|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Aug. 03, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Enterprise risk management (ERM) is an integral part of our business processes and our ERM framework considers cybersecurity risk, alongside other company risks, as part of our overall risk assessment process. We follow an industry-leading
National Institute of Standards and Technology cybersecurity framework (NIST CSF) and have developed a comprehensive information security program for assessing, identifying and managing cybersecurity risks that is designed to protect our systems and data from unauthorized access, use or other security impact.
As part of our information security program, we continuously monitor and update our information technology networks and infrastructure. We have dedicated internal legal, compliance and information security teams, and leverage consultants and third-party service providers to inform our understanding of the threat landscape and to identify, prevent, detect, address and mitigate risks associated with unauthorized access, misuse, computer viruses and other events that could have a security impact. Our information security strategy focuses on complying with applicable data privacy and protection laws, maintaining the availability of our manufacturing operations, protecting data, detecting and responding to threats, building resiliency and providing a secure foundation for growth and innovation. We invest in industry standard security technology to protect the company’s data and business processes against risk of cybersecurity incidents. Our data security management program includes identity, trust, vulnerability and threat management business processes, as well as adoption of standard data protection policies.
We measure our data security effectiveness by benchmarking against industry-accepted methods, presenting the results to our Board and Audit Committee for evaluation, and making improvements based on such evaluation. We maintain and routinely test backup systems and disaster recovery and also have processes in place to prevent disruptions resulting from our implementation of new software and systems. We maintain a third-party cyber risk management process to review and monitor critical suppliers regularly for cybersecurity risk and prescribe remediation activities when necessary.
We train our employees through annual security training, phishing simulations and regular communications about timely security topics to enhance their understanding of cybersecurity threats and their ability to identify and escalate potential cybersecurity events. We have a cross-functional crisis management team comprised of business unit and functional leaders and a crisis management plan that includes procedures for identifying, containing and responding to cybersecurity incidents. We engage third-party cybersecurity experts to conduct tabletop exercises with our executive leadership to enhance incident response preparedness.
Our cybersecurity risk management strategy includes the use of cybersecurity insurance that provides protection against certain potential losses arising from certain cybersecurity incidents; however, such insurance may not insure us against all claims related to security breaches, cyberattacks and other related breaches. The company has previously experienced threats and breaches to its data and systems but has not experienced a breach that had a material impact on its operations or business and has not incurred any material breach-related expenses for the last three years that are reasonably likely to materially affect the company or its business strategy, results of operations or financial condition. However, as discussed in “Item 1A. Risk Factors,” specifically the risks under the heading, “We may be adversely impacted by a disruption, failure or security breach of our information technology systems,” cyber threats are constantly evolving and becoming more frequent and sophisticated. Accordingly, no matter how well designed or implemented the company’s information security policies and procedures are, there can be no assurance that these policies and procedures will prevent or limit the impact of a cybersecurity incident.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Enterprise risk management (ERM) is an integral part of our business processes and our ERM framework considers cybersecurity risk, alongside other company risks, as part of our overall risk assessment process.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|The company has previously experienced threats and breaches to its data and systems but has not experienced a breach that had a material impact on its operations or business and has not incurred any material breach-related expenses for the last three years that are reasonably likely to materially affect the company or its business strategy, results of operations or financial condition.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
We have established oversight mechanisms intended to provide effective cybersecurity governance, risk management, and timely incident response. Our Board, in coordination with the Audit Committee, oversees the company’s ERM process, including the management of risks arising from cybersecurity threats.
Our Board annually reviews assessments of our information security program under the NIST CSF. It receives benchmarking results of our data security effectiveness and reports from our Chief Digital & Technology Officer (CDTO) and Chief Information Security Officer (CISO) on our information security program and recent developments. Our Board has delegated the primary responsibility to oversee cybersecurity matters to the Audit Committee. To fulfill its oversight responsibilities, the Audit Committee reviews the measures implemented by the company to identify and mitigate cybersecurity risks and receives quarterly updates from our CDTO and CISO on the information security program, including the status of significant cybersecurity incidences, the emerging threat landscape, and the status of projects to strengthen the company’s information security posture. The Audit Committee regularly reports to the Board on cybersecurity matters. In addition, we have a crisis management plan and protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the company and, where appropriate, reported promptly to the Audit Committee or Board, with ongoing updates regarding any such incident until it has been addressed. Our risk oversight processes and disclosure controls and procedures are designed to escalate key risks for the Board to analyze for disclosure purposes.
Our CDTO, a member of our corporate leadership team, oversees the team responsible for leading the enterprise-wide information technology strategy, policy, standards, architecture, and processes. Our CISO, who reports to the CDTO, oversees the dedicated information security team, which works in partnership with the company’s ERM team and corporate audit department as well as consultants as part of an overall internal controls process to monitor cybersecurity threats and prevent, detect, mitigate and remediate cybersecurity incidents. The CDTO has over 30 years of information technology experience, including serving in strategic planning, oversight and global operation of information systems and technology functions for
companies in the consumer packaged goods industry. The CISO has over 25 years of information technology experience, including strategy, execution, and operations of enterprise-wide security programs, including cybersecurity programs, and global information technology infrastructure programs.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board, in coordination with the Audit Committee, oversees the company’s ERM process, including the management of risks arising from cybersecurity threats.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our Board annually reviews assessments of our information security program under the NIST CSF. It receives benchmarking results of our data security effectiveness and reports from our Chief Digital & Technology Officer (CDTO) and Chief Information Security Officer (CISO) on our information security program and recent developments. Our Board has delegated the primary responsibility to oversee cybersecurity matters to the Audit Committee. To fulfill its oversight responsibilities, the Audit Committee reviews the measures implemented by the company to identify and mitigate cybersecurity risks and receives quarterly updates from our CDTO and CISO on the information security program, including the status of significant cybersecurity incidences, the emerging threat landscape, and the status of projects to strengthen the company’s information security posture. The Audit Committee regularly reports to the Board on cybersecurity matters. In addition, we have a crisis management plan and protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the company and, where appropriate, reported promptly to the Audit Committee or Board, with ongoing updates regarding any such incident until it has been addressed. Our risk oversight processes and disclosure controls and procedures are designed to escalate key risks for the Board to analyze for disclosure purposes.
|Cybersecurity Risk Role of Management [Text Block]
|Our CDTO, a member of our corporate leadership team, oversees the team responsible for leading the enterprise-wide information technology strategy, policy, standards, architecture, and processes. Our CISO, who reports to the CDTO, oversees the dedicated information security team, which works in partnership with the company’s ERM team and corporate audit department as well as consultants as part of an overall internal controls process to monitor cybersecurity threats and prevent, detect, mitigate and remediate cybersecurity incidents.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our Board has delegated the primary responsibility to oversee cybersecurity matters to the Audit Committee. To fulfill its oversight responsibilities, the Audit Committee reviews the measures implemented by the company to identify and mitigate cybersecurity risks and receives quarterly updates from our CDTO and CISO
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The CDTO has over 30 years of information technology experience, including serving in strategic planning, oversight and global operation of information systems and technology functions for
companies in the consumer packaged goods industry. The CISO has over 25 years of information technology experience, including strategy, execution, and operations of enterprise-wide security programs, including cybersecurity programs, and global information technology infrastructure programs.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Audit Committee regularly reports to the Board on cybersecurity matters. In addition, we have a crisis management plan and protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the company and, where appropriate, reported promptly to the Audit Committee or Board, with ongoing updates regarding any such incident until it has been addressed. Our risk oversight processes and disclosure controls and procedures are designed to escalate key risks for the Board to analyze for disclosure purposes.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef