XML 51 R32.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk Assessment and Management. The Company’s cybersecurity risk management program is based on industry standard information security principles and best practices, specifically the NIST Cybersecurity Framework and the Payment Card Industry Data Security Standard ("PCI DSS"). The program encompasses all Company directly-managed brands, entities, and internal organizations other than its publicly-traded trivago subsidiary, which has its own standalone cybersecurity risk management program, and uses a proactive approach to regularly identify and assess cybersecurity threats, vulnerabilities and risks, and to evaluate the effectiveness of implemented security controls through internal audits, external threat intelligence, and periodic external independent assessments. Risks identified and assessed through the cybersecurity risk management program are then communicated to the Company’s senior leadership team and used to prioritize risks based on their potential impact and likelihood as part of the Company’s dynamic risk response strategy.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company’s Board of Directors (the “Board”) recognizes that safeguarding the Company’s data, information systems, and technology assets is critical to maintaining the trust and confidence of the Company’s travelers, business partners and employees. The Board actively exercises oversight of the Company’s technological infrastructure, information security and its cybersecurity, which are key components of the Company’s risk management program. The Company’s cybersecurity policies, standards, processes and programs are integrated into its risk management program and are based on industry standard frameworks established by the National Institute of Standards and Technology ("NIST") and the International Organization for Standardization, among others, as well as on evolving best practices.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board, in coordination with the Audit Committee, oversees the Company’s risk management program, which includes risks arising from cybersecurity threats. The Audit Committee regularly receives presentations and reports from both Company management and third-parties, as appropriate, that address a wide range of topics related to cybersecurity risks, including evolving standards, third-party and independent reviews, threat environment updates, technology trends and information security considerations arising with respect to the Company’s peers and partners. The Company’s CSO and/or the Company’s CTO regularly meet with the Audit Committee (and, where appropriate, the full Board) to discuss technology, information security and cybersecurity programs, progress updates on the Company's key cybersecurity initiatives and related priorities and controls. At least annually, the Audit Committee and the full Board receive a comprehensive written report covering the Company's cybersecurity program and associated risks, and any changes made to the program since the previous report. Additionally, the Audit Committee is promptly apprised of any cybersecurity incident that meets established reporting thresholds, and receives ongoing updates regarding any such incident until it has been resolved. At each regularly scheduled Board meeting, the Audit Committee Chair provides the full Board with an update on all significant matters discussed, reviewed, considered and approved by the committee since the last regularly scheduled Board meeting.
The Company’s CSO, in coordination with the Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”), CTO, and Chief Legal Officer (“CLO”), works collaboratively across the Company to implement and monitor a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s cybersecurity incident response plan and its security policy. To facilitate the success of the Company’s cybersecurity risk management program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, the CSO, the CTO and other executive leadership team members are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report risks from cybersecurity threats and cybersecurity incidents to the Audit Committee when appropriate.
The Company’s prior Chief Security Officer departed in late 2024 and the CSO function is currently overseen by two co-CSOs on an interim basis until a permanent successor is appointed. Each of the co-CSOs has over 30 years of relevant experience in a variety of sectors, including travel, fintech, and e-commerce. One co-CSO has held Chief Information Security Officer, Chief Information Officer and Chief Security Officer roles at multiple multinational public companies, leading enterprise-wide cybersecurity strategies and risk management programs; he holds a Master's degree in Security and Risk Management. The other co-CSO has served as Chief Technology Officer and Chief Information Officer at several multinational public companies, where he has driven digital transformation initiatives, technology modernization efforts, and secure platform development; he holds a Bachelor's degree in Computer Information Systems. The Company’s CTO has over 20 years of experience, including leading global technology teams focused on developing secure, large-scale platforms, implementing advanced data security measures, and mitigating risks across complex technological ecosystems. He holds a Bachelor’s degree in Technology and a Master’s degree in Technology. The Company’s CEO, CFO and CLO each hold undergraduate and graduate degrees in their respective fields, and each have extensive experience managing risks at the Company and at similar companies, including risks arising from cybersecurity threats.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board, in coordination with the Audit Committee, oversees the Company’s risk management program, which includes risks arising from cybersecurity threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee regularly receives presentations and reports from both Company management and third-parties, as appropriate, that address a wide range of topics related to cybersecurity risks, including evolving standards, third-party and independent reviews, threat environment updates, technology trends and information security considerations arising with respect to the Company’s peers and partners. The Company’s CSO and/or the Company’s CTO regularly meet with the Audit Committee (and, where appropriate, the full Board) to discuss technology, information security and cybersecurity programs, progress updates on the Company's key cybersecurity initiatives and related priorities and controls. At least annually, the Audit Committee and the full Board receive a comprehensive written report covering the Company's cybersecurity program and associated risks, and any changes made to the program since the previous report. Additionally, the Audit Committee is promptly apprised of any cybersecurity incident that meets established reporting thresholds, and receives ongoing updates regarding any such incident until it has been resolved. At each regularly scheduled Board meeting, the Audit Committee Chair provides the full Board with an update on all significant matters discussed, reviewed, considered and approved by the committee since the last regularly scheduled Board meeting.
Cybersecurity Risk Role of Management [Text Block] The Company’s CSO, in coordination with the Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”), CTO, and Chief Legal Officer (“CLO”), works collaboratively across the Company to implement and monitor a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s cybersecurity incident response plan and its security policy
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
The Company’s CSO, in coordination with the Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”), CTO, and Chief Legal Officer (“CLO”), works collaboratively across the Company to implement and monitor a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s cybersecurity incident response plan and its security policy. To facilitate the success of the Company’s cybersecurity risk management program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, the CSO, the CTO and other executive leadership team members are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report risks from cybersecurity threats and cybersecurity incidents to the Audit Committee when appropriate.
The Company’s prior Chief Security Officer departed in late 2024 and the CSO function is currently overseen by two co-CSOs on an interim basis until a permanent successor is appointed. Each of the co-CSOs has over 30 years of relevant experience in a variety of sectors, including travel, fintech, and e-commerce. One co-CSO has held Chief Information Security Officer, Chief Information Officer and Chief Security Officer roles at multiple multinational public companies, leading enterprise-wide cybersecurity strategies and risk management programs; he holds a Master's degree in Security and Risk Management. The other co-CSO has served as Chief Technology Officer and Chief Information Officer at several multinational public companies, where he has driven digital transformation initiatives, technology modernization efforts, and secure platform development; he holds a Bachelor's degree in Computer Information Systems. The Company’s CTO has over 20 years of experience, including leading global technology teams focused on developing secure, large-scale platforms, implementing advanced data security measures, and mitigating risks across complex technological ecosystems. He holds a Bachelor’s degree in Technology and a Master’s degree in Technology.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Each of the co-CSOs has over 30 years of relevant experience in a variety of sectors, including travel, fintech, and e-commerce. One co-CSO has held Chief Information Security Officer, Chief Information Officer and Chief Security Officer roles at multiple multinational public companies, leading enterprise-wide cybersecurity strategies and risk management programs; he holds a Master's degree in Security and Risk Management. The other co-CSO has served as Chief Technology Officer and Chief Information Officer at several multinational public companies, where he has driven digital transformation initiatives, technology modernization efforts, and secure platform development; he holds a Bachelor's degree in Computer Information Systems. The Company’s CTO has over 20 years of experience, including leading global technology teams focused on developing secure, large-scale platforms, implementing advanced data security measures, and mitigating risks across complex technological ecosystems. He holds a Bachelor’s degree in Technology and a Master’s degree in Technology. The Company’s CEO, CFO and CLO each hold undergraduate and graduate degrees in their respective fields, and each have extensive experience managing risks at the Company and at similar companies, including risks arising from cybersecurity threats.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee regularly receives presentations and reports from both Company management and third-parties, as appropriate, that address a wide range of topics related to cybersecurity risks, including evolving standards, third-party and independent reviews, threat environment updates, technology trends and information security considerations arising with respect to the Company’s peers and partners. The Company’s CSO and/or the Company’s CTO regularly meet with the Audit Committee (and, where appropriate, the full Board) to discuss technology, information security and cybersecurity programs, progress updates on the Company's key cybersecurity initiatives and related priorities and controls. At least annually, the Audit Committee and the full Board receive a comprehensive written report covering the Company's cybersecurity program and associated risks, and any changes made to the program since the previous report. Additionally, the Audit Committee is promptly apprised of any cybersecurity incident that meets established reporting thresholds, and receives ongoing updates regarding any such incident until it has been resolved. At each regularly scheduled Board meeting, the Audit Committee Chair provides the full Board with an update on all significant matters discussed, reviewed, considered and approved by the committee since the last regularly scheduled Board meeting.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true