|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 28, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
The Company’s cybersecurity policies, standards, processes, and practices for assessing, identifying and managing material risks from cybersecurity threats and responding to cybersecurity incidents are part of the Company’s overall risk assessment efforts. The Company has established controls and procedures, including an incidence response plan, that provide for the identification, notification, escalation, communication, and remediation of data security incidents at appropriate levels so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. The Company continues to review its Cybersecurity program and controls and procedures as part of its efforts to strengthen its defenses.As part of its cybersecurity program, the Company utilizes firewalls, identity and access management programs, email security, anti-malware, and a detection and response program. The Company periodically assesses and tests its policies, standards, processes and practices that are designed to address cybersecurity threats and incidents by performing internal and external vulnerability scans, penetration testing, and phishing exercises. The Company utilizes a combination of internal employees and third parties to perform security monitoring and 24/7 response, penetration testing, phishing campaigns, and provide security awareness training to our employees. We recently updated our onboarding process for certain third-party vendors and service providers to include a review and assessment of their information security practices. The Company also conducts information security and awareness training to ensure that employees are aware of information security risks and to enable them to take steps to mitigate those risks.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Cybersecurity Risk Management and Strategy
The Company’s cybersecurity policies, standards, processes, and practices for assessing, identifying and managing material risks from cybersecurity threats and responding to cybersecurity incidents are part of the Company’s overall risk assessment efforts. The Company has established controls and procedures, including an incidence response plan, that provide for the identification, notification, escalation, communication, and remediation of data security incidents at appropriate levels so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. The Company continues to review its Cybersecurity program and controls and procedures as part of its efforts to strengthen its defenses.As part of its cybersecurity program, the Company utilizes firewalls, identity and access management programs, email security, anti-malware, and a detection and response program. The Company periodically assesses and tests its policies, standards, processes and practices that are designed to address cybersecurity threats and incidents by performing internal and external vulnerability scans, penetration testing, and phishing exercises. The Company utilizes a combination of internal employees and third parties to perform security monitoring and 24/7 response, penetration testing, phishing campaigns, and provide security awareness training to our employees. We recently updated our onboarding process for certain third-party vendors and service providers to include a review and assessment of their information security practices. The Company also conducts information security and awareness training to ensure that employees are aware of information security risks and to enable them to take steps to mitigate those risks.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|As of the date of this report, the Company is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations, or financial condition. In the event of an attack or other intrusion, we have a response team of internal and external resources engaged and prepared to respond. We also maintain cyber liability insurance to help mitigate potential liabilities resulting from cyber issues. We plan to continually invest in efforts to enhance data security in response to developments in the cybersecurity landscape.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Audit Committee and the Board of Directors are responsible for the oversight of cybersecurity risk. The Audit Committee and Board of Directors receive periodic updates from management on the Company's cybersecurity program, threats, and defense measures implemented. Additionally, our Senior Vice President of Information Technology ("SVP - IT") provides updates to the Board of Directors on an as needed basis with respect to cybersecurity risks or any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such cybersecurity incident until it has been remediated.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee and the Board of Directors are responsible for the oversight of cybersecurity risk. The Audit Committee and Board of Directors receive periodic updates from management on the Company's cybersecurity program, threats, and defense measures implemented. Additionally, our Senior Vice President of Information Technology ("SVP - IT") provides updates to the Board of Directors on an as needed basis with respect to cybersecurity risks or any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such cybersecurity incident until it has been remediated.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Additionally, our Senior Vice President of Information Technology ("SVP - IT") provides updates to the Board of Directors on an as needed basis with respect to cybersecurity risks or any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such cybersecurity incident until it has been remediated
|Cybersecurity Risk Role of Management [Text Block]
|
The Audit Committee and the Board of Directors are responsible for the oversight of cybersecurity risk. The Audit Committee and Board of Directors receive periodic updates from management on the Company's cybersecurity program, threats, and defense measures implemented. Additionally, our Senior Vice President of Information Technology ("SVP - IT") provides updates to the Board of Directors on an as needed basis with respect to cybersecurity risks or any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such cybersecurity incident until it has been remediated.
Role of Management
Our SVP-IT oversees and provides accountability related to our cybersecurity risk management strategy and overall information security program. The SVP-IT’s cybersecurity team is led by a Director of Information Technology Security. The cybersecurity team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The program incorporates policies and practices designed to protect the privacy and security of our sensitive information.
The cybersecurity team includes dedicated internal resources that currently have Certified Information Systems Security Professional ("CISSP") credentials, Certificate of Cloud Security Knowledge ("CCSK"), and other security and network certifications. In addition to our internal security staff, we partner with various third-party security service providers to augment our staffing, expertise, and hours of operation.
The cybersecurity team leverages tools and systems such as Security Information and Event Management ("SIEM"), for real time alerts and insights.
The SVP-IT regularly reports to our senior leadership team, as well as periodically to our Board of Directors, regarding our cybersecurity program and material cybersecurity risks. The SVP-IT coordinates with other teams including internal Audit, to ensure a combined focus on technology modernization and remediation needs. The SVP-IT is briefed weekly on current security operations and relevant issues across the cybersecurity threat landscape.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our SVP-IT oversees and provides accountability related to our cybersecurity risk management strategy and overall information security program. The SVP-IT’s cybersecurity team is led by a Director of Information Technology Security. The cybersecurity team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The program incorporates policies and practices designed to protect the privacy and security of our sensitive information.
The cybersecurity team includes dedicated internal resources that currently have Certified Information Systems Security Professional ("CISSP") credentials, Certificate of Cloud Security Knowledge ("CCSK"), and other security and network certifications. In addition to our internal security staff, we partner with various third-party security service providers to augment our staffing, expertise, and hours of operation.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The cybersecurity team is responsible for leading enterprise-wide cybersecurity strategy, policy, standards, architecture, and processes. The program incorporates policies and practices designed to protect the privacy and security of our sensitive information.
The cybersecurity team includes dedicated internal resources that currently have Certified Information Systems Security Professional ("CISSP") credentials, Certificate of Cloud Security Knowledge ("CCSK"), and other security and network certifications. In addition to our internal security staff, we partner with various third-party security service providers to augment our staffing, expertise, and hours of operation.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The SVP-IT regularly reports to our senior leadership team, as well as periodically to our Board of Directors, regarding our cybersecurity program and material cybersecurity risks. The SVP-IT coordinates with other teams including internal Audit, to ensure a combined focus on technology modernization and remediation needs. The SVP-IT is briefed weekly on current security operations and relevant issues across the cybersecurity threat landscape.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef