XML 51 R31.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Our industry has become increasingly dependent on digital technologies to conduct certain processing activities. For example, we depend on digital technologies to perform many of our services, to process and record financial and operating data and to collect and store sensitive data, including our proprietary business information and personally identifiable information of our employees and others. We recognize the importance of assessing and managing material risks associated with cybersecurity threats. We seek to assess, identify and manage cybersecurity risks for our IT environment, leveraging the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”), through the processes described below:

Risk Assessment:

We recognize that cybersecurity threats are constantly evolving, and we have implemented risk management procedures designed to protect our systems and data. We conduct vulnerability assessments, and periodic audits to identify and address potential cybersecurity vulnerabilities. We conduct periodic assessments to identify material cybersecurity risks, and we endeavor to update cybersecurity infrastructure, procedures, policies, and education programs in response to those findings. As part of our efforts to safeguard our systems and data, we have sought to implement industry-standard security controls, including firewalls, encryption, and multi-factor authentication.

Incident Identification and Response:

A monitoring and detection system has been implemented to help promptly identify cybersecurity incidents and recommend mitigating actions. Despite our best efforts, no security measure is entirely foolproof. In the event of a cybersecurity incident, we utilize a range of standard incident response practices to attempt to identify, analyze, contain, and recover the event with the goal of minimizing the impact and restoring normal operations.

Cybersecurity Training and Awareness:

We require that our employees receive periodic cybersecurity trainings including phishing campaigns and general awareness campaigns.

Access Controls:

Users are provided with access consistent with the principle of least privilege, which requires that users be given no more access than necessary to complete their job functions. A multi-factor authentication process has been implemented for employees accessing company information.

We engage third-party vendors, assessors, consultants, auditors, and other third party service providers in connection with the above processes. We recognize that third-party service providers introduce cybersecurity risks. We have implemented processes to oversee and identify the risks from cybersecurity threats that impact select suppliers and third-party service providers with whom we share personal identifying and confidential information. The above cybersecurity risk management processes are integrated into the Company’s overall enterprise risk management processes.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We recognize that cybersecurity threats are constantly evolving, and we have implemented risk management procedures designed to protect our systems and data. We conduct vulnerability assessments, and periodic audits to identify and address potential cybersecurity vulnerabilities. We conduct periodic assessments to identify material cybersecurity risks, and we endeavor to update cybersecurity infrastructure, procedures, policies, and education programs in response to those findings. As part of our efforts to safeguard our systems and data, we have sought to implement industry-standard security controls, including firewalls, encryption, and multi-factor authentication.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Our Board of Directors has delegated the responsibility for the oversight of risks from cybersecurity threats and our cybersecurity practices to the Audit Committee. Our Board of Directors and our Audit Committee receive regular updates on potential cybersecurity risks and mitigation strategies from the Company’s Chief Technology Officer (“CTO”).

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Audit Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]

Our Board of Directors has delegated the responsibility for the oversight of risks from cybersecurity threats and our cybersecurity practices to the Audit Committee. Our Board of Directors and our Audit Committee receive regular updates on potential cybersecurity risks and mitigation strategies from the Company’s Chief Technology Officer (“CTO”).

Cybersecurity Risk Role of Management [Text Block]

Management is responsible for assessing and managing risks from cybersecurity threats and implementing the Company’s cybersecurity strategies. Our CTO focuses on current and emerging cybersecurity matters and is responsible for establishing and maintaining the Company’s cybersecurity-related policies and procedures. Our CTO has an Engineering degree from Rice University, a Master of Business Administration from Harvard Business School, more than 20 years' work experience, and a background in leading digital / software development organizations. Supporting our CTO is the Company’s Vice President of Corporate Platform and Infrastructure and our team of cybersecurity experts (collectively with the CTO, the “Technology Team”). Our Vice President has an undergraduate degree from The University of Houston and has served in various Information Technology and Information Security roles for over 20 years across oil and gas, consulting, and power generation sectors. This team is collectively responsible for upward reporting on an as-needed basis of emerging cybersecurity incidents to senior management and, if appropriate, the Audit Committee of the Board of Directors. To facilitate effective oversight, our Technology Team holds regular discussions with our management team, the Audit Committee and the Board of Directors around cybersecurity risks, incident trends, and the effectiveness of our cybersecurity measures.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CTO has an Engineering degree from Rice University, a Master of Business Administration from Harvard Business School, more than 20 years' work experience, and a background in leading digital / software development organizations. Supporting our CTO is the Company’s Vice President of Corporate Platform and Infrastructure and our team of cybersecurity experts (collectively with the CTO, the “Technology Team”). Our Vice President has an undergraduate degree from The University of Houston and has served in various Information Technology and Information Security roles for over 20 years across oil and gas, consulting, and power generation sectors. 
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] responsible for upward reporting on an as-needed basis of emerging cybersecurity incidents to senior management and, if appropriate, the Audit Committee of the Board of Directors. To facilitate effective oversight, our Technology Team holds regular discussions with our management team, the Audit Committee and the Board of Directors around cybersecurity risks, incident trends, and the effectiveness of our cybersecurity measures
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true