Expedia Group, Inc. 10-K Cybersecurity GRC - 2024-02-08

Page last updated on July 16, 2024

Expedia Group, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-02-08 17:40:40 EST.

Filings

10-K filed on 2024-02-08

Expedia Group, Inc. filed a 10-K at 2024-02-08 17:40:40 EST
Accession Number: 0001324424-24-000007

Item 1C. Cybersecurity.

The Company’s Board of Directors (the “Board”) recognizes that safeguarding the Company’s data, information systems, and technology assets is critical to maintaining the trust and confidence of the Company’s travelers, business partners and employees. The Board actively exercises oversight of the Company’s technological infrastructure, information security and its cybersecurity, which are key components of the Company’s risk management program. The Company’s cybersecurity policies, standards, processes and programs are integrated into its risk management program and are based on industry standard frameworks established by the National Institute of Standards and Technology (“NIST”) and the International Organization for Standardization, among others, as well as on evolving best practices.

Cybersecurity Risk Management and Strategy

The Company’s cybersecurity risk management program is composed of the following key elements:

To date, no risks from cybersecurity threats, including those resulting from any previous cybersecurity incidents, have materially adversely affected, or are reasonably likely to materially adversely affect, the Company, including its business strategy, results of operations or financial condition. Although the Company’s cybersecurity risk management program, as described above, is designed to help prevent, detect, respond to, and mitigate the impact of cybersecurity incidents, there is no guarantee that a future cybersecurity incident would not materially adversely affect the Company’s business strategy, results of operations or financial condition. For information regarding cybersecurity risks that the Company faces and potential impacts on its business related thereto, see the disclosure set forth in Part I, Item 1A, Risk Factors, under the caption “System interruption, security breaches and unplanned outages in our information systems may harm our businesses.”

Cybersecurity Governance

The Board, in coordination with the Audit Committee, oversees the Company’s risk management program, which includes risks arising from cybersecurity threats. The Audit Committee regularly receives presentations and reports from both Company management and third-parties, as appropriate, that address a wide range of topics related to cybersecurity risks, including evolving standards, third-party and independent reviews, threat environment updates, technology trends and information security considerations arising with respect to the Company’s peers and partners. The Company’s CSO and/or the Company’s CTO regularly meet with the Audit Committee (and, where appropriate, the full Board) to discuss technology, information security and cybersecurity programs, progress updates on the Company’s key cybersecurity initiatives and related priorities and controls. At least annually, the Audit Committee and the full Board receive a comprehensive written report covering the Company’s cybersecurity program and associated risks, and any changes made to the program since the previous report. Additionally, the Audit Committee is promptly apprised of any cybersecurity incident that meets established reporting thresholds, and receives ongoing updates regarding any such incident until it has been resolved. At each regularly scheduled Board meeting, the Audit Committee Chair provides the full Board with an update on all significant matters discussed, reviewed, considered and approved by the committee since the last regularly scheduled Board meeting.

The Company’s CSO, in coordination with the Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”), CTO, and Chief Legal Officer (“CLO”), works collaboratively across the Company to implement and monitor a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s cybersecurity incident response plan and its security policy. To facilitate the success of the Company’s cybersecurity risk management program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, the CSO, the CTO and other executive leadership team members are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report risks from cybersecurity threats and cybersecurity incidents to the Audit Committee when appropriate.

The CSO has extensive cybersecurity experience, having served in various roles in information technology and information security for over two decades. Before joining the Company, he served as the Chief Cybersecurity Officer of the U.S. division of a large, multinational company. Additionally, the CSO has played an active role in shaping public cybersecurity policy and standards. The CSO holds a Bachelor of Science in Computer Science and is a Certified Information Systems Security Professional (CISSP) and a Certified Information Systems Auditor. The Company’s CTO holds an undergraduate degree in electrical engineering and a master’s degree in computer engineering, and has held senior technology roles for over 25 years, including serving as either the CTO or Chief Information Officer of four public companies. The Company’s CEO, CFO and CLO each hold undergraduate and graduate degrees in their respective fields, and each have extensive experience managing risks at the Company and at similar companies, including risks arising from cybersecurity threats.


Company Information

NameExpedia Group, Inc.
CIK0001324424
SIC DescriptionTransportation Services
TickerEXPE - Nasdaq
Website
CategoryLarge accelerated filer
Fiscal Year EndDecember 30