|
Cybersecurity risk management, strategy, and governance
|12 Months Ended
Jan. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
ITEM 1C. Cybersecurity
Risk Management, Governance and Strategy
We recognize the importance of assessing, identifying, and managing material risks associated with cybersecurity threats. These risks include, among other things: operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
Our board of directors as a whole oversees the Company’s privacy and data security, including cybersecurity, risk exposures, policies and practices, and the steps management has taken to prevent, detect, monitor and control such risks and the potential impact of those exposures on our business, financial results, operations, and reputation. We have tools and protocols in place designed to prevent, detect and escalate security incidents within the Company.
Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. This process is owned by the Chief Information Security Officer (“CISO”) and is supported by both management and our board of directors. Our CISO has served in various information technology and security leadership roles for over 30 years. He has a Master of Science degree in Electrical Engineering from Stanford University.
Cybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed through a multi-faceted approach including third party assessments and reviews. As part of our risk assessment process, we may perform cybersecurity risk evaluations when selecting applicable third-party vendors, suppliers, and other service providers. To defend, detect and respond to cybersecurity incidents, we, among other things: conduct proactive cybersecurity reviews of systems and applications, conduct employee phishing training, and monitor emerging laws and regulations related to data protection and information security.
We have implemented incident response and breach management processes. Notifications are made based on the level of threat of the incident. Incidents are evaluated to determine materiality as well as operational and business impact. Depending on the nature and severity of an incident, this process provides for escalating notification to our CEO and the board of directors.
The "Risk Factors" section includes further detail about the material cybersecurity risks we face. We believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date.
Although we continue to invest in cybersecurity and to enhance our internal controls and processes, we cannot guarantee these measures will be sufficient to protect us from a network security incident. For further information regarding the risks we face from cybersecurity threats refer to the “Risk Factors” within this Form 10-K.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes.
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our board of directors as a whole oversees the Company’s privacy and data security, including cybersecurity, risk exposures, policies and practices, and the steps management has taken to prevent, detect, monitor and control such risks and the potential impact of those exposures on our business, financial results, operations, and reputation. We have tools and protocols in place designed to prevent, detect and escalate security incidents within the Company.
Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. This process is owned by the Chief Information Security Officer (“CISO”) and is supported by both management and our board of directors. Our CISO has served in various information technology and security leadership roles for over 30 years. He has a Master of Science degree in Electrical Engineering from Stanford University.
Cybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed through a multi-faceted approach including third party assessments and reviews. As part of our risk assessment process, we may perform cybersecurity risk evaluations when selecting applicable third-party vendors, suppliers, and other service providers. To defend, detect and respond to cybersecurity incidents, we, among other things: conduct proactive cybersecurity reviews of systems and applications, conduct employee phishing training, and monitor emerging laws and regulations related to data protection and information security.
We have implemented incident response and breach management processes. Notifications are made based on the level of threat of the incident. Incidents are evaluated to determine materiality as well as operational and business impact. Depending on the nature and severity of an incident, this process provides for escalating notification to our CEO and the board of directors.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our board of directors as a whole oversees the Company’s privacy and data security, including cybersecurity, risk exposures, policies and practices, and the steps management has taken to prevent, detect, monitor and control such risks and the potential impact of those exposures on our business, financial results, operations, and reputation.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
We have implemented incident response and breach management processes. Notifications are made based on the level of threat of the incident. Incidents are evaluated to determine materiality as well as operational and business impact. Depending on the nature and severity of an incident, this process provides for escalating notification to our CEO and the board of directors.
|Cybersecurity Risk Role of Management [Text Block]
|
Risk Management, Governance and Strategy
We recognize the importance of assessing, identifying, and managing material risks associated with cybersecurity threats. These risks include, among other things: operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
Our board of directors as a whole oversees the Company’s privacy and data security, including cybersecurity, risk exposures, policies and practices, and the steps management has taken to prevent, detect, monitor and control such risks and the potential impact of those exposures on our business, financial results, operations, and reputation. We have tools and protocols in place designed to prevent, detect and escalate security incidents within the Company.
Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. This process is owned by the Chief Information Security Officer (“CISO”) and is supported by both management and our board of directors. Our CISO has served in various information technology and security leadership roles for over 30 years. He has a Master of Science degree in Electrical Engineering from Stanford University.
Cybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed through a multi-faceted approach including third party assessments and reviews. As part of our risk assessment process, we may perform cybersecurity risk evaluations when selecting applicable third-party vendors, suppliers, and other service providers. To defend, detect and respond to cybersecurity incidents, we, among other things: conduct proactive cybersecurity reviews of systems and applications, conduct employee phishing training, and monitor emerging laws and regulations related to data protection and information security.
We have implemented incident response and breach management processes. Notifications are made based on the level of threat of the incident. Incidents are evaluated to determine materiality as well as operational and business impact. Depending on the nature and severity of an incident, this process provides for escalating notification to our CEO and the board of directors.
The "Risk Factors" section includes further detail about the material cybersecurity risks we face. We believe that risks from prior cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business to date.
Although we continue to invest in cybersecurity and to enhance our internal controls and processes, we cannot guarantee these measures will be sufficient to protect us from a network security incident. For further information regarding the risks we face from cybersecurity threats refer to the “Risk Factors” within this Form 10-K.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|This process is owned by the Chief Information Security Officer (“CISO”) and is supported by both management and our board of directors.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our CISO has served in various information technology and security leadership roles for over 30 years. He has a Master of Science degree in Electrical Engineering from Stanford University.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
We recognize the importance of assessing, identifying, and managing material risks associated with cybersecurity threats. These risks include, among other things: operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef