XML 139 R13.htm IDEA: XBRL DOCUMENT v3.25.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk Management and StrategyWe maintain a technology and cybersecurity program, which includes information security, as part of our overall risk management process with the aim that our information systems, including those of our suppliers and other third-parties, will be resilient, effective and capable of safeguarding against emerging risks and cybersecurity threats. We endeavor to assure our program is appropriately resourced and to attract and retain expert talent to execute it.

 

The program is based on the PRC Cybersecurity Law, aiming to comply with applicable laws and regulations. We use the PRC Cybersecurity Law as a guideline to help us identify, assess, and manage cybersecurity risks related to our business operations.

 

Under the PRC Cybersecurity Law, we have established preventive measures that are consistent with the national cybersecurity level. We fulfill our security obligations to protect our networks from interference, damage, or unauthorized access, and to prevent the leakage, theft, or alteration of network data. As part of our supplier risk management program, we conduct security assessments prior to engagement of high-risk suppliers and other third-party providers and have a monitoring program to evaluate ongoing compliance with our cybersecurity standards.

A key element of our technology and cybersecurity program strategy is fostering training and awareness. Our training and awareness program includes annual cybersecurity awareness training and role-based phishing tests for our employees and for third parties with access to our systems.

 

Our technology and cybersecurity program focuses on the defense, rapid detection and rapid remediation of cybersecurity threats and incidents. Our approach aims to deliver the control capabilities specified in the PRC Cybersecurity Law. Additionally, our program incorporates comprehensive cybersecurity policies and crisis response and management procedures, aimed at rapidly addressing, responding to, and effectively communicating about cybersecurity threats and incident.

 

Our cybersecurity crisis management program sets forth the items, procedures and actions we expect to address and follow in the event of a cybersecurity incident, including detection, response, mitigation and remediation. When a potential threat or incident is identified, our cyber security incident response team will assign a risk level classification and initiate the escalation and other steps called for by our plan. All incidents that are initially assessed by the cybersecurity incident response team as potentially high-risk are escalated promptly to our Chief Financial Officer, who will determine whether and what elements of our cybersecurity crisis response and management plan should be activated, including escalation to other senior management. Our Chief Financial Officer will inform our Board of Directors of cybersecurity incidents, as appropriate, considering a variety of factors, including financial, operational, legal or reputational impact.

 

Our program’s maturity and operational readiness are regularly evaluated by independent experts using the PRC Cybersecurity Law’s cybersecurity framework and penetration tests that are consistent with the national cybersecurity level. Our program, and the results of these independent evaluations and testing, are regularly reviewed by our senior management and members of our Board of Directors.

 

We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.

 
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] we have established preventive measures that are consistent with the national cybersecurity level. We fulfill our security obligations to protect our networks from interference, damage, or unauthorized access, and to prevent the leakage, theft, or alteration of network data.
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Risk Governance 

We are committed to appropriate cybersecurity governance and oversight.

 

Our Board of Directors has oversight of our strategic and business risk management, including cybersecurity risk management. Our Board of Directors is responsible for ensuring that management has processes in place designed to identify and evaluate cybersecurity risks to which we are exposed and to implement processes and programs to manage cybersecurity risks and mitigate cybersecurity incidents. Management is responsible for identifying, assessing, and managing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity policies and procedures, and providing regular reports to our Board of Directors.

 

For additional information on our cybersecurity risks, please see Item 1A “Risk Factors.”

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board of Directors has oversight of our strategic and business risk management, including cybersecurity risk management.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board of Directors is responsible for ensuring that management has processes in place designed to identify and evaluate cybersecurity risks to which we are exposed and to implement processes and programs to manage cybersecurity risks and mitigate cybersecurity incidents.
Cybersecurity Risk Role of Management [Text Block] Management is responsible for identifying, assessing, and managing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity policies and procedures, and providing regular reports to our Board of Directors.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true