Cybersecurity Risk Management and Strategy Disclosure |
12 Months Ended |
|---|---|
Jun. 30, 2026 | |
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] | The Company recognizes the critical importance of developing, implementing, and maintaining effective cybersecurity measures to protect our information systems and provide for the confidentiality, integrity, and availability of our data, as well as that of our customers, business partners and employees. Our cybersecurity processes are integrated into our overall enterprise risk management framework so that cybersecurity risks can be evaluated and managed alongside other business risks. Such integration supports our effort to promote a company-wide culture of cybersecurity risk management. Our cybersecurity risk management program is focused on the following key areas: Risk Assessment. Our in-house security teams and third-party security firms periodically evaluate the Company’s cybersecurity policies, processes, and practices. Such evaluations may include audits, assessments, penetration testing, threat modeling, tabletop exercises, and similar activities focused on evaluating the effectiveness of our cybersecurity processes and planning. The Company updates its cybersecurity policies, standards, processes, and practices periodically, as appropriate, based on the insights gained from these assessments, evolving industry standards, cybersecurity threat intelligence, changes to our infrastructure, and client-specific requirements. Identified risks are documented, prioritized, assigned to responsible owners, and tracked through remediation or other risk retirement, as appropriate. The Company considers the following factors in assessing its cybersecurity risks, mitigation, and remediation strategies: the likelihood and degree of risk; potential impact, if a risk materializes; and the feasibility, cost and impact of controls. The specific controls used by the Company vary based on the systems and program involved, but typically include vulnerability and patch management, penetration testing, firewalls, intrusion prevention and detection systems, anti-malware (including anti-phishing) technical safeguards and access controls, privileged access management, endpoint threat detection and response, identity and access management, multi-factor authentication, logging and monitoring, data encryption, backup and recovery systems, cyber insurance, and physical security controls. The Company also incorporates threat intelligence and monitors emerging cybersecurity threats relevant to the BPO industry, including AI-enabled threats. We have, and will continue to, integrate AI into our solutions, as well as explore potential third-party partnerships to help us be better positioned to offer our clients robust solutions. While AI offers significant benefits, it also presents risks and challenges. AI solutions are evolving and are not infallible, and we may encounter issues with data sourcing, technology integration, bias in data models or decision-making algorithms, security challenges, and the protection of personal information and privacy. Depending on the nature and risk profile of the proposed used, the Company conducts reviews of third-party AI systems, and providers that may include data security, model security, privacy, legal and regulatory compliance and contractual protections. Third-Party Risks. We have established processes to oversee and identify cybersecurity risks presented by third parties. Under these processes, contracts with relevant third parties are reviewed, as appropriate, for contractual controls, including provisions requiring appropriate cybersecurity measures. We periodically conduct assessments of key vendors and business partners’ cybersecurity practices and require them to adhere to our security standards, as appropriate. Additionally, we may perform additional due diligence on select third-party service providers by collecting and reviewing certifications and other assurance materials when available. The Company may also periodically review third-party processes, assessments, and certifications to evaluate their use of industry best practices. Business Continuity, Incident Response and Disaster Recovery. The Company has established and maintains business continuity, incident response, and disaster recovery plans designed to address the Company’s response to cybersecurity incidents and other potential disruptions. Our IT Security, Technology, Operations, Legal, and Compliance teams periodically evaluate and update these plans and participate in exercises intended to enhance our incident response preparedness. The Company also leverages third party incident response and threat detection services. The Company has processes designed to escalate potentially significant cybersecurity incidents for assessment by appropriate members of management, including to evaluate applicable contractual, legal, regulatory, and disclosure obligations. Education and Awareness. The Company provides regular, mandatory training for personnel on cybersecurity threats and has processes and procedures in place to communicate out-of-cycle notices and updates regarding the Company’s information security policies, standards, processes, and practices by the Chief Technology Officer (“CTO”) as needed.
|
| Cybersecurity Risk Management Processes Integrated [Flag] | true |
| Cybersecurity Risk Management Processes Integrated [Text Block] | The Company recognizes the critical importance of developing, implementing, and maintaining effective cybersecurity measures to protect our information systems and provide for the confidentiality, integrity, and availability of our data, as well as that of our customers, business partners and employees. Our cybersecurity processes are integrated into our overall enterprise risk management framework so that cybersecurity risks can be evaluated and managed alongside other business risks. Such integration supports our effort to promote a company-wide culture of cybersecurity risk management. |
| Cybersecurity Risk Management Third Party Engaged [Flag] | true |
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false |
| Cybersecurity Risk Board of Directors Oversight [Text Block] | The Company’s Board is responsible for overseeing cybersecurity risk management as part of its oversight of the Company’s enterprise risk management framework. The Board receives periodic updates from management on cybersecurity strategy, risk assessments, and significant developments but is not involved in day-to-day operational decision-making. The Company’s management team is responsible for the day-to-day oversight and management of cybersecurity risks, supported by our dedicated professionals responsible for cybersecurity, fraud, risk management, and compliance. Additionally, our Cybersecurity Committee, which is composed of certain members of executive management and leaders from Technology, Information Security, Legal, Compliance, and Operations, provides sponsorship, oversight, and guidance to help achieve our management objectives. Our Chief Information Security Officer (“CISO”) reports to our CTO and assists in the day-to-day management of cybersecurity risks by leading the Information Security department and operationalizing our Information Security management systems.
|
| Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] | Our current CISO has served in information security leadership roles at the Company for more than ten years and holds more than eighteen years of experience in cybersecurity, including security operations, cloud security, and risk management. He has extensive experience with enterprise information security controls and frameworks, such as ISO 27001, PCI DSS, SOC 2 Type II, and HITRUST. Additionally, our CISO holds multiple professional certifications, including CISSP (Certified Information Systems Security Professional), CISA (Certified Information Security Auditor), and CISM (Certified Information Security Manager |
| Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] | The CTO and CISO meet regularly with the Cybersecurity Committee to review the Company’s management of information security risks, and the Cybersecurity Committee evaluates the adequacy of the Company’s IT security program, compliance and controls with our CTO. In addition to scheduled meetings, the CTO, Cybersecurity Committee, and CEO maintain a regular dialogue regarding emerging or potential cybersecurity risks, which may include input from our third-party vendors and other external sources. The Cybersecurity Committee receives updates on significant developments in the cybersecurity domain from the CTO and CISO, as needed and at least quarterly. These updates, as well as other cybersecurity matters, are provided to the Company’s Board by the CTO to support the Board’s oversight of cybersecurity-related risks. The Board and executive management meet regularly to review cybersecurity risks and developments as part of our enterprise risk management framework. |
| Cybersecurity Risk Role of Management [Text Block] | The Company’s Board is responsible for overseeing cybersecurity risk management as part of its oversight of the Company’s enterprise risk management framework. The Board receives periodic updates from management on cybersecurity strategy, risk assessments, and significant developments but is not involved in day-to-day operational decision-making. The Company’s management team is responsible for the day-to-day oversight and management of cybersecurity risks, supported by our dedicated professionals responsible for cybersecurity, fraud, risk management, and compliance. Additionally, our Cybersecurity Committee, which is composed of certain members of executive management and leaders from Technology, Information Security, Legal, Compliance, and Operations, provides sponsorship, oversight, and guidance to help achieve our management objectives. Our Chief Information Security Officer (“CISO”) reports to our CTO and assists in the day-to-day management of cybersecurity risks by leading the Information Security department and operationalizing our Information Security management systems. Our current CISO has served in information security leadership roles at the Company for more than ten years and holds more than eighteen years of experience in cybersecurity, including security operations, cloud security, and risk management. He has extensive experience with enterprise information security controls and frameworks, such as ISO 27001, PCI DSS, SOC 2 Type II, and HITRUST. Additionally, our CISO holds multiple professional certifications, including CISSP (Certified Information Systems Security Professional), CISA (Certified Information Security Auditor), and CISM (Certified Information Security Manager). The CTO and CISO meet regularly with the Cybersecurity Committee to review the Company’s management of information security risks, and the Cybersecurity Committee evaluates the adequacy of the Company’s IT security program, compliance and controls with our CTO. In addition to scheduled meetings, the CTO, Cybersecurity Committee, and CEO maintain a regular dialogue regarding emerging or potential cybersecurity risks, which may include input from our third-party vendors and other external sources. The Cybersecurity Committee receives updates on significant developments in the cybersecurity domain from the CTO and CISO, as needed and at least quarterly. These updates, as well as other cybersecurity matters, are provided to the Company’s Board by the CTO to support the Board’s oversight of cybersecurity-related risks. The Board and executive management meet regularly to review cybersecurity risks and developments as part of our enterprise risk management framework.
|
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |
| Cybersecurity Risk Management Positions or Committees Responsible [Text Block] | Our current CISO has served in information security leadership roles at the Company for more than ten years and holds more than eighteen years of experience in cybersecurity, including security operations, cloud security, and risk management. He has extensive experience with enterprise information security controls and frameworks, such as ISO 27001, PCI DSS, SOC 2 Type II, and HITRUST. Additionally, our CISO holds multiple professional certifications, including CISSP (Certified Information Systems Security Professional), CISA (Certified Information Security Auditor), and CISM (Certified Information Security Manager). The CTO and CISO meet regularly with the Cybersecurity Committee to review the Company’s management of information security risks, and the Cybersecurity Committee evaluates the adequacy of the Company’s IT security program, compliance and controls with our CTO. In addition to scheduled meetings, the CTO, Cybersecurity Committee, and CEO maintain a regular dialogue regarding emerging or potential cybersecurity risks, which may include input from our third-party vendors and other external sources. The Cybersecurity Committee receives updates on significant developments in the cybersecurity domain from the CTO and CISO, as needed and at least quarterly. These updates, as well as other cybersecurity matters, are provided to the Company’s Board by the CTO to support the Board’s oversight of cybersecurity-related risks. The Board and executive management meet regularly to review cybersecurity risks and developments as part of our enterprise risk management framework.
|
| Cybersecurity Risk Management Expertise of Management Responsible [Text Block] | Our current CISO has served in information security leadership roles at the Company for more than ten years and holds more than eighteen years of experience in cybersecurity, including security operations, cloud security, and risk management. |
| Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] | The Cybersecurity Committee receives updates on significant developments in the cybersecurity domain from the CTO and CISO, as needed and at least quarterly. These updates, as well as other cybersecurity matters, are provided to the Company’s Board by the CTO to support the Board’s oversight of cybersecurity-related risks. The Board and executive management meet regularly to review cybersecurity risks and developments as part of our enterprise risk management framework. |
| Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] | true |