XML 66 R36.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Peabody uses digital technology to conduct its business operations and engage with its customers, vendors and partners. As the Company invests in technologies such as cloud, analytics, automation and artificial intelligence, it strives to provide the necessary controls to protect these digital assets from continuously evolving cybersecurity risks.
Peabody’s cybersecurity strategy emphasizes reduction of cybersecurity risk exposure and continuous improvement of its controls and policies based on industry recognized best practices for cybersecurity and information technology, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). This strategy includes: (i) proactive management of cybersecurity risk to ensure compliance with contractual, legal and regulatory requirements; (ii) performing due diligence on third parties to ensure they have sound cybersecurity practices in place; (iii) ensuring essential business services remain available during a business disruption; (iv) annual cybersecurity assessments to include NIST CSF maturity assessments, penetration testing and red team assessments, as well as table top exercises with subsequent remediation of key findings; (v) participation in Information Sharing and Collaboration industry groups; (vi) maintaining an updated cybersecurity policy and incident response plan; (vii) exercising cyber incident response plans and risk mitigation strategies to address potential incidents should they occur; and (viii) annual cybersecurity awareness training for all employees and directors, including formal training and simulated phishing events.
Third-party experts are engaged to conduct NIST CSF maturity assessments, penetration testing assessments, periodic red team assessments and table top exercises. At a minimum, at least one of these assessments is conducted annually by a third-party expert. Peabody also engages a third-party expert to assess the risk of its business and operational vendors.
Peabody’s enterprise risk management (ERM) framework considers cybersecurity risk alongside other company risks as part of the Company’s overall risk assessment process. The ERM team collaborates with the Chief Information Security Officer (CISO), to gather insights for assessing, identifying and managing cybersecurity threat risks, their severity, and potential mitigations.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Peabody’s enterprise risk management (ERM) framework considers cybersecurity risk alongside other company risks as part of the Company’s overall risk assessment process. The ERM team collaborates with the Chief Information Security Officer (CISO), to gather insights for assessing, identifying and managing cybersecurity threat risks, their severity, and potential mitigations.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] While Peabody has experienced cybersecurity incidents in the past, to date none have materially affected the Company’s business strategy, results of operations or financial condition
Cybersecurity Risk Board of Directors Oversight [Text Block] Peabody’s Board of Directors maintains direct oversight over cybersecurity risks and oversees an enterprise-wide approach to risk management, designed to support the achievement of organizational objectives to enhance long-term performance and stockholder value.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board, as a whole, and through its committees, is responsible for the oversight of risk management
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Senior leadership, including Peabody’s CISO, regularly briefs the Board on cybersecurity matters and the Board is informed of cybersecurity incidents deemed to have a moderate or higher business impact, even if such incidents are determined to be immaterial, on an ongoing basis.
Cybersecurity Risk Role of Management [Text Block] Peabody’s management is responsible for the day-to-day management of the risks the Company faces.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Peabody’s global cybersecurity department is responsible for overall cybersecurity strategy, policy, operations and cybersecurity incident response.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Team members who support the Company’s cybersecurity program invest in ongoing skills development including maintaining industry recognized certifications such as the ISC2 CISSP, GIAC GCIH, Comp TIA Security+, as well as platform specific certifications focused on Peabody’s current cybersecurity infrastructure.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Peabody’s management is responsible for the day-to-day management of the risks the Company faces. Senior leadership, including Peabody’s CISO, regularly briefs the Board on cybersecurity matters and the Board is informed of cybersecurity incidents deemed to have a moderate or higher business impact, even if such incidents are determined to be immaterial, on an ongoing basis.Peabody’s global cybersecurity department is responsible for overall cybersecurity strategy, policy, operations and cybersecurity incident response.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true