v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
May 31, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Our ability to attract and retain customers, efficiently operate our businesses, and compete effectively increasingly depends in part upon the sophistication, security, and reliability of our technology network, including our ability to provide features of service that are important to our customers, to protect our confidential business information and the information provided by our customers, and to maintain customer confidence in our ability to protect our systems and to provide services consistent with their expectations.
Cybersecurity Risk Management and Strategy
FedEx Freight has an information technology (“IT”) risk management process designed to identify and manage risk within its IT environment, including cybersecurity. The IT risk management process is based on an established framework for identification, measurement, and monitoring of cybersecurity and other risk areas and supplements our Enterprise Risk Management (“ERM”) process and framework. Our IT risk management, ERM, and compliance teams collaborate to regularly evaluate and manage cybersecurity-related risks using various tools and services. Leveraging components from multiple industry frameworks and best practices such as the International Organization for Standardization (“ISO”) 27001 and National Institute of Standards and Technology (“NIST”) standards, including the NIST Cybersecurity Framework, our cybersecurity program prioritizes governance, identification, protection, detection, response, and remediation measures.
As we move forward following the Spin-Off, we will regularly assess our cybersecurity program’s capabilities and tools to help us enhance reliability and evaluate our environment for vulnerabilities. Our IT risk management team, including our Vice President — Chief Information Security Officer (“CISO”), communicates with senior management on the cybersecurity risk posture of our IT assets and strives to ensure consistent risk remediation activities. In addition, our internal audit team monitors the effectiveness of our IT-related controls and performs reviews of our information security organization to help ensure controls are operating effectively and as designed.
Company-wide information security training (including with respect to cybersecurity), supplemented by awareness programs, is crucial for risk reduction and safeguarding customer, employee, and Company information. We provide training to employees based on access to our network, risk, roles, policies, standards, and behaviors, which is updated to address emerging technology and security issues.
We will periodically engage with assessors, consultants, auditors, and other third parties to review and improve our cybersecurity program. In connection with the Spin-Off, we have also entered into the Transition Services Agreement and related agreements with FedEx under which FedEx provides, and we rely on FedEx for, certain IT and cybersecurity functions during the transition period. Compliance with regulatory requirements involves regular third-party assessments. Our processes are also designed to address cybersecurity risks associated with third-party service providers, including risk assessment and due diligence during selection and
oversight. Key third parties will undergo regular assessments to gauge cybersecurity control effectiveness, with heightened review of those with access to non-public data.
We will regularly conduct table-top simulation exercises to test our cybersecurity incident response processes with the aim of enhancing effectiveness against evolving threats. Our incident response procedures guide our preparedness, detection, response, and recovery actions.
While we have significant security processes and initiatives in place, we may be unable to detect or prevent a breach or disruption in the future. For more information about cybersecurity-related risks, please see Item 1A. “Risk Factors” of this Annual Report.
Since the Spin-Off and as of the date of this Annual Report, we have not identified any risks from cybersecurity threats or become aware of any cybersecurity incidents, including any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] FedEx Freight has an information technology (“IT”) risk management process designed to identify and manage risk within its IT environment, including cybersecurity. The IT risk management process is based on an established framework for identification, measurement, and monitoring of cybersecurity and other risk areas and supplements our Enterprise Risk Management (“ERM”) process and framework. Our IT risk management, ERM, and compliance teams collaborate to regularly evaluate and manage cybersecurity-related risks using various tools and services. Leveraging components from multiple industry frameworks and best practices such as the International Organization for Standardization (“ISO”) 27001 and National Institute of Standards and Technology (“NIST”) standards, including the NIST Cybersecurity Framework, our cybersecurity program prioritizes governance, identification, protection, detection, response, and remediation measures.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Cybersecurity Governance
The Board has delegated to its Risk Oversight Committee (the “ROC”) responsibility for overseeing the Company’s cyber and technology-related risks, including network security, information and digital security, data privacy and protection, and risks related to emerging technologies such as AI and machine learning; the technologies, policies, processes, and practices for managing and mitigating such risks; and the Company’s cyber incident response and recovery plan. The ROC also oversees the cybersecurity, cyber-resiliency, and technology aspects of the Company’s business continuity and disaster recovery capabilities and contingency plans.
Following the Spin-Off, the ROC will receive regular updates from our CISO and other members of management on risks related to these matters. Specific topics may include updates to FedEx Freight’s cyber risks and threats, the status of existing or new strategies and associated projects intended to strengthen FedEx Freight’s information security systems, assessments of FedEx Freight’s cybersecurity program, risks associated with third-party service providers, and the emerging threat landscape. The ROC also will receive regular updates on key metrics related to our cybersecurity-related risks. The results of the IT risk management process will also be presented at least annually to the ROC. Additionally, members of the ROC will participate in certain of the future simulation exercises conducted by management. The Chair of the ROC will brief the full Board on certain of these matters. Separately, through our ERM program, key enterprise risks, including with respect to cybersecurity, will be communicated to the Board and its Audit Committee (the “Audit Committee”) at least annually, and any significant changes to these risks will be reported to the Board and its Audit Committee.
Our CISO, who reports to the Executive Vice President — Chief Technology Officer, leads our information security team and has management responsibility for overseeing FedEx Freight’s cybersecurity program, including assessing and managing material risks from cybersecurity threats. Our CISO has more than 25 years of experience in information security, governance, risk management, compliance, and cybersecurity operations. Prior to his current role, he held leadership positions across the transportation, consulting, telecommunications, retail, and energy industries, where he was responsible for enterprise technology, security, and risk management functions. The CISO oversees an information security organization of more than 50 security, risk, and compliance professionals across FedEx Freight. The leadership team of our information security organization has extensive experience in IT and cybersecurity and possesses certifications in cybersecurity and related fields.
Our CISO oversees the execution of our comprehensive IT risk management program. In this capacity, the CISO receives periodic updates on FedEx Freight’s IT risk profile and is responsible for assessing the overall risk framework, evaluating risk prioritization efforts and associated risk mitigation activities, as well as monitoring the evolving risk landscape and posture. FedEx Freight is in the process of formalizing an IT Risk Management Committee, which is expected to be established by the end of the year to further enhance governance and oversight.
Our Executive Leadership Team, of which our Executive Vice President — Chief Technology Officer is a member, oversees our business risk, with cybersecurity threat risks being a regular topic of discussion. Our cybersecurity incident response plan includes processes for communicating cybersecurity incidents to relevant levels of management, including the Executive Leadership Team, the ROC, and the full Board of Directors, as appropriate, and consideration of external reporting and disclosure requirements.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board has delegated to its Risk Oversight Committee (the “ROC”) responsibility for overseeing the Company’s cyber and technology-related risks, including network security, information and digital security, data privacy and protection, and risks related to emerging technologies such as AI and machine learning; the technologies, policies, processes, and practices for managing and mitigating such risks; and the Company’s cyber incident response and recovery plan. The ROC also oversees the cybersecurity, cyber-resiliency, and technology aspects of the Company’s business continuity and disaster recovery capabilities and contingency plans.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board has delegated to its Risk Oversight Committee (the “ROC”) responsibility for overseeing the Company’s cyber and technology-related risks, including network security, information and digital security, data privacy and protection, and risks related to emerging technologies such as AI and machine learning; the technologies, policies, processes, and practices for managing and mitigating such risks; and the Company’s cyber incident response and recovery plan. The ROC also oversees the cybersecurity, cyber-resiliency, and technology aspects of the Company’s business continuity and disaster recovery capabilities and contingency plans.
Cybersecurity Risk Role of Management [Text Block] the ROC will receive regular updates from our CISO and other members of management on risks related to these matters. Specific topics may include updates to FedEx Freight’s cyber risks and threats, the status of existing or new strategies and associated projects intended to strengthen FedEx Freight’s information security systems, assessments of FedEx Freight’s cybersecurity program, risks associated with third-party service providers, and the emerging threat landscape. The ROC also will receive regular updates on key metrics related to our cybersecurity-related risks. The results of the IT risk management process will also be presented at least annually to the ROC. Additionally, members of the ROC will participate in certain of the future simulation exercises conducted by management. The Chair of the ROC will brief the full Board on certain of these matters. Separately, through our ERM program, key enterprise risks, including with respect to cybersecurity, will be communicated to the Board and its Audit Committee (the “Audit Committee”) at least annually, and any significant changes to these risks will be reported to the Board and its Audit Committee.
Our CISO, who reports to the Executive Vice President — Chief Technology Officer, leads our information security team and has management responsibility for overseeing FedEx Freight’s cybersecurity program, including assessing and managing material risks from cybersecurity threats. Our CISO has more than 25 years of experience in information security, governance, risk management, compliance, and cybersecurity operations. Prior to his current role, he held leadership positions across the transportation, consulting, telecommunications, retail, and energy industries, where he was responsible for enterprise technology, security, and risk management functions. The CISO oversees an information security organization of more than 50 security, risk, and compliance professionals across FedEx Freight. The leadership team of our information security organization has extensive experience in IT and cybersecurity and possesses certifications in cybersecurity and related fields.
Our CISO oversees the execution of our comprehensive IT risk management program. In this capacity, the CISO receives periodic updates on FedEx Freight’s IT risk profile and is responsible for assessing the overall risk framework, evaluating risk prioritization efforts and associated risk mitigation activities, as well as monitoring the evolving risk landscape and posture. FedEx Freight is in the process of formalizing an IT Risk Management Committee, which is expected to be established by the end of the year to further enhance governance and oversight.
Our Executive Leadership Team, of which our Executive Vice President — Chief Technology Officer is a member, oversees our business risk, with cybersecurity threat risks being a regular topic of discussion. Our cybersecurity incident response plan includes processes for communicating cybersecurity incidents to relevant levels of management, including the Executive Leadership Team, the ROC, and the full Board of Directors, as appropriate, and consideration of external reporting and disclosure requirements.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] the ROC will receive regular updates from our CISO and other members of management on risks related to these matters.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The CISO oversees an information security organization of more than 50 security, risk, and compliance professionals across FedEx Freight. The leadership team of our information security organization has extensive experience in IT and cybersecurity and possesses certifications in cybersecurity and related fields.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] the ROC will receive regular updates from our CISO and other members of management on risks related to these matters. Specific topics may include updates to FedEx Freight’s cyber risks and threats, the status of existing or new strategies and associated projects intended to strengthen FedEx Freight’s information security systems, assessments of FedEx Freight’s cybersecurity program, risks associated with third-party service providers, and the emerging threat landscape. The ROC also will receive regular updates on key metrics related to our cybersecurity-related risks. The results of the IT risk management process will also be presented at least annually to the ROC. Additionally, members of the ROC will participate in certain of the future simulation exercises conducted by management. The Chair of the ROC will brief the full Board on certain of these matters. Separately, through our ERM program, key enterprise risks, including with respect to cybersecurity, will be communicated to the Board and its Audit Committee (the “Audit Committee”) at least annually, and any significant changes to these risks will be reported to the Board and its Audit Committee.
Our CISO, who reports to the Executive Vice President — Chief Technology Officer, leads our information security team and has management responsibility for overseeing FedEx Freight’s cybersecurity program, including assessing and managing material risks from cybersecurity threats. Our CISO has more than 25 years of experience in information security, governance, risk management, compliance, and cybersecurity operations. Prior to his current role, he held leadership positions across the transportation, consulting, telecommunications, retail, and energy industries, where he was responsible for enterprise technology, security, and risk management functions. The CISO oversees an information security organization of more than 50 security, risk, and compliance professionals across FedEx Freight. The leadership team of our information security organization has extensive experience in IT and cybersecurity and possesses certifications in cybersecurity and related fields.
Our CISO oversees the execution of our comprehensive IT risk management program. In this capacity, the CISO receives periodic updates on FedEx Freight’s IT risk profile and is responsible for assessing the overall risk framework, evaluating risk prioritization efforts and associated risk mitigation activities, as well as monitoring the evolving risk landscape and posture. FedEx Freight is in the process of formalizing an IT Risk Management Committee, which is expected to be established by the end of the year to further enhance governance and oversight.
Our Executive Leadership Team, of which our Executive Vice President — Chief Technology Officer is a member, oversees our business risk, with cybersecurity threat risks being a regular topic of discussion. Our cybersecurity incident response plan includes processes for communicating cybersecurity incidents to relevant levels of management, including the Executive Leadership Team, the ROC, and the full Board of Directors, as appropriate, and consideration of external reporting and disclosure requirements.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true