XML 56 R34.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] We have established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats,
and have integrated these processes into our overall risk management systems and practices. We routinely assess material risks
from cybersecurity threats, including any potential unauthorized attack on, or use of, our information systems that may result in
adverse effects on the confidentiality, integrity, or availability of our information systems or any information stored therein.
Our security incident response framework classifies potential incidents by risk levels, and we prioritize our incident mitigation
and impact evaluation efforts based on those risk classifications or security incident categories, while focusing on maintaining
the resiliency of our systems. The risk assessments support the identification of reasonably foreseeable internal and external
risks, the likelihood of occurrence and any potential damage that could result from such risks, and the sufficiency of existing
policies, procedures, systems, controls, and other safeguards in place to manage such risks.
Following these risk assessments, we design, implement, and maintain reasonable safeguards to minimize the identified risks;
reasonably address any identified gaps in existing safeguards; update existing safeguards as necessary; and monitor the
effectiveness of our controls. Some of the other steps we have taken to detect, identify, assess, classify, and attempt to mitigate
cybersecurity risks include:
Adopting and periodically reviewing and updating information security and privacy policies;
Conducting targeted audits and penetration tests throughout the year, using both internal and external resources;
Complying with the Payment Card Industry Data Security Standard (PCI-DSS);
Implementing an Information Security Management System (ISMS) that is designed to generally align with the
requirements of the ISO 27001 standard;
Implementing a Privacy Information Management System (PIMS) that is designed to align with the requirements of
the ISO 27701 standard;
Engaging an experienced third party to independently evaluate our information security systems on a regular basis;
Adopting a vendor risk management program, which includes receiving the results of cybersecurity evaluations
conducted on certain vendors engaged in high-risk data processing;
Providing security and data protection training and awareness to our employees, contractors and key partners with
access to sensitive information and systems; and
Maintaining cyber liability insurance.
Although certain of our systems are designed to align with requirements of ISO 27701, this does not mean that we will meet
any particular technical standards, specifications, or requirements, but rather we use ISO 27701 and other cybersecurity
standards as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
At this time, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity
incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business
strategy, results of operations, or financial condition. For additional information regarding risks from cybersecurity threats,
please refer to Item 1A “Risk Factors -Cybersecurity, Data Privacy and Technology Risks.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We have established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats,
and have integrated these processes into our overall risk management systems and practices. We routinely assess material risks
from cybersecurity threats, including any potential unauthorized attack on, or use of, our information systems that may result in
adverse effects on the confidentiality, integrity, or availability of our information systems or any information stored therein.
Our security incident response framework classifies potential incidents by risk levels, and we prioritize our incident mitigation
and impact evaluation efforts based on those risk classifications or security incident categories, while focusing on maintaining
the resiliency of our systems. The risk assessments support the identification of reasonably foreseeable internal and external
risks, the likelihood of occurrence and any potential damage that could result from such risks, and the sufficiency of existing
policies, procedures, systems, controls, and other safeguards in place to manage such risks.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Cybersecurity and data protection are integrated into our overall risk management and oversight framework. Our Board of
Directors periodically receives reports from our committees, cybersecurity management, external professional advisors, and
other relevant Company personnel regarding various types of risks faced by the Company and the Company’s risk mitigation
efforts related thereto, including cybersecurity risks and related mitigation efforts.
The Board also receives presentations from management regarding trends in cybersecurity risks and risk mitigation initiatives
and plans, including briefings on recent breaches at other companies and key takeaways and lessons learned that are applicable
to our business. The Board will also periodically review key cybersecurity and data privacy related benchmarks for the
Company.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company has a dedicated Security Forum and a Data Protection Committee comprising members from our senior
leadership that convene on a regular basis to receive updates from our committees, cybersecurity management, external
professional advisors, and other relevant Company personnel about the Cybersecurity and Privacy programs we have in place;
discuss and assess material risks and planned risk mitigation, incidents and planned remediation efforts, trends observed,
consider cybersecurity-related proposals, and review and adopt changes in cybersecurity policies.
Cybersecurity Risk Role of Management [Text Block] In the event we identify a potential cybersecurity issue, we have defined procedures for responding to such issues, including
procedures that address when and how to engage with Company management, our Board of Directors, other stakeholders, and
law enforcement when responding to such issues.
We have a dedicated management team overseeing our cybersecurity initiatives, led by our Chief Information Officer, our Vice
President and Global Data Privacy Officer, and our Vice President of Cybersecurity. Our Chief Information Officer has over 25
years’ experience overseeing and managing information technology teams and complex IT systems, and our Vice President of
Cybersecurity has over 15 years’ experience developing and managing cybersecurity functions and strategies. Our Vice
President of Global Data Privacy is a recognized leader in the industry with over 7 years’ experience in managing global data
privacy programs.
Our cybersecurity management team regularly meets with industry trust groups, senior executives and other team members to
provide oversight with respect to our cybersecurity risk detection, identification, assessment, classification, and mitigation
efforts.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] We have a dedicated management team overseeing our cybersecurity initiatives, led by our Chief Information Officer, our Vice President and Global Data Privacy Officer, and our Vice President of Cybersecurity.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Information Officer has over 25
years’ experience overseeing and managing information technology teams and complex IT systems, and our Vice President of
Cybersecurity has over 15 years’ experience developing and managing cybersecurity functions and strategies. Our Vice
President of Global Data Privacy is a recognized leader in the industry with over 7 years’ experience in managing global data
privacy programs.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our cybersecurity management team regularly meets with industry trust groups, senior executives and other team members to
provide oversight with respect to our cybersecurity risk detection, identification, assessment, classification, and mitigation
efforts.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true