UNIFIRST CORP 10-K Cybersecurity GRC - 2025-10-29

Page last updated on October 29, 2025

UNIFIRST CORP reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-10-29 15:29:00 EDT.

Filings

10-K filed on 2025-10-29

UNIFIRST CORP filed a 10-K at 2025-10-29 15:29:00 EDT
Accession Number: 0001193125-25-256222

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY Cybersecurity Risk Management and Strategy Our cybersecurity risk management strategy is designed to detect, evaluate, and manage risks from cybersecurity threats and incidents. Our program is intended to identify cybersecurity risks facing our organization and inform our risk-based approach to cybersecurity preparedness and incident response procedures. Our cybersecurity risk management program is supported by our third-party vendors and service providers, and includes, but is not limited to, periodic penetration testing and endpoint detection, and automated tools to monitor our network and systems to detect vulnerabilities or unusual activity that could lead to unauthorized access to our systems or data. We conduct assessments, as appropriate, of critical third-party service providers, which generally include a cybersecurity questionnaire and a review of security assessments and certifications . We also provide cybersecurity awareness training to employees with access to our network. We also have a policy for responding to and mitigating cybersecurity incidents. Our Chief Information & Technology Officer ("CITO") oversees our incident response procedures , which are reviewed and updated periodically. We have not identified cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, we and our third-party vendors have from time to time experienced threats that could affect our information or systems. For more information, please see the risk factor titled "If our information technology systems suffer interruptions or failures, including as a result of cyber-attacks, our business operations could be disrupted or other material adverse impacts on our business could result." Cybersecurity Governance Our CITO, who reports to our Chief Executive Officer, is responsible for leading our information security team and overseeing the Company's cybersecurity risk management efforts. Our CITO has significant experience as a chief technology officer. Our Chief Information Security Officer supports the program and incident response and reports to the CITO. Our cybersecurity risk management program is overseen by our Board of Directors. Members of the Board of Directors and the Audit Committee will periodically meet with our CITO to discuss material cybersecurity risks facing our organization and significant changes or updates to our cybersecurity processes. The full Board of Directors receives a cybersecurity risk management update from management generally on a quarterly basis. 15


Company Information

NameUNIFIRST CORP
CIK0000717954
SIC DescriptionServices-Personal Services
TickerUNF - NYSE
Website
CategoryLarge accelerated filer
Fiscal Year EndAugust 28