|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Risk Management and Strategy
TripCo’s corporate level IT and cybersecurity functions are provided by Liberty Media as part of the services agreement described in Item 1. Business. Through the services agreement, we participate in Liberty Media’s processes for assessing, identifying, and managing risks from cybersecurity threats, as detailed below. Tripadvisor, as a separate publicly traded company from TripCo, operates its own cybersecurity function. While primary oversight for Tripadvisor rests with its board of directors and Audit Committee, we receive regular reporting from Tripadvisor management and collaborate with those tasked with oversight to ensure risks are appropriately addressed.
The Company is committed to protecting the security and integrity of our systems, networks, databases and applications and, as a result, has implemented processes designed to prevent, assess, identify, and manage material risks associated with cybersecurity threats.
Cybersecurity risks are assessed as part of our enterprise risk assessment and risk management program and our cybersecurity risk management program is designed and assessed based on recognized frameworks, including the National Institute of Standards and Technology Cybersecurity Framework ("NIST CSF”).
We rely on a multidisciplinary team, including our information security functions, legal departments, management, and third-party consultants, as described further below, at the corporate level and at Tripadvisor to identify, assess, and manage cybersecurity threats and risks. We identify and assess risks from cybersecurity threats by monitoring and evaluating our threat environment and our risk profile using various methods including, using manual and automated tools, such as vulnerability scanning software, monitoring existing and emerging cybersecurity threats, analyzing reports of threats and threat actors, conducting scans of the threat environment, evaluating our industry’s risk profile, utilizing internal and external audits and assessments, and conducting threat and vulnerability assessments.
To manage and mitigate material risks from cybersecurity threats to our information systems and data, we implement and maintain various technical, physical and organizational measures, processes and policies. These measures include risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our IT, Security and other departments, encryption of data, network security controls, access controls, physical security, asset management, system monitoring, vendor risk management program, employee cybersecurity awareness and training, phishing tests, and penetration testing. Cybersecurity awareness training is also made available annually to our Board of Directors.
In the event of a potential cybersecurity incident, or a series of related cybersecurity incidents, we have cybersecurity incident response frameworks in place at the corporate level and at Tripadvisor. These frameworks are a set of coordinated procedures and tasks that our incident response teams execute with the goal of ensuring timely and accurate identification, resolution and reporting of cybersecurity incidents both internally and externally, as necessary.
To operate our business, we utilize certain third-party service providers to perform a variety of operational functions. We have implemented a third-party risk management program to evaluate the cybersecurity practices of higher risk vendors and vendors that encounter our systems or data. We additionally engage and retain third party consultants, legal advisors and assessors to keep us apprised of emerging third-party risk, defense and mitigation strategies, and governance best practices.
Impact of cybersecurity risks on business strategy, results of operations or financial condition
As of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations and financial condition.
For additional information on our cybersecurity risks, see “Risk Factors” under the section entitled "Risks Related to Information Security, Cybersecurity and Data Privacy" in Part I, Item 1A of this Annual Report on Form 10-K.
For additional information on Tripadvisor’s cybersecurity program and risks refer to Item 1C. “Cybersecurity” in their 2024 Form 10-K filed on February 20, 2025.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
TripCo’s corporate level IT and cybersecurity functions are provided by Liberty Media as part of the services agreement described in Item 1. Business. Through the services agreement, we participate in Liberty Media’s processes for assessing, identifying, and managing risks from cybersecurity threats, as detailed below. Tripadvisor, as a separate publicly traded company from TripCo, operates its own cybersecurity function. While primary oversight for Tripadvisor rests with its board of directors and Audit Committee, we receive regular reporting from Tripadvisor management and collaborate with those tasked with oversight to ensure risks are appropriately addressed.
The Company is committed to protecting the security and integrity of our systems, networks, databases and applications and, as a result, has implemented processes designed to prevent, assess, identify, and manage material risks associated with cybersecurity threats.
Cybersecurity risks are assessed as part of our enterprise risk assessment and risk management program and our cybersecurity risk management program is designed and assessed based on recognized frameworks, including the National Institute of Standards and Technology Cybersecurity Framework ("NIST CSF”).
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance
Role of the Board of Directors
Our Board of Directors has overall responsibility for risk oversight and has delegated to the Audit Committee primary enterprise risk oversight responsibility, including privacy and cybersecurity risk exposures, policies and practices, the steps management takes to detect, monitor and mitigate such risks and the potential impact of those exposures on our business, financial results, operations and reputation. The Audit Committee receives quarterly updates on the enterprise risk management program, including cybersecurity risks and the initiatives undertaken to identify, assess and mitigate such risks. This cybersecurity reporting may include threat and incident reporting, vulnerability detection reporting, risk mitigation metrics, systems and security operations updates, employee education initiatives, and internal audit observations, if applicable.
In addition to the efforts undertaken by the audit committee, the full Board of Directors regularly reviews matters relating to cybersecurity risk and cybersecurity risk management. Any material cybersecurity events would be brought to the attention of the full Board of Directors once the event is deemed material. We additionally use our incident response framework as part of the process we employ to keep our management and Board of Directors informed about and monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Role of Management
Through our services agreement with Liberty Media, we have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Facilities departments. The ISSC has management oversight responsibility for assessing and managing technology and operational risk, including information security, fraud, vendor, data protection and privacy, business continuity and resilience, and cybersecurity risks at the corporate level. The ISSC receives regular reports and updates from Tripadvisor regarding their cybersecurity risk management activities and, if any, incidents that have occurred.
Tripadvisor also has executive oversight committees responsible for assessing and managing cybersecurity risk as part of their enterprise risk management and compliance programs. Tripadvisor has designated the Compliance Committee and Chief Compliance Officer (“CCO”) with day-to-day management and oversight of corporate compliance initiatives, including cybersecurity. The Tripadvisor Compliance Committee consists of, among others, the Chief Financial Officer, Chief Legal Officer and CCO. The CCO has further established an Information Governance and Privacy Committee responsible for oversight of privacy and cybersecurity risks. The Information Governance and Privacy Committee consists of senior members of Tripadvisor’s Information Security Team and CCO, as well as representatives from engineering, product development and data privacy. The Information Governance and Privacy Committee meets regularly to discuss and monitor information uses and governance and risks associated with Tripadvisor’s information assets, including prevention, detection, mitigation and remediation of risks from cybersecurity threats.
Our management team’s experience includes a diverse background in telecom and other industries, with decades of experience in various aspects of cybersecurity. Liberty Media’s Head of Cybersecurity has more than 25 years of cybersecurity and information technology experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications and has worked at a variety of companies, including large publicly-traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, customer payment systems and telecommunications networks used by customers to transmit data. Tripadvisor maintains rigorous standards for its information security leadership positions, including requiring extensive experience in building and leading cybersecurity teams and implementing enterprise-wide cybersecurity programs.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
In addition to the efforts undertaken by the audit committee, the full Board of Directors regularly reviews matters relating to cybersecurity risk and cybersecurity risk management. Any material cybersecurity events would be brought to the attention of the full Board of Directors once the event is deemed material. We additionally use our incident response framework as part of the process we employ to keep our management and Board of Directors informed about and monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents.
|Cybersecurity Risk Role of Management [Text Block]
|
Through our services agreement with Liberty Media, we have established a cross functional Information Security Steering Committee (“ISSC”) with executives from our Legal, Accounting, Internal Audit and Risk Management, Cybersecurity and Facilities departments. The ISSC has management oversight responsibility for assessing and managing technology and operational risk, including information security, fraud, vendor, data protection and privacy, business continuity and resilience, and cybersecurity risks at the corporate level. The ISSC receives regular reports and updates from Tripadvisor regarding their cybersecurity risk management activities and, if any, incidents that have occurred.
Tripadvisor also has executive oversight committees responsible for assessing and managing cybersecurity risk as part of their enterprise risk management and compliance programs. Tripadvisor has designated the Compliance Committee and Chief Compliance Officer (“CCO”) with day-to-day management and oversight of corporate compliance initiatives, including cybersecurity. The Tripadvisor Compliance Committee consists of, among others, the Chief Financial Officer, Chief Legal Officer and CCO. The CCO has further established an Information Governance and Privacy Committee responsible for oversight of privacy and cybersecurity risks. The Information Governance and Privacy Committee consists of senior members of Tripadvisor’s Information Security Team and CCO, as well as representatives from engineering, product development and data privacy. The Information Governance and Privacy Committee meets regularly to discuss and monitor information uses and governance and risks associated with Tripadvisor’s information assets, including prevention, detection, mitigation and remediation of risks from cybersecurity threats.
Our management team’s experience includes a diverse background in telecom and other industries, with decades of experience in various aspects of cybersecurity. Liberty Media’s Head of Cybersecurity has more than 25 years of cybersecurity and information technology experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications and has worked at a variety of companies, including large publicly-traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, customer payment systems and telecommunications networks used by customers to transmit data. Tripadvisor maintains rigorous standards for its information security leadership positions, including requiring extensive experience in building and leading cybersecurity teams and implementing enterprise-wide cybersecurity programs.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Compliance Committee and Chief Compliance Officer (“CCO”)
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our management team’s experience includes a diverse background in telecom and other industries, with decades of experience in various aspects of cybersecurity. Liberty Media’s Head of Cybersecurity has more than 25 years of cybersecurity and information technology experience and holds Certified Information Security Manager and Certified in Risk and Information System Control certifications and has worked at a variety of companies, including large publicly-traded companies, implementing and managing IT and cybersecurity programs and teams, developing tools and processes to protect internal networks, customer payment systems and telecommunications networks used by customers to transmit data.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Tripadvisor Compliance Committee consists of, among others, the Chief Financial Officer, Chief Legal Officer and CCO. The CCO has further established an Information Governance and Privacy Committee responsible for oversight of privacy and cybersecurity risks. The Information Governance and Privacy Committee consists of senior members of Tripadvisor’s Information Security Team and CCO, as well as representatives from engineering, product development and data privacy. The Information Governance and Privacy Committee meets regularly to discuss and monitor information uses and governance and risks associated with Tripadvisor’s information assets, including prevention, detection, mitigation and remediation of risks from cybersecurity threats.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef