Cybersecurity Risk Management, Strategy, and Governance |
12 Months Ended |
|---|---|
Jul. 31, 2026 | |
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] | Item 1C. Cybersecurity Cybersecurity is an important component of our overall enterprise risk management strategy. We are committed to protecting our information systems and data from a wide range of cybersecurity threats, including operational risks, intellectual property theft, fraud, extortion, privacy violations, legal risks, and reputational damage. Our approach integrates comprehensive processes and technologies designed to identify, assess, and mitigate these risks. Risk Management and Strategy • Enterprise Risk Management Integration: Our cybersecurity program is integrated into our broader enterprise risk management program ("ERM"). This integration is designed to ensure that cybersecurity risks, including the cybersecurity risks associated with AI, are evaluated alongside other risks to the organization as part of our overall risk management framework and strategy. Our ERM framework is periodically refreshed and involves collaboration with subject matter experts to assess the severity of potential cybersecurity threats and develop appropriate mitigation strategies. • Cybersecurity Processes: We employ a multi-faceted approach to cybersecurity: • Security and Privacy Reviews: Regular reviews of new features, software, and vendors help us work to identify and address potential risks before they impact our systems. • Security Development Lifecycle: Our internal software development lifecycle process is designed to build our products in part relying upon industry-standard practices and third-party tools and services to test our code and bundled third-party libraries for known security misconfigurations and errors. • Vulnerability Management: We operate a robust vulnerability management program designed to identify and address hardware and software vulnerabilities proactively. • Network and System Monitoring: Our systems are monitored using a range of tools designed to detect suspicious activities and potential breaches in real time. • Threat Intelligence Program: Our threat intelligence program models and researches potential adversaries, enhancing our preparedness against emerging threats. • Monitoring and Mitigation of AI-Enhanced Threats: As AI and machine learning capabilities mature, the cybersecurity threat landscape is evolving to include attacks that may be enhanced or facilitated by AI. As part of our cybersecurity program, we monitor this evolving threat landscape and evaluate protective measures intended to improve our ability to detect, prevent, triage, and respond to AI-enhanced threats. • Training and Simulations: We regularly conduct training and simulations designed to ensure our teams are prepared for a variety of cybersecurity scenarios. • Security Ecosystem: We routinely and regularly engage with consultants, assessors, auditors, and other expert third parties to help us in our understanding, discovery, and response to risks based on their growing impact or likelihood. • Frameworks and Standards: Our cybersecurity practices are designed with reference to industry-standard frameworks, including those from the International Organization for Standardization and the National Institute of Standards and Technology and other internationally recognized standards, which can be found here: https://www.nutanix.com/trust/compliance-and-certifications, which link is included as an inactive reference and the content of which is not incorporated by reference into this Annual Report on Form 10-K. We continually work to improve our security controls based on these standards and industry best practices. • Incident Response and Recovery: We have established a comprehensive Privacy and Cybersecurity Incident Response Program to manage and respond to cybersecurity incidents. This program includes processes for triaging, assessing, escalating, containing, investigating, and remediating incidents. We also maintain procedures to comply with legal obligations and mitigate reputational damage. Regular tabletop exercises help us test and strengthen our incident response capabilities. We also have an external bug bounty program to identify and address vulnerabilities before they can be exploited. • Vendor Risk Management: Our vendor risk management program is designed to mitigate risks associated with third-party service providers. This program includes pre-engagement diligence, contractual security, privacy, and AI-related data protection provisions, and ongoing monitoring of third-party compliance with our data protection requirements. Information on the cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors.” We believe that risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. However, we remain subject to risks from unknown or future cybersecurity threats that could materially affect us, including our business strategy, results of operations or financial condition. We remain vigilant and continue to invest in security technologies and practices to safeguard our systems. Governance • Board and Committee Oversight: Our Board of Directors (our "Board") plays an active role in overseeing cybersecurity risks. Our Board’s Security and Privacy Committee, which is composed entirely of independent directors, assists our Board in its oversight of our management of technology and information security risks and compliance with data protection and privacy laws. This committee regularly reviews our cybersecurity programs and policies as part of our overall risk management and business strategy discussions, and receives regular updates from management on our data security posture, third-party assessments, and progress toward risk-mitigation goals. The committee also reviews incident response plans and any significant cybersecurity threats or incidents. Our Board's Security and Privacy Committee reports quarterly to our Board regarding its activities in overseeing cybersecurity, AI, data protection and privacy risk management. • Management's Role: Our Chief Information Security Officer ("CISO") partners with a cross-functional leadership team including the Chief Product Security Officer ("CPSO"), Chief Information and Digital Officer ("CIDO"), and Legal and Privacy Counsel, to develop and implement our overall cybersecurity strategy. This team contributes to the development of policies, monitors evolving risks, manages the overall cybersecurity and privacy programs, and reports on these and related topics to our Board's Security and Privacy Committee. Our CISO has served in various roles in information technology and information security for over 25 years, including previously serving as Chief Information Security Officer at two other companies. He holds an undergraduate degree in computer science. Our CPSO also previously held the role at Nutanix and served as the Chief Information Security Officer at Intuit. He holds a PhD in computer science. •
Incident Management: Our Enterprise and Product Security Team manages our incident response efforts. This team assesses incidents' severity, coordinates the response, and communicates with relevant stakeholders. Our Security and Privacy Management Team, including, as appropriate, our CISO, CIDO, and CPSO, provides additional expertise and support as needed. |
| Cybersecurity Risk Management Processes Integrated [Flag] | true |
| Cybersecurity Risk Management Processes Integrated [Text Block] | •
Enterprise Risk Management Integration: Our cybersecurity program is integrated into our broader enterprise risk management program ("ERM"). This integration is designed to ensure that cybersecurity risks, including the cybersecurity risks associated with AI, are evaluated alongside other risks to the organization as part of our overall risk management framework and strategy. Our ERM framework is periodically refreshed and involves collaboration with subject matter experts to assess the severity of potential cybersecurity threats and develop appropriate mitigation strategies. |
| Cybersecurity Risk Management Third Party Engaged [Flag] | true |
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false |
| Cybersecurity Risk Board of Directors Oversight [Text Block] | •
Board and Committee Oversight: Our Board of Directors (our "Board") plays an active role in overseeing cybersecurity risks. Our Board’s Security and Privacy Committee, which is composed entirely of independent directors, assists our Board in its oversight of our management of technology and information security risks and compliance with data protection and privacy laws. This committee regularly reviews our cybersecurity programs and policies as part of our overall risk management and business strategy discussions, and receives regular updates from management on our data security posture, third-party assessments, and progress toward risk-mitigation goals. The committee also reviews incident response plans and any significant cybersecurity threats or incidents. Our Board's Security and Privacy Committee reports quarterly to our Board regarding its activities in overseeing cybersecurity, AI, data protection and privacy risk management. |
| Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] | Our Board’s Security and Privacy Committee, which is composed entirely of independent directors, assists our Board in its oversight of our management of technology and information security risks and compliance with data protection and privacy laws. This committee regularly reviews our cybersecurity programs and policies as part of our overall risk management and business strategy discussions, and receives regular updates from management on our data security posture, third-party assessments, and progress toward risk-mitigation goals. The committee also reviews incident response plans and any significant cybersecurity threats or incidents. |
| Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] | Our Board's Security and Privacy Committee reports quarterly to our Board regarding its activities in overseeing cybersecurity, AI, data protection and privacy risk management. |
| Cybersecurity Risk Role of Management [Text Block] | •
Management's Role: Our Chief Information Security Officer ("CISO") partners with a cross-functional leadership team including the Chief Product Security Officer ("CPSO"), Chief Information and Digital Officer ("CIDO"), and Legal and Privacy Counsel, to develop and implement our overall cybersecurity strategy. This team contributes to the development of policies, monitors evolving risks, manages the overall cybersecurity and privacy programs, and reports on these and related topics to our Board's Security and Privacy Committee. Our CISO has served in various roles in information technology and information security for over 25 years, including previously serving as Chief Information Security Officer at two other companies. He holds an undergraduate degree in computer science. Our CPSO also previously held the role at Nutanix and served as the Chief Information Security Officer at Intuit. He holds a PhD in computer science. |
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |
| Cybersecurity Risk Management Positions or Committees Responsible [Text Block] | partners with a cross-functional leadership team including the Chief Product Security Officer ("CPSO"), Chief Information and Digital Officer ("CIDO"), and Legal and Privacy Counsel, to develop and implement our overall cybersecurity strategy. |
| Cybersecurity Risk Management Expertise of Management Responsible [Text Block] | Our CISO has served in various roles in information technology and information security for over 25 years, including previously serving as Chief Information Security Officer at two other companies. He holds an undergraduate degree in computer science. Our CPSO also previously held the role at Nutanix and served as the Chief Information Security Officer at Intuit. He holds a PhD in computer science. |
| Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] | This team contributes to the development of policies, monitors evolving risks, manages the overall cybersecurity and privacy programs, and |
| Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] | true |