior management.
Our Board of Directors has delegated to the Audit Committee the responsibility for reviewing our processes and policies with respect to risk assessment, risk management and risk acceptance, including our processes and policies with respect to information security and cybersecurity. The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
Our CTO leads our global technology strategy and multiplatform operations and has over 15 years of experience working in technology positions at large media companies. The senior members of our information security team have extensive experience in technology and information security.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Board of Directors has delegated to the Audit Committee the responsibility for reviewing our processes and policies with respect to risk assessment, risk management and risk acceptance, including our processes and policies with respect to information security and cybersecurity. The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
Our CTO leads our global technology strategy and multiplatform operations and has over 15 years of experience working in technology positions at large media companies. The senior members of our information security team have extensive experience in technology and information security.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
Our CTO leads our global technology strategy and multiplatform operations and has over 15 years of experience working in technology positions at large media companies. The senior members of our information security team have extensive experience in technology and information security.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Audit Committee receives quarterly reports from the CTO and senior members of the information security team, which include information on cybersecurity incidents and related remediation efforts, the broader information security and cybersecurity threat landscape, the information security program’s strategic priorities and progress made in respect of those priorities. Our Chief Audit Executive reports to the Audit Committee with respect to our key risks, including information security and cybersecurity risks, which are monitored pursuant to our SRM program.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef