XML 29 R7.htm IDEA: XBRL DOCUMENT v3.25.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Cybersecurity Risk management and strategy

Our cybersecurity risk management process guides us in making cybersecurity risk-informed decisions and provides the basis for evaluating and monitoring the cybersecurity risk profile of the Company. This process provides a shared understanding and promotes a consistent approach to cybersecurity risk management within the Company in line with our information security policy and includes a cybersecurity incident response plan.

 

As part of our cybersecurity risk management program, we review industry best practices, including the NIST (National Institute of Standards and Technology) Cybersecurity Framework and ISO (International Organization for Standardization) 27001 to manage information security. We periodically conduct ongoing internal and external vulnerability analyses, including simulated attack as well as external testing via a third-party to evaluate the effectiveness of our cybersecurity process and controls.

 

In an effort to minimize third-party risk, we have established a process to assess the security practices of third-party vendors and service providers and related risks. Our process includes a security assessment informed by vendor questionnaires and contractual security requirements related to data privacy for certain vendors.

 

The SOC is responsible for investigating all security incidents and alerts including determining the threat type, incident scope and incident severity. Where appropriate, major incidents are escalated according to cybersecurity incident process.

 

Employee awareness and training are essential to our ability as a company to thwart cyber-attacks. We continuously raise employees’ risk awareness with mandatory, regular online training for all employees and complimentary awareness campaigns.

 

In 2024, we did not identify any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition. Despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurance that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see Item 3. Key Information – D. Risk Factors.

 
Cybersecurity Risk Management Processes Integrated [Flag] false
Cybersecurity Risk Management Processes Integrated [Text Block] Our cybersecurity risk management process guides us in making cybersecurity risk-informed decisions and provides the basis for evaluating and monitoring the cybersecurity risk profile of the Company. This process provides a shared understanding and promotes a consistent approach to cybersecurity risk management within the Company in line with our information security policy and includes a cybersecurity incident response plan.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Board of Directors Oversight [Text Block] Our board of directors has overall oversight responsibility for our risk management strategy, and delegates information security and related risk management oversight to the Audit Committee
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Cybersecurity Governance

 

Our board of directors has overall oversight responsibility for our risk management strategy, and delegates information security and related risk management oversight to the Audit Committee. Members of the audit committee receive regular updates from management, regarding cybersecurity related matters. This includes existing and new cybersecurity risks, how management is addressing, managing and/or mitigating those risks, cybersecurity and data privacy incidents (if relevant), and the status of key information security initiatives.

 

Our management and our cybersecurity and risks council overseas regular review of cybersecurity risk management activities, is responsible for the management of our cyber risk exposure and monitoring the effectiveness of the cybersecurity program, including but not limited to, our cybersecurity tools and controls, and is responsible for establishing and reviewing our risk tolerance for our cyber risk framework.

 

The cybersecurity and risks council includes the CEO, and the CTO, and cybersecurity specialists. Those employees have decades of experience in cybersecurity and operations, cybersecurity education, and certifications from various organizations.

 
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true