XML 44 R28.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We have implemented a cybersecurity program to assess, identify, and manage risks from cybersecurity threats. Our efforts are designed to maintain the confidentiality, integrity, and availability of our information and operational technology systems and the data stored on those systems. The program includes:
periodic risk assessments to identify and assess cybersecurity risks and vulnerabilities in our information technology systems;
security event monitoring, management, and incident response;
deployment of best in-class solutions to enhance our security posture;
penetration testing performed by a dedicated specialized team that is supplemented with periodic third-party engagements;
periodic third-party reviews of program maturity are conducted based on the National Institute of Standards and Technology ("NIST") Cybersecurity Framework;
reviews by our internal audit team of the effectiveness of information technology-related internal controls;
cybersecurity risk assessments of our third-party vendors; and
employee training, including regular phishing simulations.
The program is continually adapting to the evolving threat landscape and technology developments.
Cybersecurity risk management is included within our overall enterprise risk management program which is overseen by our Global Risk Oversight Committee (“GROC”). The GROC is composed of executive officers and other senior leaders and coordinates with other risk assurance functions, including internal audit and compliance. The GROC receives regular briefings concerning cybersecurity risks and risk management processes.
Additional information on cybersecurity risks we face is discussed in Item 1A, "Risk Factors,” which should be read in conjunction with the information in this section.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
Our Board of Directors has delegated to the Audit Committee oversight responsibility of our risk management program, including cybersecurity, business continuity, IT operational resilience, and data privacy. The Audit Committee receives quarterly reports from our CDTO and our CISO covering cybersecurity risks, strategic programs for managing cybersecurity risk, emerging trends and operational and policy compliance metrics.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] At the management level, our cybersecurity program is led by our CDTO and our CISO.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CDTO has served in various information technology roles for over 27 years, including as Chief Digital and Technology Officer of Kimberly-Clark and as Executive Vice President and Chief Digital Officer of Toyota Motors North America, Inc. Our interim CISO has served in various information technology roles for over 20 years. Our interim CISO also has several information technology-related certifications, including the Certified Information Systems Security Professional ("CISSP") certification.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our interim CISO reports to our CDTO, who in turn regularly reports to our Chairman of the Board and Chief Executive Officer. We have protocols by which certain cybersecurity incidents are reported promptly to the Chairman of the Board and Chief Executive Officer, or the Audit Committee, as appropriate.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true