XML 50 R28.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Our Cybersecurity Program

 

Our products and services are normally classified as EAR 99 (items not designated under the control) by the U.S. government, but our defense customers may ask us to make some alterations for the environments in which the products will be used. Moreover, our products sold for defense applications are integrated with our customers’ products. Given the nature of our business and the cybersecurity risks we face, we have instituted a cybersecurity program for identifying, assessing, and managing cybersecurity risks, which include material risks from cybersecurity threats to our internal systems, our products, services and programs for customers, and our supply chain.

 

Our enterprise cybersecurity program has been designed to align, as much as reasonably possible, with the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) standards, among others. The program includes processes and controls for the deployment of new IT systems by the Company and controls over new and existing system operations. We, or third parties we contract with, monitor and conduct regular testing of these controls and systems, including vulnerability management through active discovery and testing to regularly assess patching and configuration status. In addition, we require our employees to complete annual cybersecurity training, and we regularly conduct simulated phishing and cyber-related communications.

To supplement our internal capabilities, we engage third-party service providers to support aspects of our cybersecurity program, including monitoring, testing, and incident response activities. Our primary external cybersecurity service provider is based in the United States and operates a 24x7x365 security operations center.

We periodically assess and evaluate the effectiveness of our cybersecurity controls, policies, and processes, including compliance with applicable regulatory requirements and identification of potential risk areas and improvement opportunities. Findings from these assessments are used to inform enhancements to our cybersecurity program.

 

Incident Response

 

 Our cybersecurity program includes processes for monitoring, detecting, and responding to cybersecurity incidents. Potential incidents are evaluated and assigned severity levels, and an incident response team is engaged based on the nature and severity of the incident. Our incident response processes are designed to manage and mitigate cybersecurity risks and to support continuity of essential business operations in the event of a cybersecurity incident.

Cybersecurity incidents are reported internally to senior management and, when appropriate based on severity and incident type, to the Board of Directors. Incidents are also evaluated for potential external reporting obligations.

Third-Party Service Providers.

 

We engage third party service providers to expand the capabilities and capacity of our cybersecurity program, including for design, monitoring and testing of the program’s risk prevention and protection measures, and process execution including incident detection, investigation, analysis and response, eradication, and recovery. Our main external service provider is US-based and utilizes  a 24x7x365 Service Operation Center (SOC).

 

Program Assessment.

 

We regularly evaluate and seek to improve and mature our cybersecurity processes. Our cybersecurity program is regularly assessed through management self-evaluation and ongoing monitoring procedures to evaluate our program effectiveness, including assessments associated with internal controls over financial reporting as well as vulnerability management through active discovery and testing to validate patching and configuration. As cybersecurity threats are continuously evolving, we also periodically engage with third parties to perform maturity assessments of our program to identify potential risk areas and improvement opportunities. This includes assessment of our overall program, policies and processes, compliance with regulatory requirements and an overall assessment of key vulnerabilities. We use these assessments to supplement our own evaluation of the overall health of our program and target improvement areas.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

Our products and services are normally classified as EAR 99 (items not designated under the control) by the U.S. government, but our defense customers may ask us to make some alterations for the environments in which the products will be used. Moreover, our products sold for defense applications are integrated with our customers’ products. Given the nature of our business and the cybersecurity risks we face, we have instituted a cybersecurity program for identifying, assessing, and managing cybersecurity risks, which include material risks from cybersecurity threats to our internal systems, our products, services and programs for customers, and our supply chain.

 

Our enterprise cybersecurity program has been designed to align, as much as reasonably possible, with the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) standards, among others. The program includes processes and controls for the deployment of new IT systems by the Company and controls over new and existing system operations. We, or third parties we contract with, monitor and conduct regular testing of these controls and systems, including vulnerability management through active discovery and testing to regularly assess patching and configuration status. In addition, we require our employees to complete annual cybersecurity training, and we regularly conduct simulated phishing and cyber-related communications.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true