XML 49 R29.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cybersecurity Risk Management
At Goosehead, cybersecurity risk management is an integral part of our overall enterprise risk management system. Our cybersecurity risk management program is modeled after recognized data protection principles, such as the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF) and the National Association of Insurance Commissioners (NAIC) Data Security Model Law. These and other industry best practices provide the framework for identifying, monitoring, assessing and managing cybersecurity threats and incidents, including threats and incidents associated with the use of applications developed, and services provided, by third-party vendors and service providers, and facilitating coordination across different departments of the Company.
Our cybersecurity team, led by our Director, IT Security & Compliance, is responsible for assessing and maintaining our cybersecurity risk management program. We also have a cybersecurity committee, comprised of cross-
functional key business and technical leaders in the Company as well as the heads of our legal, governance, risk and compliance functions. The cybersecurity team identifies and assesses material cybersecurity risk by performing internal audits against cybersecurity controls and through regular consultations with, deliberation by, and recommendations from, our cybersecurity committees. Our cybersecurity team and cybersecurity committees utilize various tools and services designed to identify, monitor, assess and manage actual cybersecurity risk, including risks from cybersecurity threats associated with the use of third-party vendors and service providers. The cybersecurity team manages and maintains a risk register, incorporates risk mitigation items within our cybersecurity plans, conducts periodic reviews (primarily through our cybersecurity committees) of our mitigation and progress, and utilizes a third-party security risk management program both to screen third-party vendors and service providers prior to onboarding and to periodically re-evaluate existing third-party vendors and service providers based on risk classification.
Our cybersecurity program includes steps for assessing the severity of a cybersecurity threat or incident, identifying the source of a cybersecurity threat or incident (including whether such cybersecurity threat or incident is associated with a third-party vendor or service provider), implementing cybersecurity countermeasures and mitigation strategies, and informing management and our board of directors of material cybersecurity threats and incidents. The cybersecurity team also conducts regular vulnerability assessments, and our cybersecurity and risk management teams perform annual risk assessments. We utilize a third party to conduct regular risk assessments of our new and existing third-party vendors and service providers and a separate vendor performs penetration testing annually. All users of our information systems receive regular cybersecurity awareness training, and our cybersecurity team provides annual training to all employees.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] At Goosehead, cybersecurity risk management is an integral part of our overall enterprise risk management system.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Management is responsible for identifying, monitoring, assessing and managing material cybersecurity risks on an ongoing basis by establishing processes designed to ensure that potential cybersecurity risks are monitored, putting in place appropriate mitigation and remediation measures, and maintaining cybersecurity programs. Our cybersecurity programs are under the direction of our Director, IT Security & Compliance, who directs our cybersecurity team and oversees the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents. Our Director, IT Security & Compliance has over 25 years of experience in IT systems architecture, application development, and cybersecurity, and is certified in software development, systems, AI and machine learning, database, and networking.
As discussed above, we also have a cybersecurity committee, which consists of cross-functional key business and technical leaders in the Company as well as the heads of our governance, risk and compliance functions. Our cybersecurity committee meets monthly to address cybersecurity risks and evaluate our cybersecurity program.
Management, including our Director, IT Security & Compliance and our cybersecurity committees, updates our General Counsel on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies on a monthly basis. Our General Counsel provides quarterly cybersecurity reports to the audit committee of the board of directors that cover, among other topics, third-party assessments of the Company’s cybersecurity programs and any updates to the Company’s cybersecurity programs and mitigation strategies, and other cybersecurity developments. Our General Counsel will also provide updates on cybersecurity threats and incidents to the audit committee and/or the board of directors as part of our incident response processes, based on management’s assessment of risk.
Our board of directors has ultimate oversight responsibility for our overall enterprise risk management and is responsible for ensuring that management has processes in place designed to identify, monitor and evaluate cybersecurity risks to which the Company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate and remediate cybersecurity threats and incidents. In particular, the board of directors has entrusted the audit committee with oversight of our cybersecurity program and related risks. Our General Counsel meets with the audit committee of the board of directors on at least a quarterly basis to review and discuss our cybersecurity and other information technology strategies and policies.
In 2025, we did not identify any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or incidents, or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see “Risk Factors – Risks relating to intellectual property, data privacy and cybersecurity” in this annual report on Form 10-K.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our board of directors has ultimate oversight responsibility for our overall enterprise risk management and is responsible for ensuring that management has processes in place designed to identify, monitor and evaluate cybersecurity risks to which the Company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate and remediate cybersecurity threats and incidents.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our General Counsel meets with the audit committee of the board of directors on at least a quarterly basis to review and discuss our cybersecurity and other information technology strategies and policies.
Cybersecurity Risk Role of Management [Text Block] Our cybersecurity programs are under the direction of our Director, IT Security & Compliance, who directs our cybersecurity team and oversees the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents. Our Director, IT Security & Compliance has over 25 years of experience in IT systems architecture, application development, and cybersecurity, and is certified in software development, systems, AI and machine learning, database, and networking.
As discussed above, we also have a cybersecurity committee, which consists of cross-functional key business and technical leaders in the Company as well as the heads of our governance, risk and compliance functions. Our cybersecurity committee meets monthly to address cybersecurity risks and evaluate our cybersecurity program.
Management, including our Director, IT Security & Compliance and our cybersecurity committees, updates our General Counsel on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies on a monthly basis. Our General Counsel provides quarterly cybersecurity reports to the audit committee of the board of directors that cover, among other topics, third-party assessments of the Company’s cybersecurity programs and any updates to the Company’s cybersecurity programs and mitigation strategies, and other cybersecurity developments. Our General Counsel will also provide updates on cybersecurity threats and incidents to the audit committee and/or the board of directors as part of our incident response processes, based on management’s assessment of risk.
Our board of directors has ultimate oversight responsibility for our overall enterprise risk management and is responsible for ensuring that management has processes in place designed to identify, monitor and evaluate cybersecurity risks to which the Company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate and remediate cybersecurity threats and incidents. In particular, the board of directors has entrusted the audit committee with oversight of our cybersecurity program and related risks. Our General Counsel meets with the audit committee of the board of directors on at least a quarterly basis to review and discuss our cybersecurity and other information technology strategies and policies.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Management, including our Director, IT Security & Compliance and our cybersecurity committees, updates our General Counsel on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies on a monthly basis. Our General Counsel provides quarterly cybersecurity reports to the audit committee of the board of directors that cover, among other topics, third-party assessments of the Company’s cybersecurity programs and any updates to the Company’s cybersecurity programs and mitigation strategies, and other cybersecurity developments. Our General Counsel will also provide updates on cybersecurity threats and incidents to the audit committee and/or the board of directors as part of our incident response processes, based on management’s assessment of risk.
Our board of directors has ultimate oversight responsibility for our overall enterprise risk management and is responsible for ensuring that management has processes in place designed to identify, monitor and evaluate cybersecurity risks to which the Company is exposed and to implement processes and programs to manage cybersecurity risks and mitigate and remediate cybersecurity threats and incidents. In particular, the board of directors has entrusted the audit committee with oversight of our cybersecurity program and related risks. Our General Counsel meets with the audit committee of the board of directors on at least a quarterly basis to review and discuss our cybersecurity and other information technology strategies and policies.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our cybersecurity programs are under the direction of our Director, IT Security & Compliance, who directs our cybersecurity team and oversees the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents. Our Director, IT Security & Compliance has over 25 years of experience in IT systems architecture, application development, and cybersecurity, and is certified in software development, systems, AI and machine learning, database, and networking.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
Management, including our Director, IT Security & Compliance and our cybersecurity committees, updates our General Counsel on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies on a monthly basis. Our General Counsel provides quarterly cybersecurity reports to the audit committee of the board of directors that cover, among other topics, third-party assessments of the Company’s cybersecurity programs and any updates to the Company’s cybersecurity programs and mitigation strategies, and other cybersecurity developments. Our General Counsel will also provide updates on cybersecurity threats and incidents to the audit committee and/or the board of directors as part of our incident response processes, based on management’s assessment of risk.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true