XML 44 R28.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Information technology is important to our business operations, and we are committed to protecting the privacy, security and integrity of the data we use in our business, as well as our employee and clinical data. The Company has a comprehensive cybersecurity program in place for assessing, identifying and managing cybersecurity risks that is designed to protect its systems and data from unauthorized access, use or other security impact. This program is integrated into the Company’s overall Enterprise Risk Management and Resiliency process.

We continuously monitor and update our information technology networks and infrastructure to prevent, detect, address and mitigate risks associated with unauthorized access, misuse, computer viruses and other events that could have a security impact. We invest in industry standard security technology to protect the Company’s data and business processes against risk of cybersecurity incidents. Our data security management program includes identity, trust, vulnerability and threat management business processes, as well as adoption of standard data protection policies.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company has a comprehensive cybersecurity program in place for assessing, identifying and managing cybersecurity risks that is designed to protect its systems and data from unauthorized access, use or other security impact. This program is integrated into the Company’s overall Enterprise Risk Management and Resiliency process.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Board Oversight:

Cybersecurity risks fall within the purview of the Audit Committee and, ultimately, the Board of Directors. Regular oversight and reviews occur at established intervals. The Audit Committee engages in discussions with the CEO and Company management at least once a year, covering various aspects of cybersecurity risk management, including recent developments, evolving standards, vulnerability assessments, and the threat environment.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Audit Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
Cybersecurity risks fall within the purview of the Audit Committee and, ultimately, the Board of Directors. Regular oversight and reviews occur at established intervals. The Audit Committee engages in discussions with the CEO and Company management at least once a year, covering various aspects of cybersecurity risk management, including recent developments, evolving standards, vulnerability assessments, and the threat environment.
Cybersecurity Risk Role of Management [Text Block]

In terms of governance and oversight, the following is in place to enhance transparency and accountability in cybersecurity management:

Responsibility Assignment:

The Company’s Chief Executive Officer (CEO) assumes a pivotal role in overseeing the cybersecurity risk management program. The CEO collaborates with business leaders on the matters of cybersecurity across the Company.

Board Oversight:

Cybersecurity risks fall within the purview of the Audit Committee and, ultimately, the Board of Directors. Regular oversight and reviews occur at established intervals. The Audit Committee engages in discussions with the CEO and Company management at least once a year, covering various aspects of cybersecurity risk management, including recent developments, evolving standards, vulnerability assessments, and the threat environment.

We measure our data security effectiveness by benchmarking against industry-accepted methods and we work to remediate any significant findings. We maintain and routinely test backup systems and disaster recovery and also have processes in place to prevent disruptions resulting from our implementation of new software and systems.

We have a comprehensive incident response plan to address cybersecurity incidents. Our incident response plan includes procedures for identifying, containing and responding to cybersecurity incidents and is subject to regular review and assessment to ensure that it is effective in protecting our information technology. To date, we believe that our cybersecurity program has been effective in protecting the confidentiality, integrity, and availability of its information; however, the Company cannot guarantee that its cybersecurity program will be successful in preventing all cybersecurity incidents. Further, we currently maintain a cyber insurance policy that provides coverage for security breaches; however, such insurance may not be sufficient in type or amount to cover us against claims related to security breaches, cyber-attacks and other related breaches.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Chief Executive Officer (CEO)
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee engages in discussions with the CEO and Company management at least once a year, covering various aspects of cybersecurity risk management, including recent developments, evolving standards, vulnerability assessments, and the threat environment.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true