XML 43 R10.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk Management 

We understand the importance of preventing, assessing, identifying, and managing material risks associated with cybersecurity threats. Processes to manage risks from cybersecurity threats have been incorporated as a part of our overall risk assessment process. Our cybersecurity risks include theft of business data, fraud or extortion, lack of access to our information systems, harm to employees, harm to business partners, violation of privacy laws, potential reputational damage, and litigation or other legal risk if a cybersecurity incident were to occur. It is difficult to assign a monetary materiality assessment to these risks or to the impact if we were to sustain a breach of our systems. Our approach is based on the premise that any cybersecurity incident could result in material harm to our company.

 

Threats to security, confidentiality, and availability are identified and assessed as part of our annual and routine risk assessments. Our annual risk assessment is performed by using the ISO27001 risk assessment as a basis for risk identification, which is conducted by a trusted third-party provider to test our enterprise and product security controls. Additionally, our employees go through cybersecurity awareness training as part of their onboarding procedures. We also try to stay ahead of emerging cyber threats by continuously updating our security measures and investing in the latest technologies. We believe this proactive approach will help us be prepared to defend against new types of attacks, keeping our customers’ data secure.

 

Matters determined to present potential material impacts to our financial results, operations, and/or reputation would immediately be reported by our cybersecurity team and escalated, as appropriate. In relation to security incident levels P0 - P4, the following escalation framework will be evoked, as outlined in the table below:

 

 

We manage significant and persistent cybersecurity risks due to the need to protect our business, including our intellectual property and intellectual property of others that is licensed for our use, our confidential information and information concerning our personnel and others with whom we conduct business. As other technology companies we occasionally face threats from actors who seek to disrupt our business as well as others who are engaging in malicious activities or for reputation damage. Disclose of certain information as a result of a cybersecurity breach may result in a breach of privacy laws. The substantial level of harm that could occur to us and our suppliers and customers were we to suffer impacts of a material cybersecurity incident; and our use of third-party products, services and components requires us to maintain robust governance and oversight of these risks and to implement mechanisms, technologies and processes designed to help us assess, identify, and eliminate these risks.

 

While we have not, as of the date of this annual report, experienced a cybersecurity threat or incident that resulted in a material adverse impact to our business or operations, we cannot assure you that we will not experience such an incident in the future. We have seen an increase in cyberattack volume, frequency, and sophistication. We seek to detect and investigate unauthorized attempts and attacks against our network, products, and services, and to prevent their occurrence and recurrence where practicable through changes or updates to our internal processes and tools and changes or updates to our products and services; however, while diligently taking actions to eliminate and reduce cyber risks, we remain potentially vulnerable to known or unknown threats. In some instances, we, our suppliers, our customers, and the users of our products and services can be unaware of a threat or incident or its magnitude and effects. Further, there are increasing regulation requirements regarding responses to cybersecurity incidents, including reporting to regulators, which could subject us to additional liability and reputational harm.

 

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Threats to security, confidentiality, and availability are identified and assessed as part of our annual and routine risk assessments. Our annual risk assessment is performed by using the ISO27001 risk assessment as a basis for risk identification, which is conducted by a trusted third-party provider to test our enterprise and product security controls. Additionally, our employees go through cybersecurity awareness training as part of their onboarding procedures. We also try to stay ahead of emerging cyber threats by continuously updating our security measures and investing in the latest technologies. We believe this proactive approach will help us be prepared to defend against new types of attacks, keeping our customers’ data secure
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false