XML 193 R21.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Risk Management and Strategy

Information systems and other technologies, including those related to the Corporation’s information and operational technology systems, and its technical and environmental data, are an important part of the Corporation’s business activities. We must comply with certain elevated contractual requirements, including those related to adequately safeguarding controlled unclassified information and reporting cybersecurity incidents to the DOW. We continue to implement cybersecurity processes designed to align with DOW requirements, instructions and guidance and work with the DOW as needed to assess cybersecurity risk and implement policies and practices aimed at mitigating identified risks as appropriate. Accordingly, the Company maintains processes for assessing, identifying and managing material risks from cybersecurity threats.

Such processes include the use of traffic monitoring tools, as well as training Corporation personnel to detect, report and prevent (where applicable) suspicious activity involving the Corporation’s IT systems and other technologies. We also employ monitoring mechanisms designed to help us detect and respond to cybersecurity threats. We conduct regular assessments and testing of the effectiveness of these controls, including security audits, incident response planning and regulatory compliance assessments. We seek to foster cybersecurity awareness and responsibility throughout the organization by regularly providing our employees with training on cybersecurity practices.

We use user access controls to limit unauthorized access to sensitive information and critical systems. In addition, we use multi-factor authentication for remote access, use of privileged accounts and access to critical systems. Encryption methods are used to protect sensitive data such as customer data, financial information and other confidential data. The implementation and management of these cybersecurity processes are integrated with the Company’s overall operational risk management processes, which seeks to limit our exposure to unnecessary risks across our operations.

We maintain an incident response plan that outlines the steps to be taken in the event of a cybersecurity incident. In accordance with the Company’s internal protocols, designated personnel in the management team are responsible for notifying relevant leadership, including senior management and the Board of Directors, of certain cybersecurity events that may significantly affect business operations. The Company’s procedures also involve:

Gathering information about the cybersecurity incident and internally escalating the issue as appropriate.
Consulting with cybersecurity consultants and other parties to assess the cybersecurity incident.
Evaluating the materiality of the cybersecurity incident, determining whether there are disclosure obligations under applicable securities laws, and external reporting, as required.

We may engage third party service providers including consultants and auditors in connection with the above processes. We recognize that third-party service providers may introduce cybersecurity risks.

Impacts from Cybersecurity Threats

As of the date of this Annual Report, though the Company and our service providers have been subject to certain cybersecurity incidents, we are not aware of any previous cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company. However, we acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains. Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cyberattack will not occur. A successful attack on our information technology systems could have significant consequences to the business. For additional information about the risks to our business associated with a breach or compromise to our information technology systems, see “Item 1A. Risk Factors – System security vulnerabilities, data breaches and cyberattacks could compromise proprietary or otherwise sensitive information or disrupt operations, which could adversely affect Perpetua Resources’ business, reputation, operations and stock price” above.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

Such processes include the use of traffic monitoring tools, as well as training Corporation personnel to detect, report and prevent (where applicable) suspicious activity involving the Corporation’s IT systems and other technologies. We also employ monitoring mechanisms designed to help us detect and respond to cybersecurity threats. We conduct regular assessments and testing of the effectiveness of these controls, including security audits, incident response planning and regulatory compliance assessments. We seek to foster cybersecurity awareness and responsibility throughout the organization by regularly providing our employees with training on cybersecurity practices.

We use user access controls to limit unauthorized access to sensitive information and critical systems. In addition, we use multi-factor authentication for remote access, use of privileged accounts and access to critical systems. Encryption methods are used to protect sensitive data such as customer data, financial information and other confidential data. The implementation and management of these cybersecurity processes are integrated with the Company’s overall operational risk management processes, which seeks to limit our exposure to unnecessary risks across our operations.

We maintain an incident response plan that outlines the steps to be taken in the event of a cybersecurity incident. In accordance with the Company’s internal protocols, designated personnel in the management team are responsible for notifying relevant leadership, including senior management and the Board of Directors, of certain cybersecurity events that may significantly affect business operations. The Company’s procedures also involve:

Gathering information about the cybersecurity incident and internally escalating the issue as appropriate.
Consulting with cybersecurity consultants and other parties to assess the cybersecurity incident.
Evaluating the materiality of the cybersecurity incident, determining whether there are disclosure obligations under applicable securities laws, and external reporting, as required.

We may engage third party service providers including consultants and auditors in connection with the above processes. We recognize that third-party service providers may introduce cybersecurity risks.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] As of the date of this Annual Report, though the Company and our service providers have been subject to certain cybersecurity incidents, we are not aware of any previous cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company. However, we acknowledge that cybersecurity threats are continually evolving, and the possibility of future cybersecurity incidents remains. Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cyberattack will not occur. A successful attack on our information technology systems could have significant consequences to the business.
Cybersecurity Risk Board of Directors Oversight [Text Block]

Our full Board and our Audit Committee oversee risks from cybersecurity threats and our cybersecurity practices and policies. Accordingly, our CFO periodically updates the Board and Audit Committee on cybersecurity matters, including cybersecurity risks. Additionally, our Board and Audit Committee, as well as senior management, receive reports on an as-needed basis regarding our cybersecurity posture, cybersecurity incidents and remediation efforts.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Board and our Audit Committee
Cybersecurity Risk Role of Management [Text Block]

Our IT Systems Manager oversees our cybersecurity program and is responsible for identifying, assessing and managing cybersecurity risks to the Corporation. The IT Systems Manager reports directly to our CFO. Our IT Systems Manager holds an associate degree in computer application and support and has served in various roles in information systems administration for over ten years, including roles involving managing information technology and systems and implementing cybersecurity programs.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] IT Systems Manager
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our IT Systems Manager holds an associate degree in computer application and support and has served in various roles in information systems administration for over ten years, including roles involving managing information technology and systems and implementing cybersecurity programs.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] our CFO periodically updates the Board and Audit Committee on cybersecurity matters, including cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true