Cybersecurity Risk Management and Strategy Disclosure |
12 Months Ended | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Dec. 31, 2025 | |||||||||||||||||||
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |||||||||||||||||||
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] | Risk Management and Strategy We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats including risks relating to disruption of business operations or financial reporting systems, intellectual property theft; fraud; extortion; harm to employees or customers; violation of privacy laws and other litigation and legal risk; and reputational risk, as part of our overall risk management system and processes. Our cybersecurity risk management processes include the following:
We also engage third-party experts to evaluate the structure and test the effectiveness of our processes, as well as to provide ongoing training. Our cybersecurity risk management processes extend to the oversight and identification of cybersecurity risks associated with our use of third-party service providers. Our risk management program includes continuous monitoring, assessments, and compliance with industry best practices to mitigate potential vulnerabilities. We maintain technical support agreements with service providers that cover essential aspects such as software licensing, configuration, upgrades, and necessary changes, supplementing any internal training initiatives. In addition, have implemented a comprehensive Business Continuity Management Plan, developed in collaboration with a third-party service provider, and supported by both internal and external audits, in coordination with our legal team. Both our purchasing and IT departments regularly evaluate the competency and qualifications of third-party partners. These providers are required to demonstrate high levels of expertise and hold relevant technical certifications. Our business strategy, results of operations, and financial condition have not been materially affected by cybersecurity threats, including previous cybersecurity incidents. However, we cannot provide assurance that such risks, or any future material cybersecurity incidents, will not have a significant impact in the future. For instance, in 2021, one of our branch offices experienced a ransomware attack that targeted Microsoft Windows servers. Although this incident did not materially affect our operations, as the servers were quickly restored from backups and our ERP system remained functional throughout, it underscores the potential risks. The action plan involved isolating each affected server for a comprehensive inspection and cleanup, followed by the full replacement of our perimeter and endpoint security solutions before the servers were brought back online. While we successfully mitigated the immediate risk, this event illustrates the importance of continued vigilance, as future incidents may not be as contained or without impact. |
||||||||||||||||||
| Cybersecurity Risk Management Processes Integrated [Text Block] | We have implemented next-generation firewalls and integrated vulnerability testing with our antivirus solution to enhance overall system security | ||||||||||||||||||
| Cybersecurity Risk Management Processes Integrated [Flag] | true | ||||||||||||||||||
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true | ||||||||||||||||||
| Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] | Our cybersecurity
risk management processes extend to the oversight and identification of cybersecurity risks associated with our use of third-party service
providers. Our risk management program includes continuous monitoring, assessments, and compliance with industry best practices to mitigate
potential vulnerabilities. We maintain technical support agreements with service providers that cover essential aspects such as software licensing, configuration, upgrades, and necessary changes, supplementing any internal training initiatives. In addition, have implemented a comprehensive Business Continuity Management Plan, developed in collaboration with a third-party service provider, and supported by both internal and external audits, in coordination with our legal team. Both our purchasing and IT departments regularly evaluate the competency and qualifications of third-party partners. These providers are required to demonstrate high levels of expertise and hold relevant technical certifications. Our business strategy, results of operations, and financial condition have not been materially affected by cybersecurity threats, including previous cybersecurity incidents. However, we cannot provide assurance that such risks, or any future material cybersecurity incidents, will not have a significant impact in the future. For instance, in 2021, one of our branch offices experienced a ransomware attack that targeted Microsoft Windows servers. Although this incident did not materially affect our operations, as the servers were quickly restored from backups and our ERP system remained functional throughout, it underscores the potential risks. The action plan involved isolating each affected server for a comprehensive inspection and cleanup, followed by the full replacement of our perimeter and endpoint security solutions before the servers were brought back online. While we successfully mitigated the immediate risk, this event illustrates the importance of continued vigilance, as future incidents may not be as contained or without impact. Governance Board of Directors and Management The Board of Directors holds primary responsibility for overseeing risks related to cybersecurity threats. To fulfill this responsibility, as well as on material legal and legislative developments in this area. Additionally, Management keeps the board informed through updates on strategic key indicators, ongoing cybersecurity initiatives, and significant incidents, including their potential impact on the organization. |
||||||||||||||||||
| Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] | true | ||||||||||||||||||
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] | Our business strategy, results of operations, and financial condition have not been materially affected by cybersecurity threats, including previous cybersecurity incidents. However, we cannot provide assurance that such risks, or any future material cybersecurity incidents, will not have a significant impact in the future. |
||||||||||||||||||
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false | ||||||||||||||||||
| Cybersecurity Risk Board of Directors Oversight [Text Block] | Governance Board of Directors and Management The Board of Directors holds primary responsibility for overseeing risks related to cybersecurity threats. To fulfill this responsibility, as well as on material legal and legislative developments in this area. Additionally, Management keeps the board informed through updates on strategic key indicators, ongoing cybersecurity initiatives, and significant incidents, including their potential impact on the organization. Members of the board remain actively engaged and stay informed of the rapidly evolving cyber threat landscape to ensure the company is prepared to address emerging risks. Our IT Director, Humberto Alejandro Vazquez de Gyves, has 20 years of experience in information technology and cybersecurity, including participation in personal data protection committees, the formation of cybersecurity teams, the implementation of digital security and culture programs for employees, specialization in networks and computer security, computer security training, and the formation of CSIRT units. He is also certified in the COBIT 5 framework. His experience includes the implementation of perimeter security, endpoint security, and voice and data network security projects, as well as vulnerability analysis and remediation programs for networks and applications, including source code. He has experience implementing data centers, information encryption models, and backup and redundancy programs for physical and virtual on-premises environments, as well as cloud environments. He has also implemented BCP and DRP protocols. |
||||||||||||||||||
| Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] | The Board of Directors holds primary responsibility for overseeing risks related to cybersecurity threats | ||||||||||||||||||
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |