Cybersecurity Risk Management and Strategy Disclosure |
12 Months Ended |
|---|---|
Jun. 30, 2026 | |
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] | Risk Management and Strategy CACI maintains a structured cybersecurity risk management and oversight program designed to mitigate risks to our systems and protect internal and customer data. We utilize diverse technologies, programs, and processes to continually assess, identify, and manage cybersecurity threats while embedding industry best practices across our information security operations. Our cybersecurity program is integrated into our enterprise risk management framework. The program is primarily managed by our Chief Information Security Officer (CISO), who coordinates cross-functional internal and external resources. The CISO is responsible for establishing procedures to monitor potential cybersecurity risks, identify cybersecurity incidents, implement mitigation measures, report breaches, and maintain our overall information security infrastructure. The CISO has extensive experience managing cybersecurity programs and technical risk and oversees prevention, detection, mitigation, and remediation efforts through regular reporting from our information security team, supplemented by specialized security technologies. We continuously monitor cybersecurity threats and evaluate our cybersecurity prevention measures through routine internal and independent audits, cybersecurity threat simulations, vulnerability assessments, and employee cybersecurity training. The program is designed to align with applicable industry standards, and we continuously invest in capabilities to protect our information assets. As a government contractor, we align our cybersecurity program with National Institute of Standards and Technology frameworks and comply with applicable U.S. government cybersecurity regulations. Our information systems infrastructure is routinely assessed by government agencies, and our network undergoes independent, third-party penetration testing biannually. We also manage cybersecurity-related supply chain risks by working closely with subcontractors and suppliers. We require these partners to comply with applicable legal regulations, implement specific information security controls, and fulfill incident reporting obligations. While we perform due diligence during onboarding and establish contractual safeguards, our practical ability to monitor third-party practices or completely prevent a compromise within vendor-controlled information systems, software, or networks remains inherently limited. We maintain a formalized incident response plan to address potential cybersecurity events promptly and effectively. The CISO leads our Cybersecurity Incident Response Team, which coordinates the execution of this plan and associated response processes. Under these policies, cybersecurity events are evaluated, ranked by severity, and prioritized for escalation to our Executive Incident Assessment Committee. The response plan outlines specific procedures for containment, investigation, affected-party notification, and corrective actions to prevent future occurrences.
|
| Cybersecurity Risk Management Processes Integrated [Flag] | true |
| Cybersecurity Risk Management Processes Integrated [Text Block] | CACI maintains a structured cybersecurity risk management and oversight program designed to mitigate risks to our systems and protect internal and customer data. We utilize diverse technologies, programs, and processes to continually assess, identify, and manage cybersecurity threats while embedding industry best practices across our information security operations. |
| Cybersecurity Risk Management Third Party Engaged [Flag] | true |
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false |
| Cybersecurity Risk Board of Directors Oversight [Text Block] | Audit and Risk Committee (the Audit Committee) maintains oversight responsibility for cybersecurity risks and incidents, including compliance with regulatory requirements, cooperation with law enforcement, and the associated impacts on our financial and operational risk profiles. The Audit Committee receives regular briefings from management regarding cybersecurity matters, including our posture, prevailing trends, and specific risks, and is updated on any material cybersecurity incidents should they occur. The Audit Committee reports its findings or recommendations to the full Board of Directors, as appropriate. |
| Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] | Our Audit and Risk Committee (the Audit Committee) maintains oversight responsibility for cybersecurity risks and incidents, including compliance with regulatory requirements, cooperation with law enforcement, and the associated impacts on our financial and operational risk profiles. |
| Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] | The Audit Committee receives regular briefings from management regarding cybersecurity matters, including our posture, prevailing trends, and specific risks, and is updated on any material cybersecurity incidents should they occur. The Audit Committee reports its findings or recommendations to the full Board of Directors, as appropriate. |
| Cybersecurity Risk Role of Management [Text Block] | Our Audit and Risk Committee (the Audit Committee) maintains oversight responsibility for cybersecurity risks and incidents, including compliance with regulatory requirements, cooperation with law enforcement, and the associated impacts on our financial and operational risk profiles. The Audit Committee receives regular briefings from management regarding cybersecurity matters, including our posture, prevailing trends, and specific risks, and is updated on any material cybersecurity incidents should they occur. The Audit Committee reports its findings or recommendations to the full Board of Directors, as appropriate. |
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |
| Cybersecurity Risk Management Positions or Committees Responsible [Text Block] | Audit and Risk Committee (the Audit Committee) maintains oversight responsibility for cybersecurity risks and incidents, including compliance with regulatory requirements, cooperation with law enforcement, and the associated impacts on our financial and operational risk profiles. The Audit Committee receives regular briefings from management regarding cybersecurity matters, including our posture, prevailing trends, and specific risks, and is updated on any material cybersecurity incidents should they occur. The Audit Committee reports its findings or recommendations to the full Board of Directors, as appropriate |
| Cybersecurity Risk Management Expertise of Management Responsible [Text Block] | The CISO has extensive experience managing cybersecurity programs and technical risk and oversees prevention, detection, mitigation, and remediation efforts through regular reporting from our information security team, supplemented by specialized security technologies. |
| Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] | We maintain a formalized incident response plan to address potential cybersecurity events promptly and effectively. The CISO leads our Cybersecurity Incident Response Team, which coordinates the execution of this plan and associated response processes. Under these policies, cybersecurity events are evaluated, ranked by severity, and prioritized for escalation to our Executive Incident Assessment Committee. The response plan outlines specific procedures for containment, investigation, affected-party notification, and corrective actions to prevent future occurrences.
|
| Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] | true |