XML 40 R24.htm IDEA: XBRL DOCUMENT v3.25.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Cybersecurity Risk Management and Strategy

Cybersecurity risk management is one component of our information security program that guides continuous improvement to, and evaluates the confidentiality, integrity, and availability of our critical systems, data, and operations.

Our approach to controls and risk management is based on guidance from the National Institute of Standards and Technology (“NIST”) and the Crypto Currency Security Standard (“CCSS”). This does not mean that we meet any particular technical standards, specifications, or requirements, but rather that we use the NIST and CCSS as a guide to help us identify, assess, and manage cybersecurity controls and risks relevant to our business.

Our cybersecurity risk management program includes:

  Identifying cybersecurity risks that could impact our facilities, third-party vendors/partners, operations, critical systems, information, and broader enterprise IT environment. Risks are informed by threat intelligence, current and historical adversarial activity, and industry specify threats;
  Performing a cybersecurity risk assessment to evaluate our readiness if the risks were to materialize; and
  Ensuring risk is addressed and tracking any necessary remediation through an action plan.

While we face a number of ongoing cybersecurity risks in connection with our business, such risks have not materially affected us to date, including our business strategy, results of operations, or financial condition.

Cybersecurity Governance

Our Board considers cybersecurity risk as part of its risk oversight function and has delegated the oversight of cybersecurity and other information technology risks to the Board’s Audit Committee as well as hiring a third party vendor that specializes in cybersecurity to oversee and provide an assessment on the Company’s IT controls. The Audit Committee meets at least quarterly to discuss matters involving cybersecurity risks.

The Audit Committee ultimately provides information to our board members regarding its activities, including those related to cybersecurity risks. The Audit Committee also receives a briefing and continuing education from a member of the third party vendor relating to our cyber risk management program at least annually. The third party vendor is responsible for notifying the Audit Committee of material cybersecurity incidents.

Cybersecurity Incidents

In 2023, a threat actor representing to be the Sphere 3D Corp. (“Sphere 3D”) CFO inserted themselves into an email exchange between the Sphere 3D CFO and the Company’s former CEO, which also included Sphere 3D’s CEO, regarding the transfer of Sphere 3D’s BTC from the Company’s wallet to Sphere 3D’s wallet. The threat actor requested that the BTC be transferred to an alternate wallet. As a result, 26 BTC, with a value of approximately $560,000 at the time, was transferred to a wallet controlled by the threat actor. Via counsel, Gryphon engaged with US Federal law enforcement to recover the BTC. Despite these attempts by law enforcement to recover the BTC, recovery was not possible. Gryphon subsequently wired the commensurate amount in USD to Sphere 3D to make them whole for the stolen BTC. Gryphon also engaged a nationally recognized third-party firm to perform a forensic analysis. The analysis revealed that the threat actor did not enter the email exchange via Gryphon’s IT systems. The Company has also subsequently modified its control systems to protect against any future attempted incursions. During the quarter ended June 30, 2023, the Company made a payment to Sphere 3D for $560,000, which was classified as a general and administrative expense on Gryphon’s consolidated statement of operations.

Cybersecurity Risk Management Processes Integrated [Text Block]

Cybersecurity risk management is one component of our information security program that guides continuous improvement to, and evaluates the confidentiality, integrity, and availability of our critical systems, data, and operations.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Role of Management [Text Block]

Our approach to controls and risk management is based on guidance from the National Institute of Standards and Technology (“NIST”) and the Crypto Currency Security Standard (“CCSS”). This does not mean that we meet any particular technical standards, specifications, or requirements, but rather that we use the NIST and CCSS as a guide to help us identify, assess, and manage cybersecurity controls and risks relevant to our business.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]

While we face a number of ongoing cybersecurity risks in connection with our business, such risks have not materially affected us to date, including our business strategy, results of operations, or financial condition.

Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our Board considers cybersecurity risk as part of its risk oversight function and has delegated the oversight of cybersecurity and other information technology risks to the Board’s Audit Committee as well as hiring a third party vendor that specializes in cybersecurity to oversee and provide an assessment on the Company’s IT controls.
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee ultimately provides information to our board members regarding its activities, including those related to cybersecurity risks
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]

The Audit Committee ultimately provides information to our board members regarding its activities, including those related to cybersecurity risks. The Audit Committee also receives a briefing and continuing education from a member of the third party vendor relating to our cyber risk management program at least annually. The third party vendor is responsible for notifying the Audit Committee of material cybersecurity incidents.

Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The third party vendor is responsible for notifying the Audit Committee of material cybersecurity incidents.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true