XML 321 R36.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Process
We have established a cybersecurity risk management process that aims to identify, assess, mitigate, monitor, and report on
the IT risks and cybersecurity threats that may affect our business objectives, performance, reputation, and compliance. We
conduct an overall annual cybersecurity risk assessment to identify and prioritize the IT risks that may impact our business
strategy, results of operations, and financial condition. We have processes and controls that help prevent, detect, and recover
from security incidents and we also perform regular security assessments to test the resilience of our IT systems and networks
against potential attacks and vulnerabilities. Our employees are provided awareness training on a regular basis to help them
identify, avoid, mitigate, and report cybersecurity threats.
We use security assessments, penetration testing, and table-top or red teaming exercises with third parties to assess our
security posture and to continuously improve our processes. We also use our Internal Audit function to conduct additional
reviews and assessments. Our third-party service providers are subject to security risk assessments at the time of onboarding, on
a continuous basis and upon detection of an increase in risk profile. In addition, we require our providers to meet appropriate
security requirements, controls and responsibilities and to investigate security incidents that have impacted such providers, as
appropriate.
The Company has an Enterprise Risk Management ("ERM") Committee and process in place that reviews and evaluates
the overall risks to the Company, including its cybersecurity risks. The ERM process has the input of senior management and
other internal stakeholders, and the cybersecurity risk management process is incorporated into our ERM review. Cybersecurity
risks to the Company are reviewed, evaluated, and discussed on a quarterly basis and, when necessary, on an ad-hoc basis with
our Executive Committee and other members of the management team.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company has an Enterprise Risk Management ("ERM") Committee and process in place that reviews and evaluates
the overall risks to the Company, including its cybersecurity risks. The ERM process has the input of senior management and
other internal stakeholders, and the cybersecurity risk management process is incorporated into our ERM review. Cybersecurity
risks to the Company are reviewed, evaluated, and discussed on a quarterly basis and, when necessary, on an ad-hoc basis with
our Executive Committee and other members of the management team.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Management
Our Chief Information Officer/Chief Digital Officer ("CIO/CDO"), together with the Company’s security team, is
responsible for assessing, monitoring, and managing our cybersecurity risks. Our CIO/CDO has significant experience in  IT
security, information security, and cybersecurity having served in a variety of senior roles at the Company prior to serving as
CIO/CDO.  Our CIO/CDO also has experience with implementing various security and infrastructure transformation and
improvement programs.
We maintain controls and procedures that are designed to ensure prompt review and escalation of certain cybersecurity
incidents so that decisions regarding reporting and public disclosure of such incidents can be made in a timely manner to
comply with cybersecurity incident reporting requirements.
Board
Our Board, in coordination with the Audit Committee, oversees the management of the Company’s cybersecurity program
and risks from cybersecurity threats. Our Audit Committee receives annual reports on cybersecurity risks resulting from risk
assessments, progress of risk reduction initiatives, external auditor feedback, control maturity assessments, and relevant internal
and industry cybersecurity incidents. The CIO/CDO also informs the Audit Committee on the prevention, detection, mitigation,
and remediation of cybersecurity incidents, including significant security risks and information security vulnerabilities. The
Audit committee reports any significant matters to the Board.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board, in coordination with the Audit Committee, oversees the management of the Company’s cybersecurity program and risks from cybersecurity threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Audit Committee receives annual reports on cybersecurity risks resulting from risk
assessments, progress of risk reduction initiatives, external auditor feedback, control maturity assessments, and relevant internal
and industry cybersecurity incidents. The CIO/CDO also informs the Audit Committee on the prevention, detection, mitigation,
and remediation of cybersecurity incidents, including significant security risks and information security vulnerabilities. The
Audit committee reports any significant matters to the Board.
Cybersecurity Risk Role of Management [Text Block] Our Chief Information Officer/Chief Digital Officer ("CIO/CDO"), together with the Company’s security team, is
responsible for assessing, monitoring, and managing our cybersecurity risks. Our CIO/CDO has significant experience in  IT
security, information security, and cybersecurity having served in a variety of senior roles at the Company prior to serving as
CIO/CDO.  Our CIO/CDO also has experience with implementing various security and infrastructure transformation and
improvement programs.
The Company has an Enterprise Risk Management ("ERM") Committee and process in place that reviews and evaluates
the overall risks to the Company, including its cybersecurity risks. The ERM process has the input of senior management and
other internal stakeholders, and the cybersecurity risk management process is incorporated into our ERM review. Cybersecurity
risks to the Company are reviewed, evaluated, and discussed on a quarterly basis and, when necessary, on an ad-hoc basis with
our Executive Committee and other members of the management team.
We maintain controls and procedures that are designed to ensure prompt review and escalation of certain cybersecurity
incidents so that decisions regarding reporting and public disclosure of such incidents can be made in a timely manner to
comply with cybersecurity incident reporting requirements.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our Chief Information Officer/Chief Digital Officer ("CIO/CDO"), together with the Company’s security team, is
responsible for assessing, monitoring, and managing our cybersecurity risks. Our CIO/CDO has significant experience in  IT
security, information security, and cybersecurity having served in a variety of senior roles at the Company prior to serving as
CIO/CDO.  Our CIO/CDO also has experience with implementing various security and infrastructure transformation and
improvement programs.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CIO/CDO has significant experience in  IT
security, information security, and cybersecurity having served in a variety of senior roles at the Company prior to serving as
CIO/CDO.  Our CIO/CDO also has experience with implementing various security and infrastructure transformation and
improvement programs.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our Chief Information Officer/Chief Digital Officer ("CIO/CDO"), together with the Company’s security team, is
responsible for assessing, monitoring, and managing our cybersecurity risks. Our CIO/CDO has significant experience in  IT
security, information security, and cybersecurity having served in a variety of senior roles at the Company prior to serving as
CIO/CDO.  Our CIO/CDO also has experience with implementing various security and infrastructure transformation and
improvement programs.
The Company has an Enterprise Risk Management ("ERM") Committee and process in place that reviews and evaluates
the overall risks to the Company, including its cybersecurity risks. The ERM process has the input of senior management and
other internal stakeholders, and the cybersecurity risk management process is incorporated into our ERM review. Cybersecurity
risks to the Company are reviewed, evaluated, and discussed on a quarterly basis and, when necessary, on an ad-hoc basis with
our Executive Committee and other members of the management team.
We maintain controls and procedures that are designed to ensure prompt review and escalation of certain cybersecurity
incidents so that decisions regarding reporting and public disclosure of such incidents can be made in a timely manner to
comply with cybersecurity incident reporting requirements.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true