XML 55 R36.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy
Many of our business and operational processes are heavily dependent on traditional and emerging technology systems, some of which are managed by us and some of which are managed by third-party service and equipment providers. For instance, we use computerized systems to help run our financial and operational functions, including processing payment transactions, communicating with our employees and business partners, storing confidential records and conducting operations. Additionally, our brands maintain some of their own information systems, data and service providers and we may from time to time acquire companies with cybersecurity vulnerabilities and/or unsophisticated security measures. We also significantly rely on remote working arrangements by employees, vendors and other third parties. We recognize that all of these practices may subject our business to significant cybersecurity risks and potential threats.
As part of our cybersecurity risk management process, we have implemented security measures, internal controls and testing, systems redundancy and third-party products and services that are designed to detect and protect against cyberattacks. We conduct periodic penetration testing and security assessments to help identify material cybersecurity risks to our critical systems and information services and we regularly update and review such testing protocols. We conduct simulated cybersecurity incidents to ensure that we are prepared to respond to such incidents and to highlight any areas for potential improvement in our cyber incident preparedness. We have a cybersecurity incident management policy and response plan in place. We also implement periodic security awareness campaigns and simulated phishing trainings for all of our employees. We also maintain certain cyber liability insurance coverage that may be relied upon to address certain aspects of cybersecurity risks.
Cybersecurity breaches are evaluated by our Chief Information Officer and our Senior Director, Security & Governance who are members of our information technology team and report directly to our Chief People & Technology Executive Officer. If an incident is deemed to be a breach, it is communicated to our legal department and the rest of management for evaluation, including whether the breach requires communication to our audit committee (the "Audit Committee") or the Board or investors through a relevant public filing.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] As part of our cybersecurity risk management process, we have implemented security measures, internal controls and testing, systems redundancy and third-party products and services that are designed to detect and protect against cyberattacks.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Our risk management program is overseen by the Board, which has delegated the management of cybersecurity risks to its Audit Committee. The Audit Committee receives and assesses periodic reports and updates regarding our cybersecurity risk management from management and our Senior Director, Security & Governance and then relays them to the Board as needed.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
Our risk management program is overseen by the Board, which has delegated the management of cybersecurity risks to its Audit Committee. The Audit Committee receives and assesses periodic reports and updates regarding our cybersecurity risk management from management and our Senior Director, Security & Governance and then relays them to the Board as needed.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee receives and assesses periodic reports and updates regarding our cybersecurity risk management from management and our Senior Director, Security & Governance and then relays them to the Board as needed.
Cybersecurity Risk Role of Management [Text Block]
Governance
As a general matter, all cybersecurity risk management processes are integrated into our broader risk management program. Our cybersecurity risk management is the responsibility of our Chief Information Officer and our Senior Director, Security & Governance. Our Chief Information Officer has over 15 years of experience leading enterprise information technology management, integration and modernization. Our Senior Director, Security & Governance has over 20 years of industry experience in the field of information systems, including information security architecture and risk management . Their team oversees all risk assessment programs, remediation of known risks, processes for the regular monitoring of our information systems and our employee cybersecurity training programs. In addition, their team oversees enterprise-wide compliance with data privacy and data protection requirements and regulations.
Our risk management program is overseen by the Board, which has delegated the management of cybersecurity risks to its Audit Committee. The Audit Committee receives and assesses periodic reports and updates regarding our cybersecurity risk management from management and our Senior Director, Security & Governance and then relays them to the Board as needed.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our cybersecurity risk management is the responsibility of our Chief Information Officer and our Senior Director, Security & Governance. Our Chief Information Officer has over 15 years of experience leading enterprise information technology management, integration and modernization. Our Senior Director, Security & Governance has over 20 years of industry experience in the field of information systems, including information security architecture and risk management . Their team oversees all risk assessment programs, remediation of known risks, processes for the regular monitoring of our information systems and our employee cybersecurity training programs. In addition, their team oversees enterprise-wide compliance with data privacy and data protection requirements and regulations.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Information Officer has over 15 years of experience leading enterprise information technology management, integration and modernization. Our Senior Director, Security & Governance has over 20 years of industry experience in the field of information systems, including information security architecture and risk management .
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee receives and assesses periodic reports and updates regarding our cybersecurity risk management from management and our Senior Director, Security & Governance and then relays them to the Board as needed.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true