XML 73 R25.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We have established processes to assess, identify, and manage significant risks from cybersecurity threats as part of our broader enterprise-wide risk management system and processes, which is overseen by our Board of Directors and our Audit Committee, along with our executive management. Our cybersecurity policies, standards, processes, and practices are part of our information security management program, which is aligned to ISO 27001, an international standard to manage information security. ISO 27001 is published by the International Organization for Standardization (ISO), the world's largest developer of voluntary standards, and the International Electrotechnical Commission (IEC).
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Our cybersecurity policies, standards, processes, and practices are part of our information security management program, which is aligned to ISO 27001, an international standard to manage information security. ISO 27001 is published by the International Organization for Standardization (ISO), the world's largest developer of voluntary standards, and the International Electrotechnical Commission (IEC).
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our Board of Directors, executive management and Audit Committee are actively engaged in the oversight of IT risk management, including cybersecurity risk. Executive management and the Audit Committee share responsibility for overseeing our risk exposure to information security, cybersecurity, and data protection, as well as the steps management has taken to monitor and control such exposure. The Board of Directors, executive management and the Audit Committee receive quarterly reports on IT controls and information security. Additionally, on at least an annual basis, the Audit Committee reviews and discusses with management our policies and programs with respect to the oversight of IT risk and cybersecurity threats.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
Oversight for assessing and managing cybersecurity risk is performed by our IT cybersecurity team, with additional oversight performed by our Human Resources, Internal Audit and Legal Departments. Our executive management is briefed at least quarterly from these teams. Members of the Board of Directors, Audit Committee, and executive management are also encouraged to regularly engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our executive management, the Audit Committee, and the Board of Directors are notified of any significant cybersecurity incidents through an escalation process that is established in our incident response plan and incorporated into our disclosure controls and procedures. Additionally, we maintain a third-party vendor relationship which is available to the team for on-demand incident response and investigation, as needed.
Cybersecurity Risk Role of Management [Text Block] Oversight for assessing and managing cybersecurity risk is performed by our IT cybersecurity team, with additional oversight performed by our Human Resources, Internal Audit and Legal Departments. Our executive management is briefed at least quarterly from these teams.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Oversight for assessing and managing cybersecurity risk is performed by our IT cybersecurity team, with additional oversight performed by our Human Resources, Internal Audit and Legal Departments. Our executive management is briefed at least quarterly from these teams. Members of the Board of Directors, Audit Committee, and executive management are also encouraged to regularly engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our IT cybersecurity team is led by our Head of Information Security, Sean Pike. Mr. Pike has over 25 years of experience leading and scaling cybersecurity practices across regulated industry and critical infrastructure. Most recently, he served as Chief Information Security Officer at Business Wire, where he was responsible for transforming the security and compliance organizations to meet the needs of a globally distributed SaaS newswire. Prior to Business Wire, Mr. Pike held leadership positions at VMware, IDC, and Nielsen Radio.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Board of Directors, executive management and the Audit Committee receive quarterly reports on IT controls and information security. Additionally, on at least an annual basis, the Audit Committee reviews and discusses with management our policies and programs with respect to the oversight of IT risk and cybersecurity threats.
Oversight for assessing and managing cybersecurity risk is performed by our IT cybersecurity team, with additional oversight performed by our Human Resources, Internal Audit and Legal Departments. Our executive management is briefed at least quarterly from these teams. Members of the Board of Directors, Audit Committee, and executive management are also encouraged to regularly engage in ad hoc conversations with management on cybersecurity-related news events and discuss any updates to our cybersecurity risk management and strategy programs.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true