XML 56 R35.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Data and the systems through which we manage data are vital to our business. In the ordinary course of our business, we handle our business information as well as information about our customers, suppliers and business partners, including information related to potential new ventures and transactions, and personal information related to our employees, customers and business partners. Our business is dependent upon operational and information technology to process the data necessary to conduct our business. This breadth and complexity of the technology necessary for our business continues to expand, increasing our reliance on third-party technology solutions, including cloud and artificial intelligence systems.

To protect our data and systems against cybersecurity threats, our cybersecurity risk management program is designed to assess, identify, manage and mitigate cybersecurity threats that could adversely and materially affect our business. Our cybersecurity risk management program is aligned with our business strategy and integrated throughout our operations. Our cybersecurity risk management program is comprised of technical and administrative controls, processes, policies and procedures based on applicable laws and industry standards and guided by the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.

As part of our cybersecurity risk management program, we undertake ongoing cybersecurity risk assessments to help us detect, evaluate and respond to cybersecurity threats, including regular testing by our internal cybersecurity operations team. Our vulnerability management program is designed to identify, assess, and remediate cybersecurity threats in our systems, such as through penetration testing. We have implemented measures designed to address the risks associated with the use of industrial control systems to help maintain the reliability and safety of our operations. Our information technology and operational technology disaster recovery program is designed to help maintain the continuity of critical business operations in the event of a disruptive cybersecurity incident through procedures for data recovery, system restoration, and business resumption.

We engage third-party cybersecurity service providers to conduct cybersecurity audits, targeted attack testing, cybersecurity threat intelligence and cybersecurity incident response services. We also operate a threat hunting program to help us identify potential cybersecurity threats in our systems. We require all employees and certain contractors to participate in cybersecurity training designed to enhance their understanding of cybersecurity threats and their ability to identify and escalate potential incidents.

Our internal data privacy and data security team has processes to evaluate new third party technology service providers and periodically reassess certain providers that have or will have access (directly or indirectly) to our data and/or systems. These processes help us document and mitigate potential cybersecurity threats associated with our use of third-party technology service providers.

Our cybersecurity risk management program includes an incident response (“IR”) plan that is designed to facilitate our response to cybersecurity incidents, including an escalation process for cybersecurity incidents that may have a moderate or higher business impact to notify our executive officers, other members of our senior management team and other internal stakeholders.

Our IR plan provides our executive officers and other members of our senior management team with the information needed to assess whether a cybersecurity incident materially affected or is reasonably likely to materially affect our business strategy, results of operations, or financial condition, and the need for public disclosure. We aim to test our IR plan at least annually to assess its operational effectiveness. We strive to conduct an annual “tabletop” exercise during which we simulate cybersecurity incidents to help us prepare for and respond to a cybersecurity incident and to identify areas for potential improvement. These exercises are conducted in close coordination with members of our internal cybersecurity risk management team, our retained cybersecurity incident response consultants, outside cybersecurity counsel and internal technical, operations and insurance risk management, internal audit and legal personnel, as well as certain executive officers and members of the senior management team.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

To protect our data and systems against cybersecurity threats, our cybersecurity risk management program is designed to assess, identify, manage and mitigate cybersecurity threats that could adversely and materially affect our business. Our cybersecurity risk management program is aligned with our business strategy and integrated throughout our operations. Our cybersecurity risk management program is comprised of technical and administrative controls, processes, policies and procedures based on applicable laws and industry standards and guided by the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.

As part of our cybersecurity risk management program, we undertake ongoing cybersecurity risk assessments to help us detect, evaluate and respond to cybersecurity threats, including regular testing by our internal cybersecurity operations team. Our vulnerability management program is designed to identify, assess, and remediate cybersecurity threats in our systems, such as through penetration testing. We have implemented measures designed to address the risks associated with the use of industrial control systems to help maintain the reliability and safety of our operations. Our information technology and operational technology disaster recovery program is designed to help maintain the continuity of critical business operations in the event of a disruptive cybersecurity incident through procedures for data recovery, system restoration, and business resumption.

We engage third-party cybersecurity service providers to conduct cybersecurity audits, targeted attack testing, cybersecurity threat intelligence and cybersecurity incident response services. We also operate a threat hunting program to help us identify potential cybersecurity threats in our systems. We require all employees and certain contractors to participate in cybersecurity training designed to enhance their understanding of cybersecurity threats and their ability to identify and escalate potential incidents.

Our internal data privacy and data security team has processes to evaluate new third party technology service providers and periodically reassess certain providers that have or will have access (directly or indirectly) to our data and/or systems. These processes help us document and mitigate potential cybersecurity threats associated with our use of third-party technology service providers.

Our cybersecurity risk management program includes an incident response (“IR”) plan that is designed to facilitate our response to cybersecurity incidents, including an escalation process for cybersecurity incidents that may have a moderate or higher business impact to notify our executive officers, other members of our senior management team and other internal stakeholders.

Our IR plan provides our executive officers and other members of our senior management team with the information needed to assess whether a cybersecurity incident materially affected or is reasonably likely to materially affect our business strategy, results of operations, or financial condition, and the need for public disclosure. We aim to test our IR plan at least annually to assess its operational effectiveness. We strive to conduct an annual “tabletop” exercise during which we simulate cybersecurity incidents to help us prepare for and respond to a cybersecurity incident and to identify areas for potential improvement. These exercises are conducted in close coordination with members of our internal cybersecurity risk management team, our retained cybersecurity incident response consultants, outside cybersecurity counsel and internal technical, operations and insurance risk management, internal audit and legal personnel, as well as certain executive officers and members of the senior management team.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Our Board of Directors (the “Board”) oversees all cybersecurity risk management activities. The Board’s Audit Committee has been delegated strategic oversight of the Cybersecurity Committee (described below). At least annually, the Chief Information Security Officer (“CISO”), Chief Information Officer (“CIO”) and other members of our Cybersecurity Committee report to the Board on the state of our cybersecurity risk management program and current and emerging cybersecurity risks. Any cybersecurity incident deemed to have a moderate or higher business risk also is reported to the Board.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Audit Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] At least annually, the Chief Information Security Officer (“CISO”), Chief Information Officer (“CIO”) and other members of our Cybersecurity Committee report to the Board on the state of our cybersecurity risk management program and current and emerging cybersecurity risks.
Cybersecurity Risk Role of Management [Text Block]

We have a management-level Cybersecurity Committee that has primary responsibility for our overall cybersecurity risk management program. The Cybersecurity Committee oversees our internal cybersecurity personnel and retained external cybersecurity consultants and applicable third-party service providers. The Cybersecurity Committee includes our Chief Financial Officer, Chief Legal Officer (“CLO”), CIO, Chief People Officer, Director of Internal Audit, and Vice President of Data Insights.

Our internal cybersecurity risk management team consists of our cybersecurity operations team, cybersecurity engineering team and data privacy and data security compliance team that reports to our CISO. This team is responsible for identifying and managing cybersecurity threats and assessing and managing material risks from cybersecurity threats.

With more than two decades of cybersecurity and information security experience, our CISO leads our cybersecurity risk management team and holds several accredited certifications, including CISSP, CISA, CISM, and CRISC Leveraging their cybersecurity experience, knowledge of our company and leadership, our CISO plays an important role in both the strategic development and tactical execution of our cybersecurity risk management program,

Our CISO regularly meets with the Cybersecurity Committee to provide updates on cybersecurity threats, risk management activities and other issues related to preventing, detecting and mitigating cybersecurity incidents. Our CISO and members of the internal cybersecurity risk management team also consult with internal and external cybersecurity and threat intelligence consultants and communicate with senior management about cybersecurity threats and resource needs for managing them.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Chief Information Security Officer (“CISO”)
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] With more than two decades of cybersecurity and information security experience, our CISO leads our cybersecurity risk management team and holds several accredited certifications, including CISSP, CISA, CISM, and CRISC Leveraging their cybersecurity experience, knowledge of our company and leadership, our CISO plays an important role in both the strategic development and tactical execution of our cybersecurity risk management program
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our internal cybersecurity risk management team consists of our cybersecurity operations team, cybersecurity engineering team and data privacy and data security compliance team that reports to our CISO. This team is responsible for identifying and managing cybersecurity threats and assessing and managing material risks from cybersecurity threats.

Our CISO regularly meets with the Cybersecurity Committee to provide updates on cybersecurity threats, risk management activities and other issues related to preventing, detecting and mitigating cybersecurity incidents. Our CISO and members of the internal cybersecurity risk management team also consult with internal and external cybersecurity and threat intelligence consultants and communicate with senior management about cybersecurity threats and resource needs for managing them.

Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true