XML 47 R32.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
CBIZ maintains a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats. This program, which is integrated into the Company’s enterprise risk management system, includes the development, implementation, and maintenance of security measures and controls, as well as policies and procedures governing the operation of these security measures and controls.
The underlying controls of the cyber risk management program are based on recognized practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”) and the International Organization Standardization (“ISO”) 27002 framework and code of practice for information security controls to establish, implement, and improve an Information Security Management System focused on cybersecurity.
Cyber partners are a key part of CBIZ’s cybersecurity infrastructure. CBIZ partners with leading cybersecurity companies and organizations, leveraging third-party technology and expertise. CBIZ engages with these partners to monitor and maintain the performance and effectiveness of third-party products and services that are deployed in CBIZ’s environment, to scan for potential vulnerabilities and to conduct penetration testing.
CBIZ’s Vice President, IT Security and Compliance reports to CBIZ’s Chief Information Officer and is the head of the Company’s cybersecurity team. The IT Security Director is responsible for assessing and managing CBIZ’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts. The cybersecurity team has decades of experience selecting, deploying and operating cybersecurity technologies, initiatives and processes. Additionally, members of the cyber security team have extensive information technology and program management expertise
and have earned various cybersecurity certifications. Finally, the cybersecurity team relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants engaged by CBIZ.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] This program, which is integrated into the Company’s enterprise risk management system, includes the development, implementation, and maintenance of security measures and controls, as well as policies and procedures governing the operation of these security measures and controls.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Board of Directors oversees CBIZ’s cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks. The cybersecurity team briefs the Board of Directors on the status of CBIZ’s cyber risk management program, typically on a semi-annual basis.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board of Directors oversees CBIZ’s cybersecurity risk exposures and the steps taken by management to monitor and mitigate cybersecurity risks.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The cybersecurity team briefs the Board of Directors on the status of CBIZ’s cyber risk management program, typically on a semi-annual basis.
Cybersecurity Risk Role of Management [Text Block]
CBIZ’s Vice President, IT Security and Compliance reports to CBIZ’s Chief Information Officer and is the head of the Company’s cybersecurity team. The IT Security Director is responsible for assessing and managing CBIZ’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts. The cybersecurity team has decades of experience selecting, deploying and operating cybersecurity technologies, initiatives and processes. Additionally, members of the cyber security team have extensive information technology and program management expertise
and have earned various cybersecurity certifications. Finally, the cybersecurity team relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external consultants engaged by CBIZ.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] CBIZ’s Vice President, IT Security and Compliance reports to CBIZ’s Chief Information Officer and is the head of the Company’s cybersecurity team. The IT Security Director is responsible for assessing and managing CBIZ’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The cybersecurity team has decades of experience selecting, deploying and operating cybersecurity technologies, initiatives and processes. Additionally, members of the cyber security team have extensive information technology and program management expertise and have earned various cybersecurity certifications.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The IT Security Director is responsible for assessing and managing CBIZ’s cyber risk management program, informs senior management regarding the prevention, detection, mitigation, and remediation of cybersecurity incidents and supervises such efforts.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true