XML 43 R27.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 26, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
As part of our cybersecurity process, we engage external auditors and consultants to assess our cybersecurity program and compliance with applicable practices and standards. To identify and manage the material risks of cybersecurity threats to our business, operations and control environments, we have made significant investments in our technology and have implemented policies, programs and controls, with a focus on cybersecurity incident prevention and mitigation. Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. Cybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed by third-party auditors and consultants, as well as our internal Information Technology and Legal teams, to ensure compliance with applicable practices and standards.

We mitigate risks from cybersecurity incidents using a multi-faceted approach that includes, but is not limited to: establishing information security policies and standards, implementing information protection processes and technologies, assessing cybersecurity risk through vulnerability assessments and audits on an annual basis, reviewing newly developed cybersecurity standards or legislation, implementing cybersecurity training, real-time monitoring our information technology systems for cybersecurity threats through a 7x24 security operations center and collaborating with public and private organizations on best practices.

We did not experience a material cybersecurity incident during the fiscal year ended December 26, 2025. For more information on risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, see “Information technology system failures, cybersecurity incidents or other disruptions to our use of technology and networks could interrupt our operations and adversely affect our business” included as part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. Cybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed by third-party auditors and consultants, as well as our internal Information Technology and Legal teams, to ensure compliance with applicable practices and standards.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Cybersecurity is an important part of our risk management processes and an area of focus for our Board and management. Our board of directors is engaged in overseeing and reviewing the Company’s strategic direction and objectives, including the Company’s risk profile and exposures as they relate to cybersecurity, conducting reviews of policies regarding risk assessment and risk management and major risk exposures, as well as evaluations of risks from potential or actual cybersecurity threats. Our chief information officer, vice president of enterprise infrastructure, senior manager of information technology risk management, and security administrator have responsibility of cybersecurity oversight of the Company and each have 15, 18, 10, and 9 years of cybersecurity experience, respectively. The security administrator reports to the vice president of enterprise infrastructure, who in turn reports to the chief information officer. Members of the board receive regular quarterly cybersecurity updates from our chief information officer, including updates on existing and new cybersecurity risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our board of directors is engaged in overseeing and reviewing the Company’s strategic direction and objectives, including the Company’s risk profile and exposures as they relate to cybersecurity, conducting reviews of policies regarding risk assessment and risk management and major risk exposures, as well as evaluations of risks from potential or actual cybersecurity threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Members of the board receive regular quarterly cybersecurity updates from our chief information officer, including updates on existing and new cybersecurity risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives.
Cybersecurity Risk Role of Management [Text Block]
Cybersecurity is an important part of our risk management processes and an area of focus for our Board and management. Our board of directors is engaged in overseeing and reviewing the Company’s strategic direction and objectives, including the Company’s risk profile and exposures as they relate to cybersecurity, conducting reviews of policies regarding risk assessment and risk management and major risk exposures, as well as evaluations of risks from potential or actual cybersecurity threats. Our chief information officer, vice president of enterprise infrastructure, senior manager of information technology risk management, and security administrator have responsibility of cybersecurity oversight of the Company and each have 15, 18, 10, and 9 years of cybersecurity experience, respectively. The security administrator reports to the vice president of enterprise infrastructure, who in turn reports to the chief information officer. Members of the board receive regular quarterly cybersecurity updates from our chief information officer, including updates on existing and new cybersecurity risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Cybersecurity is an important part of our risk management processes and an area of focus for our Board and management. Our board of directors is engaged in overseeing and reviewing the Company’s strategic direction and objectives, including the Company’s risk profile and exposures as they relate to cybersecurity, conducting reviews of policies regarding risk assessment and risk management and major risk exposures, as well as evaluations of risks from potential or actual cybersecurity threats. Our chief information officer, vice president of enterprise infrastructure, senior manager of information technology risk management, and security administrator have responsibility of cybersecurity oversight of the Company and each have 15, 18, 10, and 9 years of cybersecurity experience, respectively. The security administrator reports to the vice president of enterprise infrastructure, who in turn reports to the chief information officer. Members of the board receive regular quarterly cybersecurity updates from our chief information officer, including updates on existing and new cybersecurity risks, cybersecurity and data privacy incidents (if any) and status on key information security initiatives.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our chief information officer, vice president of enterprise infrastructure, senior manager of information technology risk management, and security administrator have responsibility of cybersecurity oversight of the Company and each have 15, 18, 10, and 9 years of cybersecurity experience, respectively.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The security administrator reports to the vice president of enterprise infrastructure, who in turn reports to the chief information officer.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true