XML 57 R36.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy
We depend on integrated information systems to conduct our business. Accordingly, we have processes in place designed to protect our information systems and to assess, identify and manage material risks from cybersecurity threats. As part of our Cyber Security Continuous Improvement Strategy, we continuously assess and improve our information systems to keep pace with the evolving threat landscape. We maintain a cybersecurity program that incorporates security measures from frameworks like the National Institute of Standards and Technology and the Center for Internet Security ("NIST"). This does not mean that we meet any particular technical standards, specifications, or requirements, but only that we use the NIST as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business. Alongside the Company's preventative measures that employ traditional and artificial intelligence technologies, we actively monitor and audit our information technology and data assets to detect any anomalies and to respond quickly to potential threats that may arise.
In addition to applying security controls to prevent unauthorized access to sensitive information and protecting the Company's information systems and networks from exploitation by outsiders, we also deploy cybersecurity training courses to all employees at least annually, maintain an incident response plan, establish cybersecurity contingency plans and conduct phishing testing on a quarterly basis.
The oversight of the Company's cybersecurity risk management process is integrated into our annual Enterprise Risk Management ("ERM") process. Our ERM process is designed to enable leaders to identify and assess leading risks facing the Company, including risks related to cybersecurity, and work collaboratively to implement plans to mitigate these risks. We also utilize third-party experts to evaluate the Company’s security program and test operational effectiveness of our security controls.
In addition, we have processes designed to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers. For example, our Terms and Conditions within our agreements with suppliers, vendors, contractors, consultants, partners and others with whom we do business (collectively "Suppliers") generally require that our Suppliers safeguard and protect the information entrusted to them, as well as information generated or developed by them, from unauthorized access, destruction, use, modification or disclosure. We also encourage the our Suppliers to maintain risked-based cybersecurity programs designed to mitigate emerging threats to their information systems, products, services and supply chain, while complying with all applicable contractual and legal requirements. However, we may have little or no oversight with respect to security measures employed by third-party service providers, which may ultimately prove to be ineffective at countering cybersecurity threats.
We have experienced cybersecurity incidents in the past and, while none of these cybersecurity incidents resulted in a material disruption to our business, we may experience additional cybersecurity incidents in the future. As of the filing of this Form 10-K, we do not believe that any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected, or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition. For additional information, refer to "Risks Relating to Our Business – A major failure of our information systems could harm our business; increased cybersecurity threats and more sophisticated and targeted cybersecurity attacks could pose a risk to our systems, networks and products." in "Item 1A.    Risk Factors" within this Form 10-K.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true