v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk Management and Strategy 

The Company has adopted a cybersecurity risk management framework designed to identify, assess, and manage material risks arising from cybersecurity threats to its information systems, client data, and financial technology infrastructure. Key elements of our framework include:

 

  Threat identification and assessment. We conduct periodic assessments of our information systems to identify vulnerabilities, evaluate potential cybersecurity threats, and prioritize remediation efforts based on risk severity. These assessments incorporate threat intelligence from industry sources and regulatory guidance issued by the financial authorities that govern our subsidiaries, including the Malta Financial Services Authority (MFSA) and the UK Financial Conduct Authority (FCA).
     
  Technical safeguards. We employ a combination of industry-standard security technologies including network access controls, data encryption, multi-factor authentication, intrusion detection systems, and endpoint protection tools across our global operations.
     
  Incident response. We maintain written incident response procedures that establish protocols for detecting, containing, and remediating cybersecurity incidents, including escalation procedures to senior management and, where applicable, regulatory notification obligations.
     
  Employee training. We provide cybersecurity awareness training to employees and contractors with access to our information systems, with emphasis on phishing, social engineering, and data handling practices.
     
  Third-party risk management. We rely on certain third-party service providers for technology infrastructure, cloud computing, and payment processing. We assess the cybersecurity practices of material vendors as part of our onboarding and ongoing monitoring processes; however, we cannot guarantee that third parties will maintain adequate safeguards at all times.
     
  Integration with enterprise risk management. Cybersecurity risk is considered as part of the Company’s overall enterprise risk management process. Material cybersecurity risks are reported to senior management and escalated to the Board of Directors as warranted.

 

 

The Company’s regulated subsidiaries are subject to cybersecurity and data protection requirements under applicable financial services regulations, including requirements imposed by the MFSA, FCA, and ASIC. Compliance with these frameworks is reviewed as part of each subsidiary’s ongoing regulatory supervision.

 

At December 31, 2025, we are not aware of any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business, results of operations, or financial condition. We recognize, however, that the threat landscape is continuously evolving, and there can be no assurance that our controls will prevent all future incidents. See “Item 1A — Risk Factors” for a discussion of cybersecurity-related risks.

 

Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Board of Directors Oversight [Text Block] responsibility for cybersecurity risk management rests with the Company’s Chief Executive Officer, Mitchell M. Eaglstein, who also serves as the Company’s principal technology and operations executive and Chief Financial Officer, Imran Firoz, who serves as the Company’s principal finance and controller executive. Mr. Eaglstein and Mr. Firoz have over 20 years of experience each in financial technology and SEC-reporting companies, with extensive involvement in information systems, regulatory compliance, and operational risk management.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Governance 

Board Oversight. The Board of Directors is responsible for overseeing the Company’s cybersecurity risk management. Senior management provides the Board with periodic updates on the cybersecurity threat environment, the status of the Company’s security posture, significant vulnerabilities or incidents, regulatory developments, and the effectiveness of remediation efforts. The Board reviews and approves the Company’s overall risk management framework, within which cybersecurity risk is addressed, and engages with management on cybersecurity matters as circumstances warrant.

 

Management’s Role. Primary responsibility for cybersecurity risk management rests with the Company’s Chief Executive Officer, Mitchell M. Eaglstein, who also serves as the Company’s principal technology and operations executive and Chief Financial Officer, Imran Firoz, who serves as the Company’s principal finance and controller executive. Mr. Eaglstein and Mr. Firoz have over 20 years of experience each in financial technology and SEC-reporting companies, with extensive involvement in information systems, regulatory compliance, and operational risk management. Day-to-day cybersecurity activities are coordinated by our technology team across our operating subsidiaries, with support from external IT security consultants where specialized expertise is required. Management reports cybersecurity matters to the Board through regular updates and, for potentially material incidents, through immediate escalation.

 

Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Board of Directors is responsible for overseeing the Company’s cybersecurity risk management. Senior management provides the Board with periodic updates on the cybersecurity threat environment, the status of the Company’s security posture, significant vulnerabilities or incidents, regulatory developments, and the effectiveness of remediation efforts.