|
Cybersecurity Risk Management, Strategy, and Governance Disclosure
|12 Months Ended
Sep. 30, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
We have implemented an information security program to assess, identify, and manage material risks from cybersecurity threats. This program includes policies and procedures that guide the development, implementation, and maintenance of security measures and controls. We utilize industry-standard metrics to evaluate the criticality of software, data assets, and operational technology. We believe that our cybersecurity efforts align with the Center for Internet Security (CIS) Controls and the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and we conduct annual assessments to ensure compliance.
Given our reliance on third-party software, service providers, and applications to support various business functions and security measures, we regularly conduct security audits and vendor management reviews. These processes are intended to ensure that third-party systems and services comply with our cybersecurity program.
Periodic cyber risk assessments of our operational technology network help us identify risks, which we address using risk-based analysis and judgment. We also conduct internal and external testing of software, hardware, and defensive systems in our efforts to uncover potential vulnerabilities. Third-party security firms are employed for certain controls and technology operations, including vulnerability scans and penetration testing. Our approach to managing third-party cybersecurity threats includes pre-acquisition due diligence, contractual obligations, and ongoing performance monitoring.
We employ governance, risk, and compliance (GRC) information technology tools to manage cybersecurity risks and maintain business continuity and disaster recovery plans to prepare for potential disruptions. Our employees receive cybersecurity awareness training upon hiring, with additional training provided on a regular basis.
Governance
The Vice President of Information Technology (IT) and the Director of IT Security are responsible for overseeing our cybersecurity risk management program and assessing cybersecurity risks. This includes managing internal cybersecurity staff, consulting with external cybersecurity experts, and staying informed through governmental and private sources. They report regularly to executive management on cybersecurity threats, resources, and program updates.
Cybersecurity risk management and strategy are integrated into our overall risk management processes. The program monitors the prevention, detection, assessment, mitigation, and remediation of cybersecurity risks and incidents. The Vice President of IT presents updates on IT projects, including cybersecurity policies and programs, to executive management at least quarterly.
The Board of Directors has overall oversight of key risks, with strategic oversight of cybersecurity risk management delegated to the Audit Committee. Annually, the Audit Committee reviews the Company’s enterprise risk management, which includes cybersecurity. In fiscal year 2024, the Audit Committee established an IT Audit Subcommittee to enhance focus on IT-related internal controls and cybersecurity. The Board and Audit Committee have appointed one of the members of the Audit Committee to sit on the IT Subcommittee. This subcommittee
meets quarterly with key company leaders to review cybersecurity risks and audit findings and reports regularly to the Audit Committee.
Impacts from Cybersecurity Threats
Although we have experienced cybersecurity incidents, we do not believe they have, or are likely to have, a material impact on the business. However, we recognize that cybersecurity threats are constantly evolving, and future incidents remain a possibility. Despite our security measures and IT controls, we cannot guarantee that future cybersecurity incidents will be prevented. A successful attack could have significant consequences for the business. For more information on the risks associated with cybersecurity threats, see Item 1A, Risk Factors - "Risk Related to Information Technology and Cybersecurity."
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Cybersecurity risk management and strategy are integrated into our overall risk management processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance
The Vice President of Information Technology (IT) and the Director of IT Security are responsible for overseeing our cybersecurity risk management program and assessing cybersecurity risks. This includes managing internal cybersecurity staff, consulting with external cybersecurity experts, and staying informed through governmental and private sources. They report regularly to executive management on cybersecurity threats, resources, and program updates.
Cybersecurity risk management and strategy are integrated into our overall risk management processes. The program monitors the prevention, detection, assessment, mitigation, and remediation of cybersecurity risks and incidents. The Vice President of IT presents updates on IT projects, including cybersecurity policies and programs, to executive management at least quarterly.
The Board of Directors has overall oversight of key risks, with strategic oversight of cybersecurity risk management delegated to the Audit Committee. Annually, the Audit Committee reviews the Company’s enterprise risk management, which includes cybersecurity. In fiscal year 2024, the Audit Committee established an IT Audit Subcommittee to enhance focus on IT-related internal controls and cybersecurity. The Board and Audit Committee have appointed one of the members of the Audit Committee to sit on the IT Subcommittee. This subcommittee
meets quarterly with key company leaders to review cybersecurity risks and audit findings and reports regularly to the Audit Committee.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board of Directors has overall oversight of key risks, with strategic oversight of cybersecurity risk management delegated to the Audit Committee. Annually, the Audit Committee reviews the Company’s enterprise risk management, which includes cybersecurity. In fiscal year 2024, the Audit Committee established an IT Audit Subcommittee to enhance focus on IT-related internal controls and cybersecurity. The Board and Audit Committee have appointed one of the members of the Audit Committee to sit on the IT Subcommittee.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board and Audit Committee have appointed one of the members of the Audit Committee to sit on the IT Subcommittee. This subcommittee
meets quarterly with key company leaders to review cybersecurity risks and audit findings and reports regularly to the Audit Committee.
|Cybersecurity Risk Role of Management [Text Block]
|
Risk Management and Strategy
We have implemented an information security program to assess, identify, and manage material risks from cybersecurity threats. This program includes policies and procedures that guide the development, implementation, and maintenance of security measures and controls. We utilize industry-standard metrics to evaluate the criticality of software, data assets, and operational technology. We believe that our cybersecurity efforts align with the Center for Internet Security (CIS) Controls and the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and we conduct annual assessments to ensure compliance.
Given our reliance on third-party software, service providers, and applications to support various business functions and security measures, we regularly conduct security audits and vendor management reviews. These processes are intended to ensure that third-party systems and services comply with our cybersecurity program.
Periodic cyber risk assessments of our operational technology network help us identify risks, which we address using risk-based analysis and judgment. We also conduct internal and external testing of software, hardware, and defensive systems in our efforts to uncover potential vulnerabilities. Third-party security firms are employed for certain controls and technology operations, including vulnerability scans and penetration testing. Our approach to managing third-party cybersecurity threats includes pre-acquisition due diligence, contractual obligations, and ongoing performance monitoring.
We employ governance, risk, and compliance (GRC) information technology tools to manage cybersecurity risks and maintain business continuity and disaster recovery plans to prepare for potential disruptions. Our employees receive cybersecurity awareness training upon hiring, with additional training provided on a regular basis.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
The Vice President of Information Technology (IT) and the Director of IT Security are responsible for overseeing our cybersecurity risk management program and assessing cybersecurity risks. This includes managing internal cybersecurity staff, consulting with external cybersecurity experts, and staying informed through governmental and private sources. They report regularly to executive management on cybersecurity threats, resources, and program updates.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Board of Directors has overall oversight of key risks, with strategic oversight of cybersecurity risk management delegated to the Audit Committee. Annually, the Audit Committee reviews the Company’s enterprise risk management, which includes cybersecurity. In fiscal year 2024, the Audit Committee established an IT Audit Subcommittee to enhance focus on IT-related internal controls and cybersecurity. The Board and Audit Committee have appointed one of the members of the Audit Committee to sit on the IT Subcommittee. This subcommittee
meets quarterly with key company leaders to review cybersecurity risks and audit findings and reports regularly to the Audit Committee.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef