|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information. Our cybersecurity risk management program includes a cybersecurity incident response plan.
We design and assess our program generally based on the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”). Although our program may not meet the technical requirements of the NIST CSF, we use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business. Additionally, as we accept credit cards as a form of payment, we consider the requirements of the Payment Card Industry Data Security Standards (“PCI DSS”) in relation to our program.
Our cybersecurity risk management program includes:
There can be no assurance that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied with or are effective in protecting our systems and information. We are not currently aware of risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information. Our cybersecurity risk management program includes a cybersecurity incident response plan.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance
Our Board of Directors considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (Committee) oversight of steps the Company has taken to monitor or mitigate significant cybersecurity risks. The Committee receives regular reports from management on our cybersecurity risks. In addition, management updates the Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.
The Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity. The full Board of Directors also receives briefings from management on our cyber risk management program. Board of Directors members
receive presentations on cybersecurity topics from our Chief Information Officer (“CIO”), internal security staff and/or external experts, as appropriate, as part of the Board of Directors’ continuing education.
Our management formed an interdepartmental Information Security Council (“ISC”), comprised of senior executives from multiple disciplines, including our CIO and Vice President of Infrastructure Services, to assess and manage our material risks from cybersecurity threats. The ISC has primary responsibility for our overall cybersecurity risk management program. Our CIO, Vice President of Infrastructure Services, and others within our Information Technology department supervise both our internal cybersecurity personnel and our retained external cybersecurity consultants. Our CIO and Vice President of Infrastructure Services have a combined 50+ years of experience in information technology, with increasing oversight of cybersecurity responsibilities over the past 20+ years.
Our management teams, including the ISC, our CIO, Vice President of Infrastructure Services, and others within our Information Technology department, as appropriate, supervise efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the information technology environment.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee (Committee)
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity.
|Cybersecurity Risk Role of Management [Text Block]
|
The Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity. The full Board of Directors also receives briefings from management on our cyber risk management program. Board of Directors members
receive presentations on cybersecurity topics from our Chief Information Officer (“CIO”), internal security staff and/or external experts, as appropriate, as part of the Board of Directors’ continuing education.
Our management formed an interdepartmental Information Security Council (“ISC”), comprised of senior executives from multiple disciplines, including our CIO and Vice President of Infrastructure Services, to assess and manage our material risks from cybersecurity threats. The ISC has primary responsibility for our overall cybersecurity risk management program. Our CIO, Vice President of Infrastructure Services, and others within our Information Technology department supervise both our internal cybersecurity personnel and our retained external cybersecurity consultants. Our CIO and Vice President of Infrastructure Services have a combined 50+ years of experience in information technology, with increasing oversight of cybersecurity responsibilities over the past 20+ years.
Our management teams, including the ISC, our CIO, Vice President of Infrastructure Services, and others within our Information Technology department, as appropriate, supervise efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the information technology environment.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|CIO, Vice President of Infrastructure Services
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our CIO and Vice President of Infrastructure Services have a combined 50+ years of experience in information technology, with increasing oversight of cybersecurity responsibilities over the past 20+ years.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Our management teams, including the ISC, our CIO, Vice President of Infrastructure Services, and others within our Information Technology department, as appropriate, supervise efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the information technology environment.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef