XML 61 R11.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] We rely on information technology systems, operational networks, design and development tools, and data environments that support our business activities. We have implemented and maintain information security processes designed to identify, assess, and manage material risks from cybersecurity threats to our critical computer networks, third-party hosted services, communications systems, hardware and software, and our critical data, including intellectual property and confidential, proprietary, strategic, or competitively sensitive information (collectively, our “Information Systems and Data”). 

Responsibility for identifying, assessing, and managing cybersecurity threats and risks primarily resides with Company management, including the Chief Operating Officer (“COO”) and the President of a third-party information technology service provider, who provide centralized oversight across the Company. This oversight extends to all subsidiaries, with certain entities in the process of being further integrated under a centralized information technology and cybersecurity governance structure. These personnel are responsible for identifying and assessing cybersecurity risks by monitoring and evaluating the Company’s threat environment using a combination of automated tools and external intelligence sources. These processes include real-time endpoint and network monitoring through managed detection and response services, continuous monitoring of network and server traffic, and the use of external cybersecurity intelligence feeds, including alerts and guidance issued by government and industry sources such as the Cybersecurity and Infrastructure Security Agency (“CISA”). Identified threats are evaluated based on applicability and potential severity, and responsive actions are taken as appropriate.

 

Depending on the environment and the nature of the systems involved, the Company maintains technical, physical, and organizational measures designed to mitigate material cybersecurity risks. These measures include, among other things, network security controls, access controls, data segregation, encryption of data, system and network monitoring, asset management and tracking, cybersecurity insurance coverage, and physical security controls over critical infrastructure and data locations. The Company also utilizes managed cybersecurity service providers to support real-time threat detection and response activities.

 

Cybersecurity risk management is integrated into the Company’s broader enterprise risk management and internal control considerations. Cybersecurity risks that could reasonably be expected to have a material impact on the Company’s operations, financial reporting, or business objectives are considered as part of management’s overall risk assessment processes and are escalated to senior management and, as appropriate, to the Board of Directors or its committees.

 

The Company uses third-party service providers to assist in identifying, assessing, and managing cybersecurity risks, including managed detection and response providers and information technology service providers that support day-to-day operations. In addition, the Company relies on third-party vendors for certain critical business operations, including information technology services, enterprise resource planning systems, payroll processing, financial systems, and consolidation and reporting platforms. Cybersecurity risks associated with critical third-party providers are managed through contractual provisions, review of available assurance reports, controls over vendor system access, and ongoing issue management by internal information technology personnel.

 

For a discussion of cybersecurity risks that may materially affect the Company, see Part I, Item 1A, Risk Factors, of this Annual Report on Form 10-K, including If our information technology systems or data, or those of the third parties with whom we work, are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions; litigation; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; loss of customers or sales; and other adverse consequences, risks which are amplified by our work for world governments.

 
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cybersecurity risk management is integrated into the Company’s broader enterprise risk management and internal control considerations. Cybersecurity risks that could reasonably be expected to have a material impact on the Company’s operations, financial reporting, or business objectives are considered as part of management’s overall risk assessment processes and are escalated to senior management and, as appropriate, to the Board of Directors or its committees.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Board of Directors Oversight [Text Block] Governance 

The Company’s Board of Directors oversees cybersecurity risk management as part of its general oversight responsibilities. The Audit Committee assists the Board in overseeing the Company’s cybersecurity, data privacy, and information technology risks, consistent with its oversight responsibilities under the Audit Committee charter.

 

Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including the COO and Chief Financial Officer (“CFO”). Our COO has relevant experience overseeing the implementation of the Company’s information systems and supporting the Company’s response to a cybersecurity incident, including recovery efforts that did not result in operational disruption. Our CFO holds a certificate in Cyber Security for Directors from the Corporate Governance Institute. Our Chief Executive Officer (“CEO”) also provides overall strategic oversight and has relevant technical and project management credentials, including Project Management Professional (“PMP”) and Microsoft Certified Systems Engineer (“MCSE”) certifications.

 

Our COO is primarily responsible for the operational management of the Company’s cybersecurity program, including hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s overall risk management strategy, and communicating key priorities to relevant personnel. Our COO is also responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports. Our CFO shares responsibility with our COO for overseeing cybersecurity risks related to financial reporting and assessing potential impacts of making certain cybersecurity disclosures.

 

Our cybersecurity incident response process is designed to escalate certain cybersecurity incidents to members of management depending on the circumstances, including the COO. The COO works with the Company’s incident response team and third-party information technology service providers, as appropriate, to help the Company assess, mitigate, and remediate cybersecurity incidents of which they are notified.

 

The Audit Committee receives periodic updates from management regarding the Company’s cybersecurity risk profile, threat environment, and mitigation activities, and reports to the full Board, as appropriate, on matters within the scope of its oversight. The Audit Committee also receives reports related to cybersecurity threats, risk and mitigation.

 
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company’s Board of Directors oversees cybersecurity risk management as part of its general oversight responsibilities.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee assists the Board in overseeing the Company’s cybersecurity, data privacy, and information technology risks, consistent with its oversight responsibilities under the Audit Committee charter.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our cybersecurity incident response process is designed to escalate certain cybersecurity incidents to members of management depending on the circumstances, including the COO. The COO works with the Company’s incident response team and third-party information technology service providers, as appropriate, to help the Company assess, mitigate, and remediate cybersecurity incidents of which they are notified.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee receives periodic updates from management regarding the Company’s cybersecurity risk profile, threat environment, and mitigation activities, and reports to the full Board, as appropriate, on matters within the scope of its oversight. The Audit Committee also receives reports related to cybersecurity threats, risk and mitigation.