XML 54 R38.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy

Our cybersecurity strategy is predicated on a risk-based approach, which is continuously informed by the standards provided by organizations such as the American Institute of Certified Public Accountants, the National Institute of Standards and Technology ("NIST"), the International Organization for Standardization, the Payment Card Industry, and others. Cybersecurity represents an important input to our overall approach to enterprise risk management ("ERM").

Our cybersecurity program is based on a framework designed to safeguard the confidentiality, integrity, and availability of our information assets. This program encompasses enterprise security policies, procedures, and technical measures to manage risks, protect sensitive data, and ensure compliance with relevant regulations. Our information security program utilizes a layered defense approach where components such as risk assessments, access controls, network security, encryption, employee training, and continuous monitoring and response processes provide layers of protection for our systems and assets.

Our cybersecurity program also considers the evolving use of AI, including generative AI, by both threat actors and defenders. We assess and seek to mitigate AI-enabled attack techniques, such as the use of AI to discover vulnerabilities or generate targeted social engineering, and we are incorporating AI-driven tools and analytics into our security monitoring, threat-hunting, and response processes to enhance our ability to identify, investigate, and remediate potential cybersecurity events.
As part of our cybersecurity program, our information security team identifies and assesses material risks based on the NIST and the International Organization for Standardization ("ISO") 27001 and ISO 27002 risk assessment models and then collaborates with internal business and technical partners to proactively create internal risk treatment plans that address identified risk exposures. In addition, we assess and manage cybersecurity risks through an incident security program which consolidates input from three primary departments, including our ERM department, which operates out of the Office of the Chief Financial Officer, our Privacy department, which operates out of the Office of the Chief Legal Officer, and the Information Security department, which operates out of the Office of the Chief Information Officer ("CIO"). Together, these departments provide subject matter expertise and specialized resources to deliver concentric layers of risk management and defense against both internal and external threats.

In addition, our cybersecurity program includes third-party cyber risk assessments which evaluate the security posture of our vendors and partners to mitigate potential vulnerabilities introduced through external connections. Data loss prevention controls are systematically implemented to prevent unauthorized data exfiltration and to protect sensitive information from compromise.

Our information security program undergoes assessments conducted by both internal and external experts. The outcomes of these evaluations are communicated to senior management and the Board for review.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Our cybersecurity program is based on a framework designed to safeguard the confidentiality, integrity, and availability of our information assets.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Board, through the Audit Committee, oversees our risk assessment and risk management activities, including our cybersecurity program. Our Audit Committee receives periodic reports from our CIO and is notified any time management determines that a cybersecurity incident may be material or may need to be reported to a regulatory body. Further, the Chair of our Audit Committee is regularly informed of cybersecurity risks and incidents that may be material, as well as those that are not.
Our cybersecurity program is led by an experienced CIO and an experienced Chief Information Security Officer ("CISO"). Our CIO has extensive experience in our industry with over 30 years of information technology experience, including extensive experience leading large global teams at several companies in his tenure. Our CISO has over 40 years of information technology experience, including 25 years of experience as a CISO leading large cybersecurity teams at four different insurance companies. Our CISO also has several industry-recognized designations.

As part of our cybersecurity risk management program, our information security department identifies, assesses, and manages cybersecurity risks, whether material or non-material. Through our Information Security department, the CIO and CISO work to ensure that key stakeholders are informed about the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents.

We have established and maintain incident response and recovery plans that address the detection, reporting, analysis, response, recovery, communication, documentation, and post-incident review of cybersecurity incidents. We periodically test and evaluate such plans on a routine basis.

As of the date of this Annual Report, we are not aware of any material risks from cyber security threats, including as a result of previous cybersecurity incidents, that are reasonably likely to have a material adverse effect on us, our business strategy, financial condition, or results of operations. For more information regarding the risks we face from cybersecurity threats, see "Risk Factors — Risks Related to Our Business — Like others in our industry, we face potential exposures to operational disruptions caused by cyber breaches or resiliency failures impacting us or third party technology providers upon whom we rely, which could impair website availability and crucial technology operations."
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Board, through the Audit Committee, oversees our risk assessment and risk management activities, including our cybersecurity program.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Board, through the Audit Committee, oversees our risk assessment and risk management activities, including our cybersecurity program. Our Audit Committee receives periodic reports from our CIO and is notified any time management determines that a cybersecurity incident may be material or may need to be reported to a regulatory body. Further, the Chair of our Audit Committee is regularly informed of cybersecurity risks and incidents that may be material, as well as those that are not.
Cybersecurity Risk Role of Management [Text Block]
As part of our cybersecurity program, our information security team identifies and assesses material risks based on the NIST and the International Organization for Standardization ("ISO") 27001 and ISO 27002 risk assessment models and then collaborates with internal business and technical partners to proactively create internal risk treatment plans that address identified risk exposures. In addition, we assess and manage cybersecurity risks through an incident security program which consolidates input from three primary departments, including our ERM department, which operates out of the Office of the Chief Financial Officer, our Privacy department, which operates out of the Office of the Chief Legal Officer, and the Information Security department, which operates out of the Office of the Chief Information Officer ("CIO"). Together, these departments provide subject matter expertise and specialized resources to deliver concentric layers of risk management and defense against both internal and external threats.

In addition, our cybersecurity program includes third-party cyber risk assessments which evaluate the security posture of our vendors and partners to mitigate potential vulnerabilities introduced through external connections. Data loss prevention controls are systematically implemented to prevent unauthorized data exfiltration and to protect sensitive information from compromise.

Our information security program undergoes assessments conducted by both internal and external experts. The outcomes of these evaluations are communicated to senior management and the Board for review.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
As part of our cybersecurity risk management program, our information security department identifies, assesses, and manages cybersecurity risks, whether material or non-material. Through our Information Security department, the CIO and CISO work to ensure that key stakeholders are informed about the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
Our cybersecurity program is led by an experienced CIO and an experienced Chief Information Security Officer ("CISO"). Our CIO has extensive experience in our industry with over 30 years of information technology experience, including extensive experience leading large global teams at several companies in his tenure. Our CISO has over 40 years of information technology experience, including 25 years of experience as a CISO leading large cybersecurity teams at four different insurance companies. Our CISO also has several industry-recognized designations.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
Our information security program undergoes assessments conducted by both internal and external experts. The outcomes of these evaluations are communicated to senior management and the Board for review.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true