XML 56 R35.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cybersecurity, and in particular cybersecurity risk management, is an important part of operations and a focus area for the Company. Cybersecurity risks are evaluated on an ongoing basis by the Company’s Technology department, both internally and with the assistance of external firms.

The Company engages a national security firm to improve its cybersecurity posture and keep current with evolving cybersecurity risks. The Company’s cybersecurity program is examined on a regular basis, and new procedures and tools are
adopted on an ongoing basis to address the changing cybersecurity landscape. The Company’s technology team gauges the effectiveness of its tools with periodic testing and evaluations.

The Company’s Board of Directors oversees the overall risk management process, including cybersecurity risks, which it administers in part through its Audit Committee. One of the Audit Committee’s responsibilities involves reviewing the Company’s policies regarding risk assessment and risk management, including with respect to cybersecurity risks. Risk oversight plays a role in all major decisions of the Company’s Board of Directors, and the evaluation of risk is a key part of its decision-making process.

Cybersecurity risks are considered as part of the risk management process across all levels of the organization but are also facilitated through a formal process in which the Company identifies significant risks through regular discussions with management and also develops responses and mitigating actions to address such risks. In conjunction with the Company’s Internal Audit department, management compiles a report of significant, enterprise risks that is shared with the Company’s Board of Directors and its Audit Committee annually or as needed. In addition, cybersecurity and information security risks are among the matters presented by the Chief Technology Officer (“CTO”) for discussion with the Company’s Board of Directors annually and its Audit Committee quarterly or as needed. The CTO, who reports to the Chief Financial Officer, is responsible for leading the assessment and management of cybersecurity risks. The Company's current CTO has more than twenty-five years of experience in IT across diverse industries, and he has designed and led the approach for the modernization of the Company's technology platforms and security posture since 2017.

As many security threats involve social engineering, the Company maintains a security awareness and training program for all employees. The program provides continuous, adaptive security simulations and education, including brief quarterly training modules focused on emerging and relevant threats. The Company monitors participation and progress to help ensure ongoing preparedness and awareness across the organization.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cybersecurity, and in particular cybersecurity risk management, is an important part of operations and a focus area for the Company. Cybersecurity risks are evaluated on an ongoing basis by the Company’s Technology department, both internally and with the assistance of external firms.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Company’s Board of Directors oversees the overall risk management process, including cybersecurity risks, which it administers in part through its Audit Committee. One of the Audit Committee’s responsibilities involves reviewing the Company’s policies regarding risk assessment and risk management, including with respect to cybersecurity risks. Risk oversight plays a role in all major decisions of the Company’s Board of Directors, and the evaluation of risk is a key part of its decision-making process.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company’s Board of Directors oversees the overall risk management process, including cybersecurity risks, which it administers in part through its Audit Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Cybersecurity risks are considered as part of the risk management process across all levels of the organization but are also facilitated through a formal process in which the Company identifies significant risks through regular discussions with management and also develops responses and mitigating actions to address such risks. In conjunction with the Company’s Internal Audit department, management compiles a report of significant, enterprise risks that is shared with the Company’s Board of Directors and its Audit Committee annually or as needed. In addition, cybersecurity and information security risks are among the matters presented by the Chief Technology Officer (“CTO”) for discussion with the Company’s Board of Directors annually and its Audit Committee quarterly or as needed. The CTO, who reports to the Chief Financial Officer, is responsible for leading the assessment and management of cybersecurity risks.
Cybersecurity Risk Role of Management [Text Block] Cybersecurity risks are considered as part of the risk management process across all levels of the organization but are also facilitated through a formal process in which the Company identifies significant risks through regular discussions with management and also develops responses and mitigating actions to address such risks. In conjunction with the Company’s Internal Audit department, management compiles a report of significant, enterprise risks that is shared with the Company’s Board of Directors and its Audit Committee annually or as needed. In addition, cybersecurity and information security risks are among the matters presented by the Chief Technology Officer (“CTO”) for discussion with the Company’s Board of Directors annually and its Audit Committee quarterly or as needed. The CTO, who reports to the Chief Financial Officer, is responsible for leading the assessment and management of cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] In conjunction with the Company’s Internal Audit department, management compiles a report of significant, enterprise risks that is shared with the Company’s Board of Directors and its Audit Committee annually or as needed. In addition, cybersecurity and information security risks are among the matters presented by the Chief Technology Officer (“CTO”) for discussion with the Company’s Board of Directors annually and its Audit Committee quarterly or as needed. The CTO, who reports to the Chief Financial Officer, is responsible for leading the assessment and management of cybersecurity risks
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Company's current CTO has more than twenty-five years of experience in IT across diverse industries, and he has designed and led the approach for the modernization of the Company's technology platforms and security posture since 2017.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Cybersecurity risks are considered as part of the risk management process across all levels of the organization but are also facilitated through a formal process in which the Company identifies significant risks through regular discussions with management and also develops responses and mitigating actions to address such risks. In conjunction with the Company’s Internal Audit department, management compiles a report of significant, enterprise risks that is shared with the Company’s Board of Directors and its Audit Committee annually or as needed. In addition, cybersecurity and information security risks are among the matters presented by the Chief Technology Officer (“CTO”) for discussion with the Company’s Board of Directors annually and its Audit Committee quarterly or as needed. The CTO, who reports to the Chief Financial Officer, is responsible for leading the assessment and management of cybersecurity risks
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true