XML 50 R34.htm IDEA: XBRL DOCUMENT v3.25.2
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jun. 30, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy
The Company maintains a comprehensive program and processes designed to assess, identify, evaluate and manage vulnerabilities to the Company’s business and operations, and other material risks from cybersecurity threats, as part of its overall Enterprise Risk Management (ERM) and cybersecurity risk management program and processes.
The Company’s cybersecurity risk management program includes the following features.
Leverages the National Institute of Standards and Technology (NIST) Cybersecurity and Zero Trust Architecture frameworks for managing cybersecurity risks;
Maintenance of security policies and standards, regular updates to response planning and protocols, and monitoring vulnerabilities, emerging threats and risks through industry information sharing channels and new technology;
A cybersecurity incident response plan designed to facilitate cross-functional coordination across the Company (including escalation based on the severity of the impact of an incident), mitigate brand and reputational damage, and comply with applicable legal obligations, which includes guidance to support the Company’s assessment of whether an incident is considered “material” for purposes of U.S. securities laws;
Executive and IT team tabletop exercises;
A cybersecurity insurance program to reimburse, up to policy limits, covered costs, losses and claims relating to a data or security breach;
Use of consultants, third-party service providers and information security firms to provide technology systems or support aspects of this program, conduct assessments of the Company's cybersecurity practices and penetration testing, and cybersecurity, risk management and legal experts;
A third-party vendor risk management process that utilizes a risk-based approach for vendors engaged through the Company’s procurement process; and
Cybersecurity awareness training for all employees who have access to Company email and connected devices, periodic phishing awareness simulations, and cybersecurity and phishing awareness content on the Company’s intranet site.
The Company’s business strategy, results of operations, and financial condition have been materially affected by our previously disclosed August 2023 cyberattack, and the Company is regularly subject to cyber threats, ransomware and other security breaches. See “Risk Factors” in Item 1A of this Annual Report on Form 10-K for more information on risks from cybersecurity threats that are reasonably likely to materially affect the Company’s business strategy, results of operations and financial condition.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company maintains a comprehensive program and processes designed to assess, identify, evaluate and manage vulnerabilities to the Company’s business and operations, and other material risks from cybersecurity threats, as part of its overall Enterprise Risk Management (ERM) and cybersecurity risk management program and processes.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] The Company’s business strategy, results of operations, and financial condition have been materially affected by our previously disclosed August 2023 cyberattack, and the Company is regularly subject to cyber threats, ransomware and other security breaches.
Cybersecurity Risk Board of Directors Oversight [Text Block]
Board of Directors
The Board, through the Audit Committee, is responsible for the oversight of the Company’s compliance with legal and regulatory requirements relating to data privacy, cybersecurity and IT risks and its framework and guidelines with respect to risk assessment and risk management. The Audit Committee receives quarterly updates on the topics set forth above from the CISIO, CIDO, and Chief Legal and External Affairs Officer.
The Board retains responsibility for the overall process of assessing and managing major risks facing the Company and receives updates regarding information security and cybersecurity risks as part of its oversight of ERM. The CIDO and Chief Legal and External Affairs Officer provide quarterly updates to the Board on topics that may include information security and cybersecurity matters. The Board may also be notified and engaged as part of the Company's cybersecurity incident response plans, depending on the severity of the impact of an incident. The Board and Audit Committee include directors with knowledge, skills and experience in data security, privacy, IT governance, and management of cyber risks.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board, through the Audit Committee, is responsible for the oversight of the Company’s compliance with legal and regulatory requirements relating to data privacy, cybersecurity and IT risks and its framework and guidelines with respect to risk assessment and risk management
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
The Board, through the Audit Committee, is responsible for the oversight of the Company’s compliance with legal and regulatory requirements relating to data privacy, cybersecurity and IT risks and its framework and guidelines with respect to risk assessment and risk management. The Audit Committee receives quarterly updates on the topics set forth above from the CISIO, CIDO, and Chief Legal and External Affairs Officer.
The Board retains responsibility for the overall process of assessing and managing major risks facing the Company and receives updates regarding information security and cybersecurity risks as part of its oversight of ERM. The CIDO and Chief Legal and External Affairs Officer provide quarterly updates to the Board on topics that may include information security and cybersecurity matters. The Board may also be notified and engaged as part of the Company's cybersecurity incident response plans, depending on the severity of the impact of an incident. The Board and Audit Committee include directors with knowledge, skills and experience in data security, privacy, IT governance, and management of cyber risks.
Cybersecurity Risk Role of Management [Text Block]
Management
The Chief Information Security and Infrastructure Officer (CISIO) is responsible for the Company’s cybersecurity risk management program. The CISIO oversees the Company’s technology risk management team. This team works in partnership with the legal, financial reporting controls and internal audit functions to review information technology-related internal controls with the Company’s independent auditors as part of the overall internal controls process.
The CISIO has IT and information security experience, including enterprise risk management leadership, and holds a Certified Information Security Manager certification from the Information Systems Audit and Control Association (ISACA). The CISIO reports to the Chief Information and Data Officer (CIDO), who is a member of the Clorox Executive Committee and reports directly to the CEO. The CIDO has experience overseeing and executing technology strategies and implementations in complex, global organizations. The CIDO has been in this role for the Company since June 2020 and has experience leading technology strategy in the consumer packaged goods, manufacturing and retail industries.
The Company has established the Clorox Information Security Executive Committee (CISEC) which oversees the information security strategy, policies and practices of the Company. The CISEC supports the Company’s objective of maintaining a strong cybersecurity posture and culture by overseeing alignment between the Company’s cybersecurity objectives and business goals, risk exposure, and compliance requirements. The CISEC is chaired by the CISIO and includes in its membership the CIDO and Chief Legal and External Affairs Officer, who are both members of the Clorox Executive Committee, as well as the Chief Accounting Officer and Controller and the Vice President, Internal Audit, among other management. The CISIO also provides
periodic reports to the Clorox Executive Committee and to the Audit Committee. These reports may include updates on critical information security and cybersecurity risks and the threat landscape; cybersecurity improvement initiatives, the internal control environment, ongoing internal audit activities; and, if relevant, the status of actions taken with respect to significant cybersecurity incidents
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Chief Information Security and Infrastructure Officer (CISIO) is responsible for the Company’s cybersecurity risk management program. The CISIO oversees the Company’s technology risk management team
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The CISIO has IT and information security experience, including enterprise risk management leadership, and holds a Certified Information Security Manager certification from the Information Systems Audit and Control Association (ISACA)
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The CISIO also provides periodic reports to the Clorox Executive Committee and to the Audit Committee. These reports may include updates on critical information security and cybersecurity risks and the threat landscape; cybersecurity improvement initiatives, the internal control environment, ongoing internal audit activities; and, if relevant, the status of actions taken with respect to significant cybersecurity incidents.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true