|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Feb. 02, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|Cybersecurity Risk Management and Strategy
We have implemented several measures to identify and assess our cybersecurity threats. We self-assess maturity levels along with areas of risk for the cyber kill chain using the ISO/IEC 33004:2015 Process Maturity Model. Within this model, our risk dashboard is continually assessed based on eight key initiatives: reconnaissance, intrusion, exploitation, privilege escalation, lateral movement, obfuscation/anti-forensics, denial of service and exfiltration. Along with this model, we engage and utilize various third parties to measure risk profiles of ourselves and vendors, security threats specific to our Company both internal and external through multiple avenues such as our website and social media and perform periodic penetration tests on Company systems to identify cybersecurity risks and threats to the Company. These evaluations include testing both the design and operational effectiveness of security controls. We recognize a cybersecurity incident experienced by a supplier or vendor could materially impact us. We assess third party cybersecurity controls as part of our third-party information technology risk when integrating new tools or third parties. We contractually require third parties to report cybersecurity incidents, if applicable, to us so we can assess the impact of the incident and any necessary regulatory reporting obligations that may be required. Additionally, as part of the contract management process, new information technology vendors are subject to a cybersecurity review by the information technology team and include cybersecurity and data privacy language, if applicable, in contracts.
Training of employees, utilization of incident response plans, payment card industry audits, and SOX testing are all processes by which we seek to prevent, detect, mitigate and remediate cybersecurity incidents. In the event of a security or data incident, the impact is evaluated, ranked by severity, and prioritized for remediation. Incidents deemed to have a moderate or higher business impact, even if immaterial to the Company, are reported to the audit committee.
Notwithstanding our risk management efforts related to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material or other adverse effect on us. See Item 1A. “Risk Factors” for a discussion of our information technology and cybersecurity risks.
In fiscal 2024, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Identifying and assessing our cybersecurity risk is integrated into our overall risk management systems and processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|Notwithstanding our risk management efforts related to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material or other adverse effect on us. See Item 1A. “Risk Factors” for a discussion of our information technology and cybersecurity risks.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|Cybersecurity Governance
Our audit committee of our board of directors is formally charged with oversight of cybersecurity risk. This includes reviewing the Company’s cybersecurity and other information technology risks, controls and procedures, including a high-level review of the threat landscape facing the Company and the Company’s strategy to mitigate cybersecurity risks and potential breaches, and the Company’s plan to respond to data breaches.
Identifying and assessing our cybersecurity risk is integrated into our overall risk management systems and processes. As part of our program, our internal audit team facilitates an annual risk assessment that includes assessing cybersecurity and other technology risks. The results are shared with the board of directors during a regular board meeting. In addition, a quarterly cyber risk assessment process run by our information technology team, including our chief technology officer, is shared with the audit committee. The chair of the audit committee reports on significant cybersecurity updates to the full board of directors during executive sessions of our quarterly meetings. Our audit committee members also engage in conversations throughout the year with management on cybersecurity events and discuss any updates to our cybersecurity processes, systems and programs.
Our cybersecurity risk management processes are overseen by leaders from our information technology, compliance and legal teams. Our chief technology officer has over 30 years of experience leading information technology organizations. Other individual leaders within these teams have on average over 20 years of experience in roles involving information technology, including security and compliance.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our audit committee of our board of directors is formally charged with oversight of cybersecurity risk.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The results are shared with the board of directors during a regular board meeting.
|Cybersecurity Risk Role of Management [Text Block]
|In addition, a quarterly cyber risk assessment process run by our information technology team, including our chief technology officer, is shared with the audit committee.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our cybersecurity risk management processes are overseen by leaders from our information technology, compliance and legal teams.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our chief technology officer has over 30 years of experience leading information technology organizations. Other individual leaders within these teams have on average over 20 years of experience in roles involving information technology, including security and compliance.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our audit committee members also engage in conversations throughout the year with management on cybersecurity events and discuss any updates to our cybersecurity processes, systems and programs.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef