v3.26.1
Cybersecurity Risk Management, Strategy, and Governance Disclosure
12 Months Ended
May 31, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Item 1C. — Cybersecurity

 

Risk Management and Strategy

 

We actively maintain an enterprise risk management program that includes information technology and cybersecurity risk management. Management’s role is to identify, mitigate, guide and review the efforts of our business units, consider whether the residual risks are acceptable, and approve plans to address potentially material risks. Cybersecurity is a key risk management category within our enterprise risk management program.

 

We maintain processes designed to assess, identify and manage material risks from cybersecurity threats to our information, information systems, manufacturing operations and business processes. Our cybersecurity program is designed to safeguard against an evolving threat landscape through effective identification, prevention, detection, response and recovery processes. Our cybersecurity risk management processes include frequent assessment of our top cybersecurity risks and mitigations. We have a comprehensive cybersecurity program which includes risk management designed to protect the confidentiality, integrity and availability of our information systems and maintain compliance.

 

Our cybersecurity and risk management program encompasses several key areas consisting of threat and vulnerability management that help to identify, prioritize and reduce cybersecurity gaps or weaknesses. We regularly educate and share best practices with our employees to raise awareness of cybersecurity threats creating a culture where everyone shares responsibility to help protect our sensitive data and information. All employees are regularly provided cybersecurity training and involved in phishing prevention campaigns to raise awareness. Our identity and access management program involves access controls for least privileged access and additional authentication methods.

 

We use cybersecurity technologies and internal and third-party security operations capabilities to monitor for, detect and respond to potential unauthorized activity. These capabilities include, among other things, firewalls, intrusion detection systems, endpoint protection, continuous monitoring and other security tools. Our threat and vulnerability management processes may include vulnerability scanning, penetration testing, patch management, risk-based remediation tracking and periodic testing by independent third parties. Given the nature of our manufacturing operations, our cybersecurity risk management processes also consider risks to operational technology, manufacturing systems, business continuity, production availability and supply chain operations.

 

Our incident response process includes procedures for escalating cybersecurity events to appropriate members of management, including information technology, cybersecurity, legal, finance, internal audit, risk management and other business leaders, as appropriate. Depending on the nature and significance of an event, the process also provides for escalation to executive management, the Audit Committee and the Board, and for consideration of disclosure, regulatory, law enforcement, customer, supplier or other external notification obligations. Incident response exercises are performed using our response and ransomware playbooks to support our readiness to respond to cybersecurity events.

 

We have a risk management program for critical third-party vendors and service providers that is designed to identify and assess cybersecurity risks from external sources. This program may include review of vendors, suppliers, cloud-based platforms, SaaS providers and other service providers that access, process or store company data or support critical business processes. These processes may include security questionnaires, contractual security requirements, review of System and Organization Controls reports or other independent assurance reports, access reviews and ongoing monitoring based on the nature and risk profile of the relationship.

We maintain an AI governance process designed to evaluate proposed AI use cases, including potential cybersecurity, privacy, data protection, intellectual property, legal and compliance risks. This process includes review of certain AI technologies before deployment and consideration of safeguards related to sensitive Company information and third-party AI tools.

 

Our cybersecurity program’s effectiveness is based on recognized best practices, standards, and frameworks for cybersecurity and information technology, including periodic evaluation against established quantifiable goals and other external benchmarks, including the Center for Internet Security, the National Institute of Standards and Technology and several other security frameworks. The evaluation is conducted through periodic internal and external risk assessments and compliance audits. We regularly engage third parties in order to help conduct evaluations and assessments and to advise us on the effectiveness of our cybersecurity program.

 

Governance

 

The Audit Committee has primary responsibility for oversight of cybersecurity matters. The Audit Committee receives quarterly updates on compliance and cybersecurity from the CIO and CISO. These updates cover a range of topics, including the performance of our cybersecurity program against established goals and external standards, insights into the evolving cybersecurity landscape, current events and recent cybersecurity threats, and enhancements to our cybersecurity program.

 

The CIO has extensive leadership experience spanning 25 years in the areas of information technology, project management, and business applications, including within manufacturing environments. The CISO is responsible for overseeing our cybersecurity risk management program, in coordination with the CIO and our other business leaders, including in the legal, internal audit, finance and risk management departments. The CISO has extensive cybersecurity knowledge and skills gained from over 25 years of technical and business experience in the cybersecurity and information security fields. The CISO reports directly to the CIO who in turn reports directly to the CEO. The CISO receives reports from a variety of sources on cybersecurity threats on an ongoing basis and, regularly reviews risks to identify and mitigate data protection and cybersecurity risks. The CISO and CIO also work closely with our legal department to oversee compliance with applicable legal, regulatory and contractual security requirements.

 

Management's cybersecurity governance includes cross-functional participation from cybersecurity, information technology, legal, finance, internal audit, risk management and business leadership. This cross-functional process supports assessment of cybersecurity risks, prioritization of remediation activities, review of significant incidents and consideration of potential disclosure implications. During fiscal 2026, the risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected, and are not reasonably likely to materially affect us or our strategy, results of operations or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident. It is possible that we may not implement appropriate controls if we do not detect a particular risk. In addition, security controls, no matter how well designed or implemented, may only mitigate and not fully eliminate the risks. Even when a risk is detected, disruptive events may not always be immediately and thoroughly interpreted and acted upon.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

We maintain processes designed to assess, identify and manage material risks from cybersecurity threats to our information, information systems, manufacturing operations and business processes. Our cybersecurity program is designed to safeguard against an evolving threat landscape through effective identification, prevention, detection, response and recovery processes. Our cybersecurity risk management processes include frequent assessment of our top cybersecurity risks and mitigations. We have a comprehensive cybersecurity program which includes risk management designed to protect the confidentiality, integrity and availability of our information systems and maintain compliance.

 

Our cybersecurity and risk management program encompasses several key areas consisting of threat and vulnerability management that help to identify, prioritize and reduce cybersecurity gaps or weaknesses. We regularly educate and share best practices with our employees to raise awareness of cybersecurity threats creating a culture where everyone shares responsibility to help protect our sensitive data and information. All employees are regularly provided cybersecurity training and involved in phishing prevention campaigns to raise awareness. Our identity and access management program involves access controls for least privileged access and additional authentication methods.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]

The Audit Committee has primary responsibility for oversight of cybersecurity matters. The Audit Committee receives quarterly updates on compliance and cybersecurity from the CIO and CISO. These updates cover a range of topics, including the performance of our cybersecurity program against established goals and external standards, insights into the evolving cybersecurity landscape, current events and recent cybersecurity threats, and enhancements to our cybersecurity program.

Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee receives quarterly updates on compliance and cybersecurity from the CIO and CISO. These updates cover a range of topics, including the performance of our cybersecurity program against established goals and external standards, insights into the evolving cybersecurity landscape, current events and recent cybersecurity threats, and enhancements to our cybersecurity program.
Cybersecurity Risk Role of Management [Text Block] Management’s role is to identify, mitigate, guide and review the efforts of our business units, consider whether the residual risks are acceptable, and approve plans to address potentially material risks. Cybersecurity is a key risk management category within our enterprise risk management program.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The CISO is responsible for overseeing our cybersecurity risk management program, in coordination with the CIO and our other business leaders, including in the legal, internal audit, finance and risk management departments.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The CIO has extensive leadership experience spanning 25 years in the areas of information technology, project management, and business applications, including within manufacturing environments.The CISO has extensive cybersecurity knowledge and skills gained from over 25 years of technical and business experience in the cybersecurity and information security fields.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The CISO reports directly to the CIO who in turn reports directly to the CEO. The CISO receives reports from a variety of sources on cybersecurity threats on an ongoing basis and, regularly reviews risks to identify and mitigate data protection and cybersecurity risks. The CISO and CIO also work closely with our legal department to oversee compliance with applicable legal, regulatory and contractual security requirements.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true