XML 54 R35.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Senior information security and technology employees, including the chief information and operations officer, meet regularly to discuss potential information and cybersecurity threats that have been identified by our systems, employees or otherwise made known to us by our third-party service providers, vendors and other external users, and to formulate the appropriate response to any identified material information and cybersecurity threats. When high-priority information or cybersecurity risks are identified, certain employees in our information security, privacy, technology, legal and compliance departments meet or communicate to review potential threats in accordance with our internal cybersecurity incident response process.
Potential threats, our response to such threats, and our evaluation of any residual risk are communicated quarterly to the audit committee. As necessary, the chief information and operations officer provides interim updates to the audit committee and, as appropriate, the board of directors, concerning high-priority or material information or cybersecurity threats. Our chief information and operations officer also provides a quarterly update to the audit committee regarding our ongoing information and cybersecurity initiatives; the current cybersecurity landscape and emerging threats; and metrics on the effectiveness of certain aspects of our information and cybersecurity program.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Our management team takes an active role in identifying, assessing, monitoring and managing material risks from information and cybersecurity threats. Management’s assessment of information and cybersecurity threats is incorporated into our enterprise risk management processes, which include assessing inherent risks posed by the internal operating environment and external factors, assessing the adequacy and design of controls, testing controls, determining residual risk and comparing it to risk appetite thresholds, and taking steps to further mitigate risks as needed.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our board of directors is actively engaged in the oversight of cybersecurity and information technology risks, with primary oversight responsibility delegated to the audit committee of the board of directors. The audit committee is composed of board members with the appropriate expertise, including risk management, cybersecurity and finance, to oversee these risks as well as management's cybersecurity processes and protocols.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our board of directors is actively engaged in the oversight of cybersecurity and information technology risks, with primary oversight responsibility delegated to the audit committee of the board of directors.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our management team takes an active role in identifying, assessing, monitoring and managing material risks from information and cybersecurity threats. Management’s assessment of information and cybersecurity threats is incorporated into our enterprise risk management processes, which include assessing inherent risks posed by the internal operating environment and external factors, assessing the adequacy and design of controls, testing controls, determining residual risk and comparing it to risk appetite thresholds, and taking steps to further mitigate risks as needed.
Cybersecurity Risk Role of Management [Text Block] Our management team takes an active role in identifying, assessing, monitoring and managing material risks from information and cybersecurity threats. Management’s assessment of information and cybersecurity threats is incorporated into our enterprise risk management processes, which include assessing inherent risks posed by the internal operating environment and external factors, assessing the adequacy and design of controls, testing controls, determining residual risk and comparing it to risk appetite thresholds, and taking steps to further mitigate risks as needed.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Senior information security and technology employees, including the chief information and operations officer, meet regularly to discuss potential information and cybersecurity threats that have been identified by our systems, employees or otherwise made known to us by our third-party service providers, vendors and other external users, and to formulate the appropriate response to any identified material information and cybersecurity threats. When high-priority information or cybersecurity risks are identified, certain employees in our information security, privacy, technology, legal and compliance departments meet or communicate to review potential threats in accordance with our internal cybersecurity incident response process.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our chief information and operations officer is a member of our leadership team and has been in this role since 2008. With more than 25 years of experience in information technology in the investment banking industry, he is responsible for overseeing more than 100 employees in our information security and technology departments who possess relevant educational and industry experience.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Senior information security and technology employees, including the chief information and operations officer, meet regularly to discuss potential information and cybersecurity threats that have been identified by our systems, employees or otherwise made known to us by our third-party service providers, vendors and other external users, and to formulate the appropriate response to any identified material information and cybersecurity threats. When high-priority information or cybersecurity risks are identified, certain employees in our information security, privacy, technology, legal and compliance departments meet or communicate to review potential threats in accordance with our internal cybersecurity incident response process.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true