|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity risk management is a component of the company’s broader enterprise risk management program and we have established cybersecurity policies and procedures to protect against and mitigate harm from cybersecurity incidents. We respond to cybersecurity incidents in accordance with our cybersecurity policies and procedures and applicable law. Rackspace maintains a cross-functional approach to cybersecurity risk, which is designed to help prevent, identify, assess, manage, mitigate, and respond to cybersecurity threats.
Our cybersecurity strategy focuses on implementing effective and efficient controls, technologies, and other processes to assess, identify, manage and address material cybersecurity risks. These include, among other things: annual and ongoing security awareness training for employees; mechanisms to detect and monitor unusual network activity; and containment and incident response tools. We monitor issues that are internally discovered or externally reported that may affect our operations, systems, network, data, products and/or services, and have processes to assess those issues for potential cybersecurity impact or risk.
We regularly assess and deploy technical safeguards designed to protect our information systems from cybersecurity threats. Such safeguards are regularly evaluated and improved based on vulnerability assessments, cybersecurity threat intelligence and incident response experience. Our cybersecurity policies and procedures include incident response plans which guide our employees, senior management, the Audit Committee and the Board on our response to cybersecurity incidents, including escalation processes, as appropriate.
Our team engages with external cybersecurity advisors and experts, including outside counsel and outside cybersecurity firms, assessors, auditors and consultants as necessary or appropriate. We also maintain numerous industry-related compliance certifications for various aspects of our business, such as International Organization for Standardization ("ISO") 27001, Service Organization Controls ("SOC 1, 2, 3") and Payment Card Industry ("PCI"), Federal Information Security Management Act ("FISMA"), Federal Risk and Authorization Management Program ("FedRAMP") and Health Information Trust Alliance (“HITRUST”) in the U.S., Information Security Registered Assessors Program ("IRAP") in Australia and Public Services Network ("PSN") in the U.K.
Our cybersecurity policies and procedures are designed to vet key third-party providers and provide for oversight and cooperation regarding cybersecurity incidents. In addition, our cybersecurity policies and procedures require our third-party providers to meet appropriate security requirements and we investigate security incidents that have impacted our third-party providers, as appropriate; however, our ability to monitor our third-party service providers’ data security is limited.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Cybersecurity risk management is a component of the company’s broader enterprise risk management program and we have established cybersecurity policies and procedures to protect against and mitigate harm from cybersecurity incidents.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Audit Committee of our Board oversees our cybersecurity risk.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our CSO leads our overall cybersecurity function and supervises our cybersecurity team’s efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our CSO reports to our President – Artificial Intelligence, Technology and Sustainability, who has been a Chief Information Officer or Chief Technology Officer of two other large publicly traded companies. He provides overall leadership and guidance for the company’s technology department, including the cybersecurity team.
|Cybersecurity Risk Role of Management [Text Block]
|
Management’s Role
Our CSO leads our overall cybersecurity function and supervises our cybersecurity team’s efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents. She provides regular updates directly to the Audit Committee, typically on a quarterly basis. She has over 20 years of experience in information security leadership positions, including with large technology and healthcare companies as well as several large financial institutions. She holds a Bachelor of Science from Arizona State University and has been with us since 2019.
Our CSO reports to our President – Artificial Intelligence, Technology and Sustainability, who has been a Chief Information Officer or Chief Technology Officer of two other large publicly traded companies. He provides overall leadership and guidance for the company’s technology department, including the cybersecurity team. He holds a Master of Business Administration in international business from The Ohio State University, a Master of Computer Applications in computer science from the University of Mumbai, a Bachelor of Science in physics from the University of Madras and has been with us since 2021.
Key security, risk, and compliance personnel across a cross-functional group of internal stakeholders, including senior management, meet regularly to develop and continually evaluate our cybersecurity policies and procedures, including discussions of the following:
•cybersecurity strategies for preservation of the confidentiality, integrity and availability of company and customer information;
• identification, prevention and mitigation of cybersecurity threats and incidents; and
•effective response to cybersecurity incidents (including escalation procedures of certain cybersecurity incidents so that decisions regarding public disclosure and other required reporting can be made by the appropriate personnel in a timely manner).
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our CSO reports to our President – Artificial Intelligence, Technology and Sustainability, who has been a Chief Information Officer or Chief Technology Officer of two other large publicly traded companies. He provides overall leadership and guidance for the company’s technology department, including the cybersecurity team.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|She has over 20 years of experience in information security leadership positions, including with large technology and healthcare companies as well as several large financial institutions. She holds a Bachelor of Science from Arizona State University and has been with us since 2019.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Our CSO leads our overall cybersecurity function and supervises our cybersecurity team’s efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents. She provides regular updates directly to the Audit Committee, typically on a quarterly basis. She has over 20 years of experience in information security leadership positions, including with large technology and healthcare companies as well as several large financial institutions. She holds a Bachelor of Science from Arizona State University and has been with us since 2019.
Our CSO reports to our President – Artificial Intelligence, Technology and Sustainability, who has been a Chief Information Officer or Chief Technology Officer of two other large publicly traded companies. He provides overall leadership and guidance for the company’s technology department, including the cybersecurity team. He holds a Master of Business Administration in international business from The Ohio State University, a Master of Computer Applications in computer science from the University of Mumbai, a Bachelor of Science in physics from the University of Madras and has been with us since 2021.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef