XML 51 R31.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Coupang has a cyber risk management framework designed to identify, assess, and manage cyber related risks. Cyber related risks are identified through self-identification, audits, assessments, and incidents. Our vulnerability scanning process uses both automated tools and penetration testing to identify vulnerabilities within our environment.
We seek to identify, manage and reduce the risks and potential vulnerabilities by integrating controls and solutions into information security and technology projects based on severity and priority.

The Chief Information Security Officer (“CISO”), who has extensive cybersecurity knowledge and skills gained from over 15 years of work experience at the Company and elsewhere, leads our global information security organization responsible for overseeing the Coupang information security program. The CISO regularly reviews our cyber strategy with technology leadership in order to integrate the cyber strategy across the organization. The CISO is updated on cybersecurity threats from experienced information security officers in our security organization on an ongoing basis and in conjunction with management, regularly reviews risk management measures implemented by the Company to identify and mitigate data protection and cybersecurity risks. Supporting the CISO, is the dedicated information security team, which comprises almost 200 individuals. In addition to full-time employees, external consultancy services provide us with certain information security services and specialized advice.

We conduct annual assessments by certified external third-party assessors as part of our industry-recognized information security certifications, ISO 27001, 27017, 27701, and ISMS-P. We periodically have external third-party consultants conduct maturity assessments of our Information Security program. The results of these audits and assessments inform us about possible risks which are managed through our enterprise risk management process. We employ external third-party vendors to provide cyber threat intelligence when relevant information is available or as requested. We also employ systems and processes designed to oversee, identify, and reduce the potential impact of a security incident at a third-party vendor, service provider, customer or otherwise implicating the third-party technology and systems we use. We also have a program of Cyber Tabletop exercises, run periodically, with key people in our business, to further enhance our capabilities to respond and recover to a cyber incident.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Coupang has a cyber risk management framework designed to identify, assess, and manage cyber related risks. Cyber related risks are identified through self-identification, audits, assessments, and incidents. Our vulnerability scanning process uses both automated tools and penetration testing to identify vulnerabilities within our environment.
We seek to identify, manage and reduce the risks and potential vulnerabilities by integrating controls and solutions into information security and technology projects based on severity and priority.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Coupang executive leadership team provides oversight and guidance on cyber policies, procedures, and strategies. Our Board of Director’s role in risk oversight is consistent with our leadership structure, with the executive leadership team having responsibility for assessing and managing risks we face in executing our business plans, and the Board and its committees providing oversight in connection with those efforts.
In addition to the full Board, the Audit Committee of the Board plays an important role in the oversight of our enterprise risk assessment and management activities, which identify key risks to our business, including risks related to cybersecurity, data privacy, and regulations, and assesses any steps taken to monitor and control such risk. The Audit Committee regularly meets with the CISO to discuss various cybersecurity matters including cyber strategy, cybersecurity risks, controls, including results of audits, mitigation strategies, areas of emerging risks, incidents, if any, and industry trends. We have protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported to the Audit Committee through ongoing updates until resolution.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Coupang executive leadership team provides oversight and guidance on cyber policies, procedures, and strategies. Our Board of Director’s role in risk oversight is consistent with our leadership structure, with the executive leadership team having responsibility for assessing and managing risks we face in executing our business plans, and the Board and its committees providing oversight in connection with those efforts.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee regularly meets with the CISO to discuss various cybersecurity matters including cyber strategy, cybersecurity risks, controls, including results of audits, mitigation strategies, areas of emerging risks, incidents, if any, and industry trends. We have protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported to the Audit Committee through ongoing updates until resolution.
Cybersecurity Risk Role of Management [Text Block]
In addition to the full Board, the Audit Committee of the Board plays an important role in the oversight of our enterprise risk assessment and management activities, which identify key risks to our business, including risks related to cybersecurity, data privacy, and regulations, and assesses any steps taken to monitor and control such risk. The Audit Committee regularly meets with the CISO to discuss various cybersecurity matters including cyber strategy, cybersecurity risks, controls, including results of audits, mitigation strategies, areas of emerging risks, incidents, if any, and industry trends. We have protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported to the Audit Committee through ongoing updates until resolution.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
In addition to the full Board, the Audit Committee of the Board plays an important role in the oversight of our enterprise risk assessment and management activities, which identify key risks to our business, including risks related to cybersecurity, data privacy, and regulations, and assesses any steps taken to monitor and control such risk. The Audit Committee regularly meets with the CISO to discuss various cybersecurity matters including cyber strategy, cybersecurity risks, controls, including results of audits, mitigation strategies, areas of emerging risks, incidents, if any, and industry trends. We have protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported to the Audit Committee through ongoing updates until resolution.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Chief Information Security Officer (“CISO”), who has extensive cybersecurity knowledge and skills gained from over 15 years of work experience at the Company and elsewhere, leads our global information security organization responsible for overseeing the Coupang information security program.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
In addition to the full Board, the Audit Committee of the Board plays an important role in the oversight of our enterprise risk assessment and management activities, which identify key risks to our business, including risks related to cybersecurity, data privacy, and regulations, and assesses any steps taken to monitor and control such risk. The Audit Committee regularly meets with the CISO to discuss various cybersecurity matters including cyber strategy, cybersecurity risks, controls, including results of audits, mitigation strategies, areas of emerging risks, incidents, if any, and industry trends. We have protocols by which certain cybersecurity incidents that meet established reporting thresholds are escalated within the Company and, where appropriate, reported to the Audit Committee through ongoing updates until resolution.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true