XML 44 R27.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy
The Company’s data protection and privacy program is designed to help it assess, identify, manage, and mitigate risks relating to cybersecurity threats and incidents. The Company designs its cybersecurity standards, policies, processes and controls to operate in an integrated manner, leveraging applicable industry standards and security frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and Center for Internet Security, Inc (CIS) Controls, as guides in supporting its ability to perform such functions.

The Company manages its data protection and privacy program, fostering collaboration with partners across business units and functional areas to identify and assess material cybersecurity threats, evaluate their severity, and explore ways to mitigate and manage such risks. Third parties are engaged to assess the Company’s cybersecurity posture and adherence to the NIST Cybersecurity Framework and CIS Controls, and the Company evaluates cybersecurity risks as part of its annual risk assessment process. Cybersecurity risk mitigation strategies and initiatives are developed based on these assessments.

As part of the Company’s data protection and privacy program, it maintains a cyber risk management program that seeks to address key risk management concepts, including mission and vision, escalation path for risk mitigation, risk assessments, and risk treatment. The Company does so by conducting a variety of planning and preparedness activities, including employing monitoring tools to identify suspicious or anomalous activity, vulnerabilities, or signs of compromise across its networks, systems, and data. The Company utilizes data from attack surface management tools to produce a prioritized set of vulnerabilities for remediation. A key area for the program is employee cybersecurity education. The Company’s employees play a key role in cybersecurity and participate in mandatory cybersecurity training, phishing attack simulations, educational events, and receive news bulletins. The Company’s data protection and privacy program is designed to adhere to and adapt to global privacy and data protection laws.
The Company has established policies, processes, and controls that are designed to monitor, detect, investigate, respond to, and escalate management of cybersecurity threats and incidents. If the Company experiences a cybersecurity incident, the Company activates an incident response plan, which includes processes to enable it to triage, assess severity of, escalate, contain, investigate, and remediate the incident, as well as to comply with applicable legal obligations and mitigate brand and reputational harm. Based on initial investigation into such incident’s impact to the Company, the actor(s) involved, and other factors, the Company assigns a severity level to an incident, which dictates the escalation path for a given incident. Incidents rising to higher levels of severity and potential materiality are escalated to designated members of the Company’s senior management for further assessment, response, and remediation. Additionally, the Company has established a Cyber Crisis Management Team, responsible for addressing and responding to the most severe cyber incidents. If warranted, senior management notifies the Audit Committee and/or the full Board of Directors, as appropriate. Throughout this process, the Company continues to investigate the incident and, as its understanding of the incident evolves, updates its severity assessment, as necessary.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The Company’s data protection and privacy program is designed to help it assess, identify, manage, and mitigate risks relating to cybersecurity threats and incidents. The Company designs its cybersecurity standards, policies, processes and controls to operate in an integrated manner, leveraging applicable industry standards and security frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and Center for Internet Security, Inc (CIS) Controls, as guides in supporting its ability to perform such functions.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
The Company’s business strategy, results of operations and financial condition have not been materially affected and are not reasonably likely to be affected by risks from cybersecurity threats, including as a result of previously identified cybersecurity incidents, but it cannot provide assurance that they will not be materially affected in the future by such risks or any future material incidents. For more information on the Company’s information technology related risks, see Item 1A Risk Factors of this Annual Report on Form 10-K.
Cybersecurity Risk Board of Directors Oversight [Text Block]
Governance
The Company’s cybersecurity program and approach is overseen by its Board of Directors, in coordination with the Audit Committee, and Senior Leadership, along with its Vice President, Information Technology. The Vice President, Information Technology reports to the Chief Administration Officer and has more than 25 years of IT experience with over 10 years of cybersecurity and international business experience. The Board of Directors receives annual reports from Senior Leadership on the Company’s cybersecurity risks. In addition, Senior Leadership updates the Board of Directors, as necessary, regarding any significant cybersecurity incidents. The Board of Directors and Senior Leadership review the strategy, tools, metrics and latest trends affecting cybersecurity utilizing the NIST Cybersecurity Framework and CIS Controls as the foundation for its cybersecurity strategy and approach.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Board of Directors, in coordination with the Audit Committee, and Senior Leadership, along with its Vice President, Information Technology
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board of Directors receives annual reports from Senior Leadership on the Company’s cybersecurity risks. In addition, Senior Leadership updates the Board of Directors, as necessary, regarding any significant cybersecurity incidents. The Board of Directors and Senior Leadership review the strategy, tools, metrics and latest trends affecting cybersecurity utilizing the NIST Cybersecurity Framework and CIS Controls as the foundation for its cybersecurity strategy and approach.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Vice President, Information Technology reports to the Chief Administration Officer and has more than 25 years of IT experience with over 10 years of cybersecurity and international business experience.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true