XML 65 R31.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The Company established a risk-based strategy informed by guiding principles from industry standard cybersecurity and risk management frameworks, such as those published by the National Institute of Standards and Technology. The Company's cybersecurity risk management framework is integrated with the Company's Enterprise Risk Management ("ERM") process that is subject to oversight by the Board. Cybersecurity risks are one of the key risks regularly evaluated, assessed and monitored as part of the Company's overall ERM process.
As part of its risk-based strategy, the Company maintains appropriate technical and organizational measures and regularly reviews the appropriateness of those controls based on changes to the technical or regulatory environment. The Company also regularly incorporates cybersecurity awareness training into employee communications, engagement and training activities. The Company participates in various information-sharing organizations to timely share and receive threat information, thereby improving the collective defense of the aviation, retail and hospitality and other critical infrastructure sectors. The Company regularly seeks opportunities to improve its capabilities, including through cybersecurity trainings and skill development programs for its CDR members.
The Company utilizes a variety of third parties in connection with its cybersecurity risk management. The Company also employs third-party cybersecurity companies to add capacity or expertise when necessary. Additionally, assessments of the Company's cybersecurity program are periodically conducted by independent third-party assessors.
The Company is subject to cybersecurity risks related to its business partners and third-party service providers, as further detailed under the heading "Increasing privacy, data security and cybersecurity obligations or a significant data breach may adversely affect the Company's business" included as part of the risk factor disclosures in Part I, Item 1A. of this report. To manage these risks, the Company considers the impact of third-party incidents as part of its cybersecurity incident response processes. The Company also conducts evaluations of key suppliers based on risk and seeks to incorporate appropriate security standards to manage the risk. The Company also regularly monitors the external cybersecurity posture of select third parties through various service providers.
Crucially, the Company and its suppliers strive to design and implement technical and organizational controls comprehensively, consistently and effectively as intended to protect the confidentiality, integrity or availability of systems and data. However, because the Company utilizes a risk-based strategy, based on professional judgment and analysis of the risks, it is possible that the Company may underappreciate or not recognize a specific risk. Moreover, even the best designed and implemented security controls may not eliminate the occurrence of cybersecurity incidents.
Cybersecurity Incident Management
The CDR organization uses a variety of prevention and detection tools and other resources to identify potential cybersecurity incidents. When a cybersecurity incident is identified, CDR's incident response team engages with the appropriate subject matter experts, the relevant management of impacted organization(s) and others to analyze, contain, eradicate, mitigate and recover from the incident as applicable. When appropriate, during the incident response process, the CISO, CDR leadership and the Company's Chief Legal Officer may be informed and consulted and if deemed necessary, incidents may be escalated for review by the Senior Leader Crisis Team, which consists of cross-functional leaders of the Company. The Company maintains a process in which a subgroup of the Company's Disclosure Council would make a recommendation regarding the materiality of a cybersecurity incident to the full Disclosure Council and subsequently to the Audit Committee. Additionally, the CDR organization has frequent operating rhythms to, among other things, review cybersecurity incidents and track the progress of cybersecurity initiatives.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The Company established a risk-based strategy informed by guiding principles from industry standard cybersecurity and risk management frameworks, such as those published by the National Institute of Standards and Technology. The Company's cybersecurity risk management framework is integrated with the Company's Enterprise Risk Management ("ERM") process that is subject to oversight by the Board. Cybersecurity risks are one of the key risks regularly evaluated, assessed and monitored as part of the Company's overall ERM process.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Company considers management of cybersecurity and digital risk as essential for enabling success. The Audit Committee (the "Audit Committee") of the Board provides oversight of the Company's risk assessment and risk management policies and strategies with respect to significant business risks, including cybersecurity and digital risk. On a regular basis, the Audit Committee reviews reports from the Company's Chief Information Security Officer ("CISO") or her representative(s) regarding the identification and management of cybersecurity risks, including when applicable, notable cybersecurity threats or incidents impacting the aviation sector and the Company; results of independent third-party assessments of the Company's cybersecurity program; key metrics, capabilities, resourcing and strategy regarding the Company's cybersecurity program; and updates related to cybersecurity regulatory developments.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee (the "Audit Committee") of the Board provides oversight of the Company's risk assessment and risk management policies and strategies with respect to significant business risks, including cybersecurity and digital risk.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] On a regular basis, the Audit Committee reviews reports from the Company's Chief Information Security Officer ("CISO") or her representative(s) regarding the identification and management of cybersecurity risks, including when applicable, notable cybersecurity threats or incidents impacting the aviation sector and the Company; results of independent third-party assessments of the Company's cybersecurity program; key metrics, capabilities, resourcing and strategy regarding the Company's cybersecurity program; and updates related to cybersecurity regulatory developments.
Cybersecurity Risk Role of Management [Text Block]
The Company considers management of cybersecurity and digital risk as essential for enabling success. The Audit Committee (the "Audit Committee") of the Board provides oversight of the Company's risk assessment and risk management policies and strategies with respect to significant business risks, including cybersecurity and digital risk. On a regular basis, the Audit Committee reviews reports from the Company's Chief Information Security Officer ("CISO") or her representative(s) regarding the identification and management of cybersecurity risks, including when applicable, notable cybersecurity threats or incidents impacting the aviation sector and the Company; results of independent third-party assessments of the Company's cybersecurity program; key metrics, capabilities, resourcing and strategy regarding the Company's cybersecurity program; and updates related to cybersecurity regulatory developments.
The CISO leads the Company's Cybersecurity and Digital Risk ("CDR") organization, which oversees the Company's approach to identifying and managing cybersecurity and digital risk. The Company's current CISO has extensive technology and risk management experience in critical infrastructure sectors and is qualified as a boardroom certified technology expert by the Digital Directors Network. She has served on the U.S. President's National Infrastructure Advisory Council, examining and providing recommendations related to cross-sector critical infrastructure security and resilience. She serves on the board of directors of the Internet Security Alliance, is currently a member of the Cybersecurity Council at Airlines for America (and has served as Chair) and is currently a member of the board of directors of the Aviation Information Sharing and Analysis Center (A-ISAC). The CDR organization includes teams focusing on cyber defense, identity & digital trust, secure product solutions & aircraft cybersecurity operations. The teams include individuals with a variety of cybersecurity expertise, including expertise in penetration testing; application cybersecurity; product cybersecurity; cloud cybersecurity; infrastructure cybersecurity; cybersecurity engineering and architecture; identity and access management; vulnerability and asset management; cybersecurity threat intelligence; cybersecurity regulatory compliance; digital fraud; digital trust; incident response; insider threat assessment; and aircraft cybersecurity.
The Company's senior leadership, including across the functions of the Company's safety, legal, government affairs, operations, aviation security, finance, communications and digital technology as well as others when appropriate, support CDR and contribute to the management of cybersecurity and digital risk by attending regular cybersecurity risk reviews and participating in cybersecurity exercises.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The CISO leads the Company's Cybersecurity and Digital Risk ("CDR") organization, which oversees the Company's approach to identifying and managing cybersecurity and digital risk.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Company's current CISO has extensive technology and risk management experience in critical infrastructure sectors and is qualified as a boardroom certified technology expert by the Digital Directors Network. She has served on the U.S. President's National Infrastructure Advisory Council, examining and providing recommendations related to cross-sector critical infrastructure security and resilience. She serves on the board of directors of the Internet Security Alliance, is currently a member of the Cybersecurity Council at Airlines for America (and has served as Chair) and is currently a member of the board of directors of the Aviation Information Sharing and Analysis Center (A-ISAC).
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] On a regular basis, the Audit Committee reviews reports from the Company's Chief Information Security Officer ("CISO") or her representative(s) regarding the identification and management of cybersecurity risks, including when applicable, notable cybersecurity threats or incidents impacting the aviation sector and the Company; results of independent third-party assessments of the Company's cybersecurity program; key metrics, capabilities, resourcing and strategy regarding the Company's cybersecurity program; and updates related to cybersecurity regulatory developments.
The CISO leads the Company's Cybersecurity and Digital Risk ("CDR") organization, which oversees the Company's approach to identifying and managing cybersecurity and digital risk. The Company's current CISO has extensive technology and risk management experience in critical infrastructure sectors and is qualified as a boardroom certified technology expert by the Digital Directors Network. She has served on the U.S. President's National Infrastructure Advisory Council, examining and providing recommendations related to cross-sector critical infrastructure security and resilience. She serves on the board of directors of the Internet Security Alliance, is currently a member of the Cybersecurity Council at Airlines for America (and has served as Chair) and is currently a member of the board of directors of the Aviation Information Sharing and Analysis Center (A-ISAC). The CDR organization includes teams focusing on cyber defense, identity & digital trust, secure product solutions & aircraft cybersecurity operations. The teams include individuals with a variety of cybersecurity expertise, including expertise in penetration testing; application cybersecurity; product cybersecurity; cloud cybersecurity; infrastructure cybersecurity; cybersecurity engineering and architecture; identity and access management; vulnerability and asset management; cybersecurity threat intelligence; cybersecurity regulatory compliance; digital fraud; digital trust; incident response; insider threat assessment; and aircraft cybersecurity.
The Company's senior leadership, including across the functions of the Company's safety, legal, government affairs, operations, aviation security, finance, communications and digital technology as well as others when appropriate, support CDR and contribute to the management of cybersecurity and digital risk by attending regular cybersecurity risk reviews and participating in cybersecurity exercises.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true