|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Oct. 04, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
We rely on information systems and the data stored on them to conduct our operations. We have adopted and maintain a cybersecurity risk management program, as a subset of our broader enterprise risk management program, which is designed in accordance with our risk profile and business. Our cybersecurity practices are aligned with standard industry frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, International Organization for Standardization (ISO) 27001, Center for Internet Security Critical Security Controls and other industry standards.
Our cybersecurity risk management program incorporates multiple components, including, but not limited to, policies, guidelines, procedures, infrastructure, and systems that are designed to protect the confidentiality, integrity and availability of our critical systems and information.
Elements of our cybersecurity risk management process include, but are not limited to, the following:
•Annual cybersecurity risk assessments of critical infrastructure and systems;
•Annual vulnerability scans and penetration testing;
•Mandatory, bi-annual cybersecurity awareness training for all employees, including phishing exercises; and
•An overarching written information security policy and written cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
We leverage IT service providers to perform penetration testing and support our cybersecurity awareness training program. We oversee cybersecurity risks related to third-party IT cloud service providers who have access to our systems and data. We require certain IT cloud service providers to complete cloud-based cybersecurity assessments.
We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, we and our third-party vendors have from time to time experienced cybersecurity threats and other security incidents that have affected our information or systems. We have experienced, and expect to continue to be subject to, cybersecurity threats and incidents, ranging from employee error or misuse to individual attempts to gain unauthorized access to information systems, to sophisticated and targeted measures known as advanced persistent threats, none of which have been material to the Company to date.
For additional information on certain risks associated with cybersecurity, including with respect to prior cybersecurity incidents, please refer to “We may be subject to disruptions or failures in our information technology systems and network infrastructures that could have a material adverse effect on us” in Item 1A: Risk Factors.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We rely on information systems and the data stored on them to conduct our operations. We have adopted and maintain a cybersecurity risk management program, as a subset of our broader enterprise risk management program, which is designed in accordance with our risk profile and business. Our cybersecurity practices are aligned with standard industry frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, International Organization for Standardization (ISO) 27001, Center for Internet Security Critical Security Controls and other industry standards.
Our cybersecurity risk management program incorporates multiple components, including, but not limited to, policies, guidelines, procedures, infrastructure, and systems that are designed to protect the confidentiality, integrity and availability of our critical systems and information.
Elements of our cybersecurity risk management process include, but are not limited to, the following:
•Annual cybersecurity risk assessments of critical infrastructure and systems;
•Annual vulnerability scans and penetration testing;
•Mandatory, bi-annual cybersecurity awareness training for all employees, including phishing exercises; and
•An overarching written information security policy and written cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance
Our Board of Directors (the “Board”) has delegated responsibility for enterprise risk management, including cybersecurity risk oversight, to our Audit Committee (the “Committee”). The Committee receives quarterly information security updates from our Chief Financial Officer and Senior Director of Governance & Information Security (the “Senior Director, GIS”). The Committee in turn reports to the full Board regarding its activities, including those related to cybersecurity, on at least a bi-annual basis.
The Senior Director, GIS, who has been a head of information security for close to 15 years and has more than 27 years of overall experience in IT and cyber security industry, holds a Bachelor of Science in Information Technology from Bina Nusantara University and Master of Business Administration from University of Liverpool.
He receives support from our operational team which comprises cybersecurity, IT, controllership, and legal professionals who regularly review cybersecurity matters and evaluate emerging threats, as well as act as first responders to triage any cybersecurity incidents. In the event of a cybersecurity incident, the Committee and Board receive updates from this team on an ad-hoc basis, if appropriate, under our tiered escalation support framework.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee (the “Committee”)
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Committee receives quarterly information security updates from our Chief Financial Officer and Senior Director of Governance & Information Security (the “Senior Director, GIS”). The Committee in turn reports to the full Board regarding its activities, including those related to cybersecurity, on at least a bi-annual basis.
|Cybersecurity Risk Role of Management [Text Block]
|
The Senior Director, GIS, who has been a head of information security for close to 15 years and has more than 27 years of overall experience in IT and cyber security industry, holds a Bachelor of Science in Information Technology from Bina Nusantara University and Master of Business Administration from University of Liverpool.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
The Senior Director, GIS, who has been a head of information security for close to 15 years and has more than 27 years of overall experience in IT and cyber security industry, holds a Bachelor of Science in Information Technology from Bina Nusantara University and Master of Business Administration from University of Liverpool.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
The Senior Director, GIS, who has been a head of information security for close to 15 years and has more than 27 years of overall experience in IT and cyber security industry, holds a Bachelor of Science in Information Technology from Bina Nusantara University and Master of Business Administration from University of Liverpool.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|In the event of a cybersecurity incident, the Committee and Board receive updates from this team on an ad-hoc basis, if appropriate, under our tiered escalation support framework.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef