v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jun. 30, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We recognize the importance of assessing, identifying, and managing risks associated with cybersecurity threats. These risks include, among other things, operational risks; intellectual property theft; fraud; extortion; harm to employees or clients; violation of privacy or security laws and other litigation and legal risk; and reputational risks. Cybersecurity risk management is integrated into our enterprise risk management processes and is designed to enable the identification, assessment, monitoring, and mitigation of cybersecurity risks that could affect our business operations, clients, products, services, and technology infrastructure. Our cybersecurity risk management program aligns with industry best practices such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and the International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) ISO/IEC 27001 standard. This provides a framework for identifying, monitoring, evaluating, and
responding to cybersecurity threats and incidents, including those associated with the use of our software, applications, services, and cloud and hybrid infrastructures developed or provided by third-party vendors and service providers. Our framework includes steps for identifying the source of a cybersecurity threat or incident, assessing the severity and risk of a cybersecurity threat or incident, implementing cybersecurity mitigation or remediation strategies, and informing our management and our Board of material cybersecurity threats and incidents.
OpenText has a cross-functional incident response team, led by our cybersecurity team and comprised of representatives from our information technology, cybersecurity, finance, and legal teams. The cybersecurity team is primarily responsible for overseeing the cybersecurity risk management program and incident response processes, in coordination with other business functions. Our incident response plan includes processes and procedures for assessing potential internal and external threats, activation and notification, crisis management, and post-incident recovery designed to safeguard the confidentiality, availability, and integrity of the Company and our clients’ information assets. Our incident response and risk management processes include procedures for evaluating the materiality of cybersecurity incidents and determining appropriate escalation, reporting and disclosure obligations.
Our cybersecurity team is responsible for assessing our cybersecurity risk management program and our incident response plan. We have devoted significant financial and personnel resources to implement security measures to meet regulatory requirements and client expectations, and we intend to continue to make investments to maintain the security of the Company and its clients’ data and data management infrastructure. We maintain processes to assess cybersecurity and data protection risks associated with third-party vendors and service providers that have access to our systems, data or technology infrastructure. These assessments are incorporated into our broader third-party risk management activities. We review and update our cybersecurity policies, standards and procedures annually, or more frequently as needed, to account for changes in the threat landscape, as well as in response to legal and regulatory developments. Our internal audit department has a team responsible for IT and information security (including cybersecurity) audits. We engage independent third-party cybersecurity firms to perform assessments, penetration testing, program reviews and other evaluations designed to identify potential cybersecurity risks and areas for improvement. Our cybersecurity efforts also include mandatory training for all employees and contractors on OpenText’s security and privacy policies as well as other ancillary trainings on topics such as phishing emails and other social engineering tactics.
In Fiscal 2026, we did not identify any cybersecurity threats or incidents or risks of such incidents that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or incidents or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, see “Risk Factors—Risks Related to our Business and Industry” in this Annual Report on Form 10-K.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We recognize the importance of assessing, identifying, and managing risks associated with cybersecurity threats. These risks include, among other things, operational risks; intellectual property theft; fraud; extortion; harm to employees or clients; violation of privacy or security laws and other litigation and legal risk; and reputational risks. Cybersecurity risk management is integrated into our enterprise risk management processes and is designed to enable the identification, assessment, monitoring, and mitigation of cybersecurity risks that could affect our business operations, clients, products, services, and technology infrastructure. Our cybersecurity risk management program aligns with industry best practices such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and the International Organization for Standardization (ISO)/International Electro-technical Commission (IEC) ISO/IEC 27001 standard. This provides a framework for identifying, monitoring, evaluating, and
responding to cybersecurity threats and incidents, including those associated with the use of our software, applications, services, and cloud and hybrid infrastructures developed or provided by third-party vendors and service providers. Our framework includes steps for identifying the source of a cybersecurity threat or incident, assessing the severity and risk of a cybersecurity threat or incident, implementing cybersecurity mitigation or remediation strategies, and informing our management and our Board of material cybersecurity threats and incidents.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Our Board of Directors is responsible for monitoring and assessing the Company’s cybersecurity risk management as part of its overall responsibility of risk oversight. The Board’s Audit Committee is responsible for overseeing risks related to our accounting, financial statements and financial reporting process, including the Company’s cybersecurity incident materiality assessment and relevant disclosures. For more information, see Part III, Item 11, “Board’s Role in Risk Oversight.”
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The CISO is responsible for overseeing cybersecurity strategy, risk assessment, incident response, security operations, and cybersecurity governance activities.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The CISO receives regular information regarding cybersecurity threats, vulnerabilities, incidents, and risk mitigation efforts and provides management with reporting regarding the Company's cybersecurity risk posture.
The CISO reports to the Chief Digital Officer (CDO), who is responsible for the Company's broader information technology strategy and operations, including capabilities related to cybersecurity resilience, incident response, and business recovery. Management, including the CISO and CDO, periodically reports to the Audit Committee and the Board of Directors regarding cybersecurity risks, significant incidents, emerging threats, mitigation activities, and the overall effectiveness of the Company's cybersecurity program.
Cybersecurity Risk Role of Management [Text Block] The CISO is responsible for overseeing cybersecurity strategy, risk assessment, incident response, security operations, and cybersecurity governance activities. The CISO receives regular information regarding cybersecurity threats, vulnerabilities, incidents, and risk mitigation efforts and provides management with reporting regarding the Company's cybersecurity risk posture.
The CISO reports to the Chief Digital Officer (CDO), who is responsible for the Company's broader information technology strategy and operations, including capabilities related to cybersecurity resilience, incident response, and business recovery. Management, including the CISO and CDO, periodically reports to the Audit Committee and the Board of Directors regarding cybersecurity risks, significant incidents, emerging threats, mitigation activities, and the overall effectiveness of the Company's cybersecurity program.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The CISO is responsible for overseeing cybersecurity strategy, risk assessment, incident response, security operations, and cybersecurity governance activities.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Information Security Officer (CISO) leads the Company’s cybersecurity program and has more than 20 years of experience managing and directing global information security functions and possesses the requisite education, skills, experience, and industry certifications expected of an individual assigned to these duties.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The CISO is responsible for overseeing cybersecurity strategy, risk assessment, incident response, security operations, and cybersecurity governance activities. The CISO receives regular information regarding cybersecurity threats, vulnerabilities, incidents, and risk mitigation efforts and provides management with reporting regarding the Company's cybersecurity risk posture.
The CISO reports to the Chief Digital Officer (CDO), who is responsible for the Company's broader information technology strategy and operations, including capabilities related to cybersecurity resilience, incident response, and business recovery. Management, including the CISO and CDO, periodically reports to the Audit Committee and the Board of Directors regarding cybersecurity risks, significant incidents, emerging threats, mitigation activities, and the overall effectiveness of the Company's cybersecurity program.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true