XML 50 R33.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jan. 31, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The protection of Company data, including customer and employee information, remains fundamental to our strategy of serving as a trusted advisor throughout the customer and employee experience. Cybersecurity is integrated into the Company’s Enterprise Risk Management framework and is overseen by management and the Audit Committee of the Board of Directors.
In 2025, two key areas of focus were (i) identifying and mitigating cybersecurity risks associated with the September 2025 acquisition of the Foot Locker Business and (ii) responding to rapid developments in AI technologies. Following the acquisition, we commenced a staged integration of Foot Locker’s employee identity and access management service to facilitate secure collaboration between the two companies and align on a common identity security standard. During this transition period, other Foot Locker systems and controls continued to operate under their pre‑acquisition cybersecurity framework, which may differ from the Company’s established standards. We expect people, process, and technology integration activities for the cybersecurity function to continue throughout the transition period.
As part of integration planning, the Company temporarily operated under a dual‑CISO structure. The Company’s Chief Information Security Officer (“CISO”) and the Foot Locker CISO were jointly responsible for overseeing cybersecurity strategy and risk management during the period subsequent to the acquisition. These leaders coordinated closely to align policies, processes, and controls; ensure continuity of security oversight; and support the migration of Foot Locker systems into the Company’s cybersecurity framework. The Company’s CISO took over responsibilities in March 2026.
The Company’s Cybersecurity team works in close partnership with internal stakeholders to monitor current and emerging data security risks across the enterprise and with third parties. The Company implements and maintains industry‑accepted cybersecurity risk management and compliance frameworks and programming, including the NIST Cybersecurity Framework. Internal and third‑party risks are reviewed, monitored, and managed by the Cybersecurity and Privacy teams, and are subject to oversight by Internal Audit and various external assessors. The Company regularly engages third‑party experts to evaluate the effectiveness of its cybersecurity controls and programs. Additionally, the Company continues to invest in skilled personnel; recurring training; processes and procedures; insurance coverages; and numerous technologies designed to address current threats, emerging trends, and the evolving legal, regulatory, and risk landscape applicable to cybersecurity.
The Company has implemented a Cybersecurity Incident Response Plan (the “IR Plan”) and framework to appropriately detect, contain and respond to cybersecurity incidents. The IR Plan identifies protocols for incident classification, the use of third-party service providers where applicable, processes for notification and internal escalation of information to senior management and the Audit Committee, and processes for materiality review. The IR Plan is reviewed and updated, as necessary, under the leadership of the Company’s CISO. Additionally, the Company maintains processes to assess the risks associated with third parties that store, transmit, or process sensitive Company data.
As of the date of this Annual Report on Form 10-K, risks from cybersecurity threats, including the results of any previous cybersecurity incidents, have not materially affected the Company, its business strategy, results of operations or financial condition. While we have no knowledge of any material data security breaches to date, any compromise of our data security could result in a violation of applicable privacy and other laws or standards, significant legal and financial exposure beyond the scope or limits of our insurance coverage, interruption of our operations, increased operating costs associated with remediation, equipment acquisitions or disposal, added personnel, and a loss of confidence in our security measures, which could harm our business, athlete experience, reputation or investor confidence. See Item 1A. “Risk Factors” for more information on the Company’s cybersecurity-related risks.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The protection of Company data, including customer and employee information, remains fundamental to our strategy of serving as a trusted advisor throughout the customer and employee experience. Cybersecurity is integrated into the Company’s Enterprise Risk Management framework and is overseen by management and the Audit Committee of the Board of Directors.
In 2025, two key areas of focus were (i) identifying and mitigating cybersecurity risks associated with the September 2025 acquisition of the Foot Locker Business and (ii) responding to rapid developments in AI technologies. Following the acquisition, we commenced a staged integration of Foot Locker’s employee identity and access management service to facilitate secure collaboration between the two companies and align on a common identity security standard. During this transition period, other Foot Locker systems and controls continued to operate under their pre‑acquisition cybersecurity framework, which may differ from the Company’s established standards. We expect people, process, and technology integration activities for the cybersecurity function to continue throughout the transition period.
As part of integration planning, the Company temporarily operated under a dual‑CISO structure. The Company’s Chief Information Security Officer (“CISO”) and the Foot Locker CISO were jointly responsible for overseeing cybersecurity strategy and risk management during the period subsequent to the acquisition. These leaders coordinated closely to align policies, processes, and controls; ensure continuity of security oversight; and support the migration of Foot Locker systems into the Company’s cybersecurity framework. The Company’s CISO took over responsibilities in March 2026.
The Company’s Cybersecurity team works in close partnership with internal stakeholders to monitor current and emerging data security risks across the enterprise and with third parties. The Company implements and maintains industry‑accepted cybersecurity risk management and compliance frameworks and programming, including the NIST Cybersecurity Framework. Internal and third‑party risks are reviewed, monitored, and managed by the Cybersecurity and Privacy teams, and are subject to oversight by Internal Audit and various external assessors. The Company regularly engages third‑party experts to evaluate the effectiveness of its cybersecurity controls and programs. Additionally, the Company continues to invest in skilled personnel; recurring training; processes and procedures; insurance coverages; and numerous technologies designed to address current threats, emerging trends, and the evolving legal, regulatory, and risk landscape applicable to cybersecurity.
The Company has implemented a Cybersecurity Incident Response Plan (the “IR Plan”) and framework to appropriately detect, contain and respond to cybersecurity incidents. The IR Plan identifies protocols for incident classification, the use of third-party service providers where applicable, processes for notification and internal escalation of information to senior management and the Audit Committee, and processes for materiality review. The IR Plan is reviewed and updated, as necessary, under the leadership of the Company’s CISO. Additionally, the Company maintains processes to assess the risks associated with third parties that store, transmit, or process sensitive Company data.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Governance
The Audit Committee oversees the Company’s cybersecurity risk management program, reflecting the Company‑wide priority placed on protecting customer and employee data. During the transition period following the Foot Locker acquisition, the Company’s cybersecurity risk management function was jointly led by the Company’s CISO—an industry leader with over 30 years of experience who joined the Company in January 2025—and the former Foot Locker CISO through March 2026.
The Company’s CISO reports to the Chief Technology Officer, who reports directly to the Chief Executive Officer. The CISO provides quarterly, and more frequent as necessary, updates to the Audit Committee and periodic briefings to the full Board regarding existing and emerging cybersecurity risks, as well as management’s mitigation activities. Together with the broader cybersecurity team, the CISO is responsible for overseeing the Company’s capabilities to protect against, detect, contain, and respond to cybersecurity threats in accordance with the IR Plan.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Audit Committee oversees the Company’s cybersecurity risk management program, reflecting the Company‑wide priority placed on protecting customer and employee data. During the transition period following the Foot Locker acquisition, the Company’s cybersecurity risk management function was jointly led by the Company’s CISO—an industry leader with over 30 years of experience who joined the Company in January 2025—and the former Foot Locker CISO through March 2026.
The Company’s CISO reports to the Chief Technology Officer, who reports directly to the Chief Executive Officer. The CISO provides quarterly, and more frequent as necessary, updates to the Audit Committee and periodic briefings to the full Board regarding existing and emerging cybersecurity risks, as well as management’s mitigation activities. Together with the broader cybersecurity team, the CISO is responsible for overseeing the Company’s capabilities to protect against, detect, contain, and respond to cybersecurity threats in accordance with the IR Plan.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Company has implemented a Cybersecurity Incident Response Plan (the “IR Plan”) and framework to appropriately detect, contain and respond to cybersecurity incidents. The IR Plan identifies protocols for incident classification, the use of third-party service providers where applicable, processes for notification and internal escalation of information to senior management and the Audit Committee, and processes for materiality review. The IR Plan is reviewed and updated, as necessary, under the leadership of the Company’s CISO. Additionally, the Company maintains processes to assess the risks associated with third parties that store, transmit, or process sensitive Company data.
Cybersecurity Risk Role of Management [Text Block] The Company’s Cybersecurity team works in close partnership with internal stakeholders to monitor current and emerging data security risks across the enterprise and with third parties. The Company implements and maintains industry‑accepted cybersecurity risk management and compliance frameworks and programming, including the NIST Cybersecurity Framework.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Company’s CISO reports to the Chief Technology Officer, who reports directly to the Chief Executive Officer.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] the Company’s CISO—an industry leader with over 30 years of experience who joined the Company in January 2025—and the former Foot Locker CISO through March 2026.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The Company’s CISO reports to the Chief Technology Officer, who reports directly to the Chief Executive Officer. The CISO provides quarterly, and more frequent as necessary, updates to the Audit Committee and periodic briefings to the full Board regarding existing and emerging cybersecurity risks, as well as management’s mitigation activities. Together with the broader cybersecurity team, the CISO is responsible for overseeing the Company’s capabilities to protect against, detect, contain, and respond to cybersecurity threats in accordance with the IR Plan.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true