|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Jul. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
Our cybersecurity framework (which includes management of related risks), is based on recognized cybersecurity industry frameworks and standards, including those of the National Institute of Standards and Technology, the Center for Internet Security Controls, and the International Organization for Standardization. We do not certify that we meet any particular technical standards, specifications, or requirements, but we use the aforementioned frameworks and standards as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business. We use these frameworks, together with information collected from internal assessments, to develop policies for the use of our information assets (e.g., IT business information and information resources such as mobile phones, computers and workstations), access to specific intellectual property or technologies, and protection of personal information. We protect these information assets through industry-standard techniques, by strong Identity and Access Management framework, such as Role Based Access Control, Attribute Based Access Control, principle of Least Privilege, Need-to-Know access and multi factor authentication as obligatory second factor to our core resources. We also enhance our endpoint protection by deploying an endpoint detection and response tool. Its core mission is to defend our endpoints and systems against new malware, rootkits, spywares and ransomware. We also work with internal stakeholders across the Company to integrate foundational cybersecurity principles throughout our operations, including the employment of multiple layers of cybersecurity defenses, restricted access based on business needs, and integrity of our business information. We routinely train our employees on cybersecurity awareness on social engineering attacks, confidential information protection, emerging threats and simulated phishing attacks to improve self-awareness of our employees.
We have standing engagements with incident response experts and external counsel, including through our cyber insurance. We frequently collaborate with industry experts and cybersecurity practitioners at other companies to exchange intelligence about potential cybersecurity threats, best practices and trends. We continuously monitor and collect insights on the latest vulnerabilities and attack patterns (TTPs) released by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST).
The annual “Threat Landscape” report published by the European Union Agency for Cybersecurity (ENISA) each October serves as a key strategic intelligence source supporting the hardening and protection of our infrastructure. This report offers a comprehensive perspective on prevalent attack types, mapped across threat vectors and industry domains, accompanied by actionable defense strategies that support effective risk reduction to levels aligned with our organizational tolerance. It allows for the deployment of tailored security measures, enhancing Zedge’s ability to withstand evolving cyber risks.
We also have our own incident response team who is engaged in dealing with security events triggered by our Security Information and Event Management (SIEM) system. Continuous monitoring of our infrastructure — from endpoint devices to virtual clusters — helps detect potential interception of internal communications, preventing the leakage of business-critical data.
Our cybersecurity risk management extends to risks associated with our use of third-party service providers. For instance, we conduct risk and compliance assessments of third-party service providers by checking on a permanent basis every new vendor that is going to cooperate with the Company. The aim is to verify if vendors due diligence and risks associated with it are within our risk tolerance set by management.
Our cybersecurity risk management is an important part of our comprehensive business continuity program and enterprise risk management. Our global information security team periodically engages with a cross-functional group of subject matter experts and leaders to assess and refine our cybersecurity risk posture and preparedness. For example, we regularly evaluate and update contingency strategies for our business in the event that a portion of our information resources were to be unavailable due to a cybersecurity incident. We practice our response to potential cybersecurity incidents through regular tabletop exercises, threat hunting and red team exercises.
Our vulnerability management program involves regular scanning and testing of systems, endpoints, virtual environments, and cloud-based assets to identify potential software flaws, misconfigurations, or exposure points. Once vulnerabilities are detected, we prioritize remediation based on risk impact and business criticality, ensuring that all gaps are addressed in a timely and effective manner. This proactive approach enables us to maintain a hardened infrastructure, reduce attack surface, and align with industry best practices and regulatory expectations.
As part of our secure development lifecycle (SDLC), we conduct both automated and manual code reviews to ensure that the applications we deliver to our users are resilient against exploitation and designed to prevent data leakage. By embedding security controls throughout the development process — from design to deployment — we uphold confidentiality, integrity, and reliability. This approach not only protects sensitive user data, but also reinforces trust in our platform and supports long-term compliance with regulatory frameworks.
In response to the growing use of AI, by bad actors, we adapt our internal policies, procedures, and control mechanisms to address AI-driven threats, including:
Our multi-layered defense strategy includes:
These practices ensure our organization remains agile, secure, and prepared for the evolving AI-driven threat landscape.
|Cybersecurity Risk Management Processes Integrated [Text Block]
|We also work with internal stakeholders across the Company to integrate foundational cybersecurity principles throughout our operations, including the employment of multiple layers of cybersecurity defenses, restricted access based on business needs, and integrity of our business information. We routinely train our employees on cybersecurity awareness on social engineering attacks, confidential information protection, emerging threats and simulated phishing attacks to improve self-awareness of our employees.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance of Cybersecurity Risk Management
The board of directors, as a whole, has oversight responsibility for our strategic and operational risks and sets associated risk parameters and tolerance levels. The audit committee assists the board of directors with this responsibility by reviewing and discussing the defined risks, its assessment and proposed mitigation strategies, including cybersecurity risks, with members of management. The audit committee, in turn, periodically reports on its review with the board of directors.
Management is responsible for day-to-day assessment and management of cybersecurity risks and reports regularly to the audit committee.
Zedge’s Cybersecurity risk governance has several components that can help our organization understand and implement cybersecurity governance practices achieve long-term cybersecurity goals beyond the day-to-day information security tasks, align with legal and regulatory compliance, and the direction of the Company through:
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The board of directors, as a whole, has oversight responsibility for our strategic and operational risks and sets associated risk parameters and tolerance levels.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
The board of directors, as a whole, has oversight responsibility for our strategic and operational risks and sets associated risk parameters and tolerance levels. The audit committee assists the board of directors with this responsibility by reviewing and discussing the defined risks, its assessment and proposed mitigation strategies, including cybersecurity risks, with members of management. The audit committee, in turn, periodically reports on its review with the board of directors.
Management is responsible for day-to-day assessment and management of cybersecurity risks and reports regularly to the audit committee.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Management is responsible for day-to-day assessment and management of cybersecurity risks and reports regularly to the audit committee.
|Cybersecurity Risk Role of Management [Text Block]
|
Zedge’s Cybersecurity risk governance has several components that can help our organization understand and implement cybersecurity governance practices achieve long-term cybersecurity goals beyond the day-to-day information security tasks, align with legal and regulatory compliance, and the direction of the Company through:
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef