XML 42 R27.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

We have established processes, procedures, and controls to identify, manage, assess, and mitigate material risks from cybersecurity threats which are designed to help protect our information assets and operations from internal and external cyber threats by understanding and seeking to manage risk while ensuring business resiliency, protecting employee and customer information from unauthorized access or attack, and securing our networks, systems, devices, products, and services, or our Cybersecurity Risk Mitigation Practices. We conduct tests on our systems and incident simulations to help discover potential vulnerabilities and ensure the effectiveness of our Cybersecurity Risk Mitigation Practices. We engage external parties, including consultants, independent privacy assessors, computer security firms, and risk management and governance experts, to enhance our cybersecurity oversight. We also regularly consult with industry groups on emerging industry trends. In order to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers, we have a third-party risk management program designed to help protect against the misuse of information technology by third parties and business partners.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

We have established processes, procedures, and controls to identify, manage, assess, and mitigate material risks from cybersecurity threats which are designed to help protect our information assets and operations from internal and external cyber threats by understanding and seeking to manage risk while ensuring business resiliency, protecting employee and customer information from unauthorized access or attack, and securing our networks, systems, devices, products, and services, or our Cybersecurity Risk Mitigation Practices. We conduct tests on our systems and incident simulations to help discover potential vulnerabilities and ensure the effectiveness of our Cybersecurity Risk Mitigation Practices. We engage external parties, including consultants, independent privacy assessors, computer security firms, and risk management and governance experts, to enhance our cybersecurity oversight. We also regularly consult with industry groups on emerging industry trends. In order to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers, we have a third-party risk management program designed to help protect against the misuse of information technology by third parties and business partners.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Our Cybersecurity Risk Mitigation Practices are managed on a day-to-day basis by members of our Information Security Steering Committee, or the Committee, and are overseen by our Board of Directors. The Committee is composed of senior management, including our Chief Information Officer and Chief Financial Officer, and senior vice presidents from various areas of the organization including IT, compliance, legal, operations and human resources, including the Vice President of Information Security and Compliance. The Vice President of Information Security and Compliance has over 40 years of IT experience and is a certified information systems security professional. The Chief Information Officer has over 10 years of experience managing cybersecurity, data protection, and incident management teams, and over 20 years of experience managing compliance and regulatory processes and controls.

As part of the administration of our Cybersecurity Risk Mitigation Practices, the Committee is tasked with managing and mitigating our exposure to cybersecurity threats, creating our cybersecurity policies, and establishing short and long-term cybersecurity goals and objectives that are designed to protect our information systems. The Committee is also responsible for planning ordinary course security projects and initiatives aimed at ensuring that our organizational leaders are informing our employees about our cybersecurity policies and about cybersecurity basic practices. On a periodic basis, the Committee meets to review the performance and effectiveness of our Cybersecurity Risk Mitigation Practices.

Members of the Committee will present the results of the periodic performance and effectiveness review to our Board of Directors, who oversee our risk management processes directly and through its committees. These results, along with other cybersecurity topics including updates on previously identified material cybersecurity threats or incidents, are presented at regularly scheduled meetings. Members of the Committee will also notify our Board of Directors between such meetings regarding significant new or updates to ongoing cybersecurity threats or incidents.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Cybersecurity Risk Mitigation Practices are managed on a day-to-day basis by members of our Information Security Steering Committee, or the Committee, and are overseen by our Board of Directors. The Committee is composed of senior management, including our Chief Information Officer and Chief Financial Officer, and senior vice presidents from various areas of the organization including IT, compliance, legal, operations and human resources, including the Vice President of Information Security and Compliance.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]

Members of the Committee will present the results of the periodic performance and effectiveness review to our Board of Directors, who oversee our risk management processes directly and through its committees. These results, along with other cybersecurity topics including updates on previously identified material cybersecurity threats or incidents, are presented at regularly scheduled meetings. Members of the Committee will also notify our Board of Directors between such meetings regarding significant new or updates to ongoing cybersecurity threats or incidents.

Cybersecurity Risk Role of Management [Text Block] the Committee is tasked with managing and mitigating our exposure to cybersecurity threats, creating our cybersecurity policies, and establishing short and long-term cybersecurity goals and objectives
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Vice President of Information Security and Compliance
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Vice President of Information Security and Compliance has over 40 years of IT experience and is a certified information systems security professional
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]

As part of the administration of our Cybersecurity Risk Mitigation Practices, the Committee is tasked with managing and mitigating our exposure to cybersecurity threats, creating our cybersecurity policies, and establishing short and long-term cybersecurity goals and objectives that are designed to protect our information systems. The Committee is also responsible for planning ordinary course security projects and initiatives aimed at ensuring that our organizational leaders are informing our employees about our cybersecurity policies and about cybersecurity basic practices. On a periodic basis, the Committee meets to review the performance and effectiveness of our Cybersecurity Risk Mitigation Practices.

Members of the Committee will present the results of the periodic performance and effectiveness review to our Board of Directors, who oversee our risk management processes directly and through its committees. These results, along with other cybersecurity topics including updates on previously identified material cybersecurity threats or incidents, are presented at regularly scheduled meetings. Members of the Committee will also notify our Board of Directors between such meetings regarding significant new or updates to ongoing cybersecurity threats or incidents.

Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true