XML 75 R47.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We are subject to various cybersecurity risks in connection with our business. For additional information, see Item 1A — Risk Factors. As part of our overall enterprise risk management system and processes, we assess, identify and manage material risks from threats to our information systems. Once risks are identified, our Enterprise Risk Management Committee (“ERM Committee”), which consists of executives appointed by the Board, oversees and reviews these risks and provides an annual report regarding such risks to the Audit Committee for further review and evaluation. We also maintain processes to oversee and identify risks from cyber threats associated with our use of third-party service providers, including annual reviews of third-party SOC1 reports.
Safeguarding our operations against cyber threats is a high priority. Recognizing the importance of a strong posture towards cyber threats, our strategy to combat the evolving threat landscape and support the protection of sensitive information includes engaging in:
Incident Response Planning and Data Backups. We maintain and regularly review a detailed incident response plan to help minimize downtime and disruption in the event of a cybersecurity incident and to assess materiality and any related disclosure obligations. We also actively maintain data backup procedures for business continuity in the event of a cybersecurity incident. Examples of our backup procedures and systems include daily server snapshots, database log files, Salesforce backups, and Google Vault. Generally, these backups of critical systems would allow us to restore operation within hours.
Third-Party Managed Monitoring, Detection, and Response Services. We partner with a reputable third-party firm for 24/7 threat monitoring, detection and response.
External Cybersecurity Process Assessments. We also engage third-party experts to conduct periodic process assessments against the U.S. National Institute of Standards and Technology (“NIST”) framework to help us evaluate and enhance our cybersecurity practices.
Penetration Testing and Phishing Simulations. We periodically engage experts for penetration testing to identify system vulnerabilities and to simulate real-world cyberattacks. We also conduct quarterly phishing simulations to test our staff's response and to deliver targeted cyber awareness training.
Continuous Improvement and Adaptation. We regularly review and update our strategies to keep pace with the dynamic cyber threat landscape, and to build a resilient and responsive cybersecurity system. Our employees receive monthly training on data protection, threat detection, and incident response. We also provide a forum for employees to report cyber “near misses” to elevate cyber threat awareness across our organization.
In the past, we have experienced targeted and non-targeted cybersecurity attacks and incidents, and we could experience similar attacks in the future. To date, no cybersecurity attack or incident, or any risk from cybersecurity threats, has materially affected or has been determined to be reasonably likely to materially affect the Company or our business strategy, results of operations, or financial condition.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We are subject to various cybersecurity risks in connection with our business. For additional information, see Item 1A — Risk Factors. As part of our overall enterprise risk management system and processes, we assess, identify and manage material risks from threats to our information systems. Once risks are identified, our Enterprise Risk Management Committee (“ERM Committee”), which consists of executives appointed by the Board, oversees and reviews these risks and provides an annual report regarding such risks to the Audit Committee for further review and evaluation. We also maintain processes to oversee and identify risks from cyber threats associated with our use of third-party service providers, including annual reviews of third-party SOC1 reports.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
In the event of a breach or incident, our Manager of IT Security assumed primary responsibility for leading our response to mitigate impact and initiate the recovery processes, given the vacancy in the Director of Information Technology position. Following the identification of a breach or incident, the Manager of IT Security reports incidents of a medium or high severity level2 to our senior leadership team. Incidents of a high severity level are also reviewed by our Disclosure Committee to assess materiality and any disclosure obligations. All incidents are reported to the Audit Committee at the next scheduled meeting, and incidents of high severity level are immediately reported to the Audit Committee. In the event of a significant incident, the matter is reported to the full Board of Directors.
The Audit Committee of our Board of Directors is responsible for overseeing cybersecurity risk management. For each Audit Committee meeting, the Manager of IT Security prepares an updated cybersecurity report, featuring key metrics and threats. Additionally, the Manager of IT Security provides an annual cybersecurity briefing to the Audit Committee. External penetration tests and process audits, conducted at regular intervals, are reported directly to the Audit Committee by our third-party firm. These comprehensive measures help the Committee remain well-informed and proactive in their oversight of cybersecurity risks.
Subsequent to December 31, 2025, following the completion of our merger, we appointed a Vice President & Chief Information Officer (CIO) to oversee our information technology and cybersecurity functions. The CIO’s responsibilities and governance structure will be reflected in future disclosures.
(1)Our Manager of IT Security has more than 20 years of IT experience. He joined the company in 2015 as a Systems Engineer and was promoted to his current position in 2020. Prior to joining Rayonier, he worked as an Infrastructure Engineer at Enterprise Integration (EI), a managed services provider. Prior to joining EI, he held various IT roles in support and engineering.
(2)    A medium severity incident level is defined as incidents that have a moderate impact on business operations or data integrity and might affect internal systems and could potentially lead to limited unauthorized access to sensitive information. A high severity incident level is defined as incidents that pose a significant threat to business operations, data integrity, or confidential information. This level of incident may have legal, regulatory and public relations implications.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee of our Board of Directors is responsible for overseeing cybersecurity risk management.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] In the event of a breach or incident, our Manager of IT Security assumed primary responsibility for leading our response to mitigate impact and initiate the recovery processes, given the vacancy in the Director of Information Technology position. Following the identification of a breach or incident, the Manager of IT Security reports incidents of a medium or high severity level2 to our senior leadership team. Incidents of a high severity level are also reviewed by our Disclosure Committee to assess materiality and any disclosure obligations. All incidents are reported to the Audit Committee at the next scheduled meeting, and incidents of high severity level are immediately reported to the Audit Committee. In the event of a significant incident, the matter is reported to the full Board of Directors.
Cybersecurity Risk Role of Management [Text Block]
As of December 31, 2025, the position of Director of Information Technology was vacant. During this period of vacancy, our Manager of IT Security, who has over 20 years of information technology experience,1 assumed primary responsibility for protecting the organization’s digital assets and sensitive information from cyber threats. The Manager of IT Security managed our partnerships with the external firm specializing in around-the-clock threat monitoring, detection, and response services, as well as other third-party providers. Material risks from threats to our information systems are reported by the Manager of IT Security to the ERM Committee.
In the event of a breach or incident, our Manager of IT Security assumed primary responsibility for leading our response to mitigate impact and initiate the recovery processes, given the vacancy in the Director of Information Technology position. Following the identification of a breach or incident, the Manager of IT Security reports incidents of a medium or high severity level2 to our senior leadership team. Incidents of a high severity level are also reviewed by our Disclosure Committee to assess materiality and any disclosure obligations. All incidents are reported to the Audit Committee at the next scheduled meeting, and incidents of high severity level are immediately reported to the Audit Committee. In the event of a significant incident, the matter is reported to the full Board of Directors.
The Audit Committee of our Board of Directors is responsible for overseeing cybersecurity risk management. For each Audit Committee meeting, the Manager of IT Security prepares an updated cybersecurity report, featuring key metrics and threats. Additionally, the Manager of IT Security provides an annual cybersecurity briefing to the Audit Committee. External penetration tests and process audits, conducted at regular intervals, are reported directly to the Audit Committee by our third-party firm. These comprehensive measures help the Committee remain well-informed and proactive in their oversight of cybersecurity risks.
Subsequent to December 31, 2025, following the completion of our merger, we appointed a Vice President & Chief Information Officer (CIO) to oversee our information technology and cybersecurity functions. The CIO’s responsibilities and governance structure will be reflected in future disclosures.
(1)Our Manager of IT Security has more than 20 years of IT experience. He joined the company in 2015 as a Systems Engineer and was promoted to his current position in 2020. Prior to joining Rayonier, he worked as an Infrastructure Engineer at Enterprise Integration (EI), a managed services provider. Prior to joining EI, he held various IT roles in support and engineering.
(2)    A medium severity incident level is defined as incidents that have a moderate impact on business operations or data integrity and might affect internal systems and could potentially lead to limited unauthorized access to sensitive information. A high severity incident level is defined as incidents that pose a significant threat to business operations, data integrity, or confidential information. This level of incident may have legal, regulatory and public relations implications.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
As of December 31, 2025, the position of Director of Information Technology was vacant. During this period of vacancy, our Manager of IT Security, who has over 20 years of information technology experience,1 assumed primary responsibility for protecting the organization’s digital assets and sensitive information from cyber threats. The Manager of IT Security managed our partnerships with the external firm specializing in around-the-clock threat monitoring, detection, and response services, as well as other third-party providers. Material risks from threats to our information systems are reported by the Manager of IT Security to the ERM Committee.
In the event of a breach or incident, our Manager of IT Security assumed primary responsibility for leading our response to mitigate impact and initiate the recovery processes, given the vacancy in the Director of Information Technology position. Following the identification of a breach or incident, the Manager of IT Security reports incidents of a medium or high severity level2 to our senior leadership team. Incidents of a high severity level are also reviewed by our Disclosure Committee to assess materiality and any disclosure obligations. All incidents are reported to the Audit Committee at the next scheduled meeting, and incidents of high severity level are immediately reported to the Audit Committee. In the event of a significant incident, the matter is reported to the full Board of Directors.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] During this period of vacancy, our Manager of IT Security, who has over 20 years of information technology experience,1 assumed primary responsibility for protecting the organization’s digital assets and sensitive information from cyber threats. The Manager of IT Security managed our partnerships with the external firm specializing in around-the-clock threat monitoring, detection, and response services, as well as other third-party providers. Material risks from threats to our information systems are reported by the Manager of IT Security to the ERM Committee.Our Manager of IT Security has more than 20 years of IT experience. He joined the company in 2015 as a Systems Engineer and was promoted to his current position in 2020. Prior to joining Rayonier, he worked as an Infrastructure Engineer at Enterprise Integration (EI), a managed services provider. Prior to joining EI, he held various IT roles in support and engineering.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] For each Audit Committee meeting, the Manager of IT Security prepares an updated cybersecurity report, featuring key metrics and threats. Additionally, the Manager of IT Security provides an annual cybersecurity briefing to the Audit Committee.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true