XML 49 R34.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Process and Standards
We devote significant resources to network security, data encryption, monitoring, and system maintenance. Our cybersecurity program is aligned with best practices, specifically the DFARS / NIST 800-171 IT Security Standard for US Government Contractors, reflecting our global operational footprint. During the year, we further strengthened our defense strategy through the enterprise-wide implementation of Sophos Endpoint Detection and Response (EDR) solutions, enhancing our real-time threat analysis and mitigation capabilities across our network. To ensure long-term success, we are committed to discovering and preparing for potential threats through the following mechanisms:
Incident Response: We maintain an incident response plan that establishes procedures for reporting and handling cybersecurity events.
Audits and Assessments: We perform periodic security audits and assessments, regularly engaging qualified independent third parties to assess our cybersecurity maturity and control environment.
Third-Party Risk: We depend on third-party vendors for firewalls, virus solutions, and backups. To manage this risk, our IT professionals perform due diligence and risk analyses on vendors, verifying security testing prior to software installation.
As of the date of the filing of this Form 10-K, we are not aware of any successful attempts by third parties to gain access to our systems that have had, or are reasonably likely to have, a material effect on our business, operations, or financial condition. Although no incidents have been material to date, we recognize that cyber-attacks are becoming more sophisticated and our network remains potentially vulnerable.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Luxfer has integrated cybersecurity risk management into our broader enterprise risk management processes. Luxfer is committed to safeguarding and protecting our information technology (“IT”) network, equipment, and systems against cybersecurity threats to ensure our security and reduce risk.
Process and Standards
We devote significant resources to network security, data encryption, monitoring, and system maintenance. Our cybersecurity program is aligned with best practices, specifically the DFARS / NIST 800-171 IT Security Standard for US Government Contractors, reflecting our global operational footprint. During the year, we further strengthened our defense strategy through the enterprise-wide implementation of Sophos Endpoint Detection and Response (EDR) solutions, enhancing our real-time threat analysis and mitigation capabilities across our network. To ensure long-term success, we are committed to discovering and preparing for potential threats through the following mechanisms:
Incident Response: We maintain an incident response plan that establishes procedures for reporting and handling cybersecurity events.
Audits and Assessments: We perform periodic security audits and assessments, regularly engaging qualified independent third parties to assess our cybersecurity maturity and control environment.
Third-Party Risk: We depend on third-party vendors for firewalls, virus solutions, and backups. To manage this risk, our IT professionals perform due diligence and risk analyses on vendors, verifying security testing prior to software installation.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Board of Directors Oversight
The Board of Directors is responsible for overseeing cybersecurity, information security, and technology risk as part of its regular risk oversight function. The Board, comprised of independent Non-Executive Directors and one Executive Director, receives regular reports on information security matters from the Senior Leadership team at least quarterly as it is their responsibility to oversee Management's actions to identify, access, mitigate and remediate material risk.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The cybersecurity program is managed by our IT Steering Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Committee Structure: The Committee is chaired by a member of the executive leadership team and includes IT Managers from across the company.
Operational Responsibility: Local IT teams, managed by IT Managers, are responsible for the day-to-day implementation and monitoring of IT policies within their respective business units.
Expertise: IT personnel are qualified within their respective roles and are provided with the resources necessary to carry out their responsibilities.
Cybersecurity Risk Role of Management [Text Block]
Management's Role
The cybersecurity program is managed by our IT Steering Committee, which maintains the vision, strategy, and operation of the program.
Committee Structure: The Committee is chaired by a member of the executive leadership team and includes IT Managers from across the company.
Operational Responsibility: Local IT teams, managed by IT Managers, are responsible for the day-to-day implementation and monitoring of IT policies within their respective business units.
Expertise: IT personnel are qualified within their respective roles and are provided with the resources necessary to carry out their responsibilities.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The cybersecurity program is managed by our IT Steering Committee
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Expertise: IT personnel are qualified within their respective roles and are provided with the resources necessary to carry out their responsibilities.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Board, comprised of independent Non-Executive Directors and one Executive Director, receives regular reports on information security matters from the Senior Leadership team at least quarterly as it is their responsibility to oversee Management's actions to identify, access, mitigate and remediate material risk.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true