XML 83 R34.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We rely on information systems, computer networks and digital technologies to operate our business, including managing our operations, protecting sensitive data, communicating internally and externally, and preparing financial and operational information. Our cybersecurity program is designed to protect these critical systems and data while supporting business operations and growth objectives.

We maintain a comprehensive, risk-based approach to assess, identify and manage material risks from cybersecurity threats. Our controls are based on the NIST Cybersecurity Framework (CSF). Our cybersecurity risk management processes are integrated into our broader enterprise risk management framework and include: (i) regular assessment and monitoring of internal and external cybersecurity threats, (ii) evaluation of potential impacts on business operations, financial performance and stakeholder interests, (iii) periodic evaluation of control effectiveness to determine residual risk levels and guide program improvements, and (iv) integration of cybersecurity considerations into business strategy and technology decisions.

Our cybersecurity framework is evaluated by internal and external experts on an ongoing basis or within the scope of certain projects or engagements. Where we use third-party service providers, we endeavor to ensure that cybersecurity threats are minimized including establishing contractual protections including minimum security and breach notification requirements. We regularly evaluate and adjust these processes based on changes in the threat landscape and business environment.
In accordance with our cybersecurity incident response plan, the severity of cybersecurity incidents is classified based on the degree of adverse impact on our business, scale of penetration, risk of propagation, significance of impact, impact on protected information, and our monitoring capability. Incident response is overseen by a cybersecurity incident response team steering committee comprised of members of management with the responsibility to inform senior management and/or the Audit Committee based on incident severity classification.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We rely on information systems, computer networks and digital technologies to operate our business, including managing our operations, protecting sensitive data, communicating internally and externally, and preparing financial and operational information. Our cybersecurity program is designed to protect these critical systems and data while supporting business operations and growth objectives.
We maintain a comprehensive, risk-based approach to assess, identify and manage material risks from cybersecurity threats. Our controls are based on the NIST Cybersecurity Framework (CSF). Our cybersecurity risk management processes are integrated into our broader enterprise risk management framework and include: (i) regular assessment and monitoring of internal and external cybersecurity threats, (ii) evaluation of potential impacts on business operations, financial performance and stakeholder interests, (iii) periodic evaluation of control effectiveness to determine residual risk levels and guide program improvements, and (iv) integration of cybersecurity considerations into business strategy and technology decisions.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Audit Committee of our Board of Directors is responsible for overseeing our risk assessment and risk management activities, including cybersecurity risks. The Audit Committee is briefed by our Chief Digital Information Officer on cybersecurity risks at regular meetings and separately as circumstances warrant. Cybersecurity risks are also included in our enterprise risk management program which is reported separately to the Audit Committee. We maintain a dedicated cybersecurity team responsible for program implementation and operational security activities.
Our Chief Digital Information Officer has managerial responsibility for our cybersecurity risk program and is a member of our cybersecurity incident response team. Our Chief Digital Information Officer has over 27 years of experience in information technology, including leadership roles responsible for cybersecurity and data privacy. He graduated from California State University, Bakersfield with a Bachelor of Science degree in Computer Science.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee of our Board of Directors is responsible for overseeing our risk assessment and risk management activities, including cybersecurity risks. The Audit Committee is briefed by our Chief Digital Information Officer on cybersecurity risks at regular meetings and separately as circumstances warrant. Cybersecurity risks are also included in our enterprise risk management program which is reported separately to the Audit Committee.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] In accordance with our cybersecurity incident response plan, the severity of cybersecurity incidents is classified based on the degree of adverse impact on our business, scale of penetration, risk of propagation, significance of impact, impact on protected information, and our monitoring capability. Incident response is overseen by a cybersecurity incident response team steering committee comprised of members of management with the responsibility to inform senior management and/or the Audit Committee based on incident severity classification.
Cybersecurity Risk Role of Management [Text Block]
Our Chief Digital Information Officer has managerial responsibility for our cybersecurity risk program and is a member of our cybersecurity incident response team. Our Chief Digital Information Officer has over 27 years of experience in information technology, including leadership roles responsible for cybersecurity and data privacy. He graduated from California State University, Bakersfield with a Bachelor of Science degree in Computer Science.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Audit Committee of our Board of Directors is responsible for overseeing our risk assessment and risk management activities, including cybersecurity risks. The Audit Committee is briefed by our Chief Digital Information Officer on cybersecurity risks at regular meetings and separately as circumstances warrant. Cybersecurity risks are also included in our enterprise risk management program which is reported separately to the Audit Committee.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Digital Information Officer has over 27 years of experience in information technology, including leadership roles responsible for cybersecurity and data privacy. He graduated from California State University, Bakersfield with a Bachelor of Science degree in Computer Science.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] In accordance with our cybersecurity incident response plan, the severity of cybersecurity incidents is classified based on the degree of adverse impact on our business, scale of penetration, risk of propagation, significance of impact, impact on protected information, and our monitoring capability. Incident response is overseen by a cybersecurity incident response team steering committee comprised of members of management with the responsibility to inform senior management and/or the Audit Committee based on incident severity classification.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true