|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Mar. 01, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
We recognize the critical importance of maintaining the confidentiality, integrity and availability of our information systems and data, and of effectively assessing, identifying and managing cybersecurity and related risks. Our cybersecurity risk management program is integrated into our Enterprise Risk Management framework and utilizes a holistic approach to addressing cybersecurity risk. It is supported by our employees, cybersecurity team, senior management, the Enterprise Risk Management committee, and our Board of Directors (Board). The underlying controls for the cybersecurity risk management program are based on recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology and the Center for Internet Security Benchmark.
Our cybersecurity risk management program includes an incident response plan for evaluation, response and reporting of cybersecurity incidents, including notification of the Board and third parties, as appropriate. Under the plan, a Cybersecurity
Intake Team, which is comprised of the Chief Information Officer (CIO), Senior Director of Information Security (SDIS) and other executive management, is responsible for a materiality assessment of cybersecurity incidents, taking into consideration both quantitative and qualitative factors, and subject to ongoing monitoring and escalation based on materiality.
Third party vendors and suppliers also play a role in our cybersecurity risk management program. In circumstances where such third parties will access our systems and data, our SDIS participates in the vendor management process, including the review of contractual requirements and contractually imposing obligations on the vendor to report cybersecurity incidents to us so that we can assess the impact.
In addition to the incident response plan and vendor management process, our cybersecurity risk management program includes:
•an information technology and cybersecurity training program, and ongoing employee testing to evaluate the effectiveness of quarterly internal training and awareness communications;
•external advisors to assist with cybersecurity risk assessment, including third-party monitoring of the Company's systems, external network penetration testing, and yearly cyber event preparedness exercises;
•development of strategies to mitigate cyber risks; and,
•crisis management, business continuity, and disaster recovery plans.
We have not encountered cybersecurity incidents or identified risks from cybersecurity threats that have had a material adverse effect or are reasonably likely to have a material effect on our business strategy, operations or financial condition.
Notwithstanding the efforts we take to manage our cybersecurity risk, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. While the Company maintains cybersecurity insurance, the costs related to cybersecurity threats or disruptions may not be fully insured. See Item 1A. “Risk Factors” for a discussion of cybersecurity risks.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Third party vendors and suppliers also play a role in our cybersecurity risk management program. In circumstances where such third parties will access our systems and data, our SDIS participates in the vendor management process, including the review of contractual requirements and contractually imposing obligations on the vendor to report cybersecurity incidents to us so that we can assess the impact.
In addition to the incident response plan and vendor management process, our cybersecurity risk management program includes:
•an information technology and cybersecurity training program, and ongoing employee testing to evaluate the effectiveness of quarterly internal training and awareness communications;
•external advisors to assist with cybersecurity risk assessment, including third-party monitoring of the Company's systems, external network penetration testing, and yearly cyber event preparedness exercises;
•development of strategies to mitigate cyber risks; and,
•crisis management, business continuity, and disaster recovery plans.
We have not encountered cybersecurity incidents or identified risks from cybersecurity threats that have had a material adverse effect or are reasonably likely to have a material effect on our business strategy, operations or financial condition.
Notwithstanding the efforts we take to manage our cybersecurity risk, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. While the Company maintains cybersecurity insurance, the costs related to cybersecurity threats or disruptions may not be fully insured. See Item 1A. “Risk Factors” for a discussion of cybersecurity risks.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Management's Role in Managing Risk
Within our organization, our CIO, who reports to our CEO, oversees cybersecurity. Our SDIS reports to our CIO and is generally responsible for management of cybersecurity risk and the protection and defense of our network and systems, including the development and management of policies and processes to identify, contain, and investigate potential incidents and ensure recovery therefrom. Our SDIS has over 15 years of experience managing information technology and cybersecurity matters in multiple industries. The SDIS maintains Certified Information Systems Security Professional and Certified Information Security Manager certifications and holds a degree in information technology management.
Board's Role in Oversight
Our Board oversees our cybersecurity risk management program, and includes cybersecurity as part of the assessment of the Company's overall Enterprise Risk Management program. At least twice per year, and more frequently, if necessary, our CIO updates our Board on the Company's cyber risk profile and the steps taken by management to mitigate those risks. In the event of a material cybersecurity incident, the Board would receive prompt and timely information regarding the incident, as well as ongoing updates regarding such incident until it has been addressed. Cybersecurity-related risks are included in the Enterprise Risk Management committee’s evaluation of top risks to the enterprise, which are also presented to the Board and executive management twice per year.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Within our organization, our CIO, who reports to our CEO, oversees cybersecurity. Our SDIS reports to our CIO and is generally responsible for management of cybersecurity risk and the protection and defense of our network and systems, including the development and management of policies and processes to identify, contain, and investigate potential incidents and ensure recovery therefrom.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|At least twice per year, and more frequently, if necessary, our CIO updates our Board on the Company's cyber risk profile and the steps taken by management to mitigate those risks.
|Cybersecurity Risk Role of Management [Text Block]
|The underlying controls for the cybersecurity risk management program are based on recognized best practices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology and the Center for Internet Security Benchmark.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Within our organization, our CIO, who reports to our CEO, oversees cybersecurity. Our SDIS reports to our CIO and is generally responsible for management of cybersecurity risk and the protection and defense of our network and systems, including the development and management of policies and processes to identify, contain, and investigate potential incidents and ensure recovery therefrom.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our SDIS has over 15 years of experience managing information technology and cybersecurity matters in multiple industries. The SDIS maintains Certified Information Systems Security Professional and Certified Information Security Manager certifications and holds a degree in information technology management.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|At least twice per year, and more frequently, if necessary, our CIO updates our Board on the Company's cyber risk profile and the steps taken by management to mitigate those risks. In the event of a material cybersecurity incident, the Board would receive prompt and timely information regarding the incident, as well as ongoing updates regarding such incident until it has been addressed. Cybersecurity-related risks are included in the Enterprise Risk Management committee’s evaluation of top risks to the enterprise, which are also presented to the Board and executive management twice per year.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef