XML 85 R72.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management Strategy And Governance Line Items  
Cybersecurity Risk Management Processes For Assessing Identifying And Managing Threats TextBlock The Company’s cybersecurity policies, standards, processes, and practices for assessing, identifying, and managing material risks from cybersecurity threats and responding to cybersecurity incidents are integrated into the Company’s risk management program and are based on recognized frameworks established by the National Institute of Standards and Technology and other applicable industry standards. The Company has established controls and procedures, including an Incident Response Plan, that provide for the identification, analysis, notification, escalation, communication, and remediation of data security incidents at appropriate levels so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. The Company has also established a process to validate the aforementioned controls are in place and the results are being reviewed as a part of the overall company risk assessment. The Company’s Incident Response Plan (i) is designed to identify and detect information security threats through various mechanisms, such as through security controls and third-party disclosures, and (ii) sets forth a process to (a) analyze any such threats detected within the Company’s IT environment or within a third-party’s IT environment, (b) contain cybersecurity threats under various circumstances, and (c) better ensure the Company can recover from cybersecurity incidents to a normal state of business operations. The Company has established and maintains other incident response and recovery plans that address the Company’s response to a cybersecurity incident.
Cybersecurity Risk Management Processes Integrated Flag true
Cybersecurity Risk Management Processes Integrated TextBlock The Company’s cybersecurity policies, standards, processes, and practices for assessing, identifying, and managing material risks from cybersecurity threats and responding to cybersecurity incidents are integrated into the Company’s risk management program and are based on recognized frameworks established by the National Institute of Standards and Technology and other applicable industry standards.
Cybersecurity Risk Management Third Party Engaged Flag true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] While the Company faces a number of cybersecurity risks in connection with its business, as of the date of this report, the Company is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition. However, there can be no assurance that the Company, or its third-party service providers, will not experience a cybersecurity threat or incident in the future that could materially adversely affect the Company, including its business strategy, results of operations, or financial condition. For further discussion of the risks related to cybersecurity, see the risk factors discussed under Item 1A. “Risk Factors” in this report.
Cybersecurity Risk Board Of Directors Oversight TextBlock In addition, the Company’s information security/cybersecurity program is managed by the Manager of Infrastructure and Security, who is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The Manager of Infrastructure and Security and Chief Information Officer provide periodic reports to our Board and Audit Committee as well as our Chief Executive Officer and other members of our senior management as appropriate. We have also established cross-functional teams to collaborate and communicate on cybersecurity-related issues. The reports to management include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the emerging threat landscape. The Incident Response Team, which includes the Chief Information Officer, Manager of Infrastructure and Security, Chief Financial Officer and key operational leaders, is regularly engaged to discuss cybersecurity risks and to review the Company’s preparations for any security events. The Incident Response Team will notify the Board of Directors of any critical events as defined in the Incident Response Plan. Additionally, the Chief Information Officer regularly engages the Board representative with cybersecurity experience to identify Board-level needs for education and communication.
Cybersecurity Risk Board Committee Or Subcommittee Responsible For Oversight TextBlock Considering the pervasive and increasing threat from cyberattacks, the Board and the Audit Committee, with input from management, assess the Company’s cybersecurity threats and the measures implemented by the Company in an effort to mitigate and prevent cyberattacks. The Audit Committee consults with management regarding ongoing cybersecurity initiatives and requests management report to the Audit Committee or the full Board regularly on their assessment of the Company’s cybersecurity program and risks, including artificial intelligence.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Considering the pervasive and increasing threat from cyberattacks, the Board and the Audit Committee, with input from management, assess the Company’s cybersecurity threats and the measures implemented by the Company in an effort to mitigate and prevent cyberattacks. The Audit Committee consults with management regarding ongoing cybersecurity initiatives and requests management report to the Audit Committee or the full Board regularly on their assessment of the Company’s cybersecurity program and risks, including artificial intelligence. Both the Audit Committee and the full Board receive quarterly reports from the Chief Information Officer on cybersecurity risks and timely reports regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
Cybersecurity Risk Role of Management [Text Block] The Company has cybersecurity insurance (subject to specified retentions or deductibles) related to a cybersecurity incident that addresses costs, losses, and expenses related to cybersecurity investigations, crisis management, notification processes and credit monitoring services, public relations, and legal advice. However, damages, fines and claims arising from such incidents may not be covered or may exceed the amount of any insurance available or may not be insurable.

As part of its cybersecurity program, the Company deploys measures to deter, prevent, detect, respond to and mitigate cybersecurity threats, including firewalls, anti-malware, extended detection and response systems, identity and access controls, strong password controls, multi-factor authentication, software patching protocols, and physical security measures. The Company periodically assesses and tests the Company’s policies, standards, processes, and practices that are designed to address cybersecurity (including artificial intelligence-related) threats and incidents, including by assessing current threat intelligence, conducting tabletop exercises, vulnerability scanning, and performing external penetration testing. The Company has a process to report material results of such testing and assessments to the Board, and periodically adjusts the Company’s cybersecurity program based on these exercises. The Company engages third parties to oversee and conduct part of such testing, as well as perform external audits of security protocols and capabilities. The Company seeks to identify and oversee cybersecurity risks presented by third parties and their systems from a risk-based perspective by identifying critical vendors (defined based on capabilities provided and investments required) and reviewing software patching, upgrades and associated changes required to reduce risk. The Company also conducts cybersecurity training for employees, including mandatory training programs for system users. The Company’s training programs require employees to complete a knowledge check prior to completion of the program. Completion of the Company’s training programs is monitored by management.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] In addition, the Company’s information security/cybersecurity program is managed by the Manager of Infrastructure and Security, who is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The Manager of Infrastructure and Security and Chief Information Officer provide periodic reports to our Board and Audit Committee as well as our Chief Executive Officer and other members of our senior management as appropriate. We have also established cross-functional teams to collaborate and communicate on cybersecurity-related issues. The reports to management include updates on the Company’s cyber risks and threats, the status of projects to strengthen our information security systems, assessments of the information security program, and the emerging threat landscape.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Chief Information Officer holds an undergraduate degree in computer science and has served in various roles in information technology for over 30 years, including serving as a senior technology leader or Chief Information Officer of two public companies and two private equity-owned firms. The Chief Information Officer has prior experience supporting organizations that have experienced cybersecurity events and continues to learn more about the current trends and risks by partnering with third parties.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] In addition, the Company’s information security/cybersecurity program is managed by the Manager of Infrastructure and Security, who is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The Manager of Infrastructure and Security and Chief Information Officer provide periodic reports to our Board and Audit Committee as well as our Chief Executive Officer and other members of our senior management as appropriate. We have also established cross-functional teams to collaborate and communicate on cybersecurity-related issues.
Cybersecurity Risk Management Positions Or Committees Responsible Report To Board Flag true