|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Feb. 01, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity risk management and strategy
We use information technology and third-party service providers to support our global business processes and activities, which exposes us to cybersecurity risks.
Key Program Components
To help manage cybersecurity risk, the Company uses cybersecurity frameworks and standards as a guide, such as the National Institute of Standards and Technology's Cybersecurity Framework, International Organization of Standardization ISO/IEC 27002, and Payment Card Industry (PCI) Security Standards. We use, and continue to improve, our cyber defense-in-depth strategy, which uses multiple layers of security for holistic protection.
Our cybersecurity risk managementincludes:
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|To help manage cybersecurity risk, the Company uses cybersecurity frameworks and standards as a guide, such as the National Institute of Standards and Technology's Cybersecurity Framework, International Organization of Standardization ISO/IEC 27002, and Payment Card Industry (PCI) Security Standards. We use, and continue to improve, our cyber defense-in-depth strategy, which uses multiple layers of security for holistic protection.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|The Company regularly updates and assesses its information security strategy and responses for new and emerging threats. To date, the Company is not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected, or are reasonably likely to materially affect, the Company's business strategy, results of operations or financial position. Notwithstanding the breadth of the Company's information security program, it may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse impact. Also see "Risks Related to Technology, Data Security, and Privacy" included as part of Item 1A. "Risk Factors," which is incorporated by reference herein.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance
The Board of Directors has risk oversight responsibility regarding risks that could affect the Company. Oversight for certain risks is administered through committees of the Board. The Audit Committee of the Board is responsible for oversight over our enterprise risk management framework. Cybersecurity risk is included in our enterprise risk management program.
The Technology and Digital Engagement Committee of the Board has primary responsibility for oversight of the Company's cybersecurity risk. This Committee receives regular briefings from our Chief Operations Officer, Chief Technology Officer, Chief Information Security Officer, and outside experts on cybersecurity risks and cyber risk oversight. During these meetings, the Technology and Digital Engagement Committee and management discuss cybersecurity risks, risk management activities and efforts, best practices, the effectiveness of our security measures, and other related matters. The Technology and Digital Engagement Committee Chair reports on the committee's meetings, considerations, and actions to the Board at the next Board meeting following each committee meeting. The Audit Committee also discusses and receives updates on cybersecurity matters in connection with its oversight of enterprise risk management.
We maintain a security incident response plan that is utilized when cybersecurity incidents are detected. We conduct periodic tabletop exercises, in which different internal and external stakeholders, including from time to time our CEO, Non-Executive Chair, or Board of Directors, participate in a simulated cyber scenario. The purpose of these exercises is to test our security incident response plan, identify weaknesses or gaps, and ensure that all participants are aware of, and familiar with, their roles and responsibilities.
Our Chief Information Security Officer, with oversight from the Chief Technology Officer and Chief Operations Officer, is primarily responsible for assessing and managing cybersecurity risks. Our Chief Information Security Officer has extensive cybersecurity knowledge and skills gained from over 25 years' experience in the field. He holds a Certified Information Systems Security Professional certification, issued by ISC, which is a globally recognized credential demonstrating expertise in information security and risk management. Our Chief Information Security Officer stays up to date on developments in cybersecurity, including potential threats and innovative risk management techniques. This ongoing knowledge acquisition also informs our program of prevention, detection, mitigation, and remediation of cybersecurity incidents.
Several experienced information security professionals report to our Chief Information Security Officer and he is supported by a team of trained cybersecurity team members. In addition to our in-house cybersecurity capabilities, at times we also engage assessors, consultants, auditors, or other third parties to assist with assessing, identifying, and managing cybersecurity risks.
The Company regularly updates and assesses its information security strategy and responses for new and emerging threats. To date, the Company is not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected, or are reasonably likely to materially affect, the Company's business strategy, results of operations or financial position. Notwithstanding the breadth of the Company's information security program, it may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse impact. Also see "Risks Related to Technology, Data Security, and Privacy" included as part of Item 1A. "Risk Factors," which is incorporated by reference herein.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Board of Directors has risk oversight responsibility regarding risks that could affect the Company. Oversight for certain risks is administered through committees of the Board. The Audit Committee of the Board is responsible for oversight over our enterprise risk management framework. Cybersecurity risk is included in our enterprise risk management program.
|Cybersecurity Risk Role of Management [Text Block]
|The Technology and Digital Engagement Committee of the Board has primary responsibility for oversight of the Company's cybersecurity risk. This Committee receives regular briefings from our Chief Operations Officer, Chief Technology Officer, Chief Information Security Officer, and outside experts on cybersecurity risks and cyber risk oversight. During these meetings, the Technology and Digital Engagement Committee and management discuss cybersecurity risks, risk management activities and efforts, best practices, the effectiveness of our security measures, and other related matters. The Technology and Digital Engagement Committee Chair reports on the committee's meetings, considerations, and actions to the Board at the next Board meeting following each committee meeting. The Audit Committee also discusses and receives updates on cybersecurity matters in connection with its oversight of enterprise risk management.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our Chief Information Security Officer, with oversight from the Chief Technology Officer and Chief Operations Officer, is primarily responsible for assessing and managing cybersecurity risks. Our Chief Information Security Officer has extensive cybersecurity knowledge and skills gained from over 25 years' experience in the field. He holds a Certified Information Systems Security Professional certification, issued by ISC, which is a globally recognized credential demonstrating expertise in information security and risk management. Our Chief Information Security Officer stays up to date on developments in cybersecurity, including potential threats and innovative risk management techniques. This ongoing knowledge acquisition also informs our program of prevention, detection, mitigation, and remediation of cybersecurity incidents.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef