{"url_path":"/sec/flws/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-09-11","source_url":"https://www.sec.gov/Archives/edgar/data/1084869/0001084869-26-000029-index.html","accession_number":"0001084869-26-000029","cik":"0001084869","ticker":"FLWS","issuer_name":"1 800 FLOWERS COM INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1084869/0001084869-26-000029-index.html","primary_entity_key":"0001084869","primary_entity_name":"1 800 FLOWERS COM INC"},"word_count":747,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity\n\nRisk Management and Strategy\n\nIn the ordinary course of our business, we utilize technology systems to collect, use, store, and transmit information. The confidentiality, integrity, and availability of the information in our systems is important to our operations, business strategy, and maintaining the trust of our customers, employees and partners. As part of our enterprise risk management program, we have processes in place to identify, assess, and manage material risks associated with cybersecurity threats, as such term is defined in Item 106(a) of Regulation S-K.\n\nOur cybersecurity team engages with applicable personnel across the enterprise and utilizes software tools to identify, categorize, and quantify material cybersecurity threat risks. The team meets regularly to consider new, known, and evolving risks and evaluate the measures in place to mitigate these risks.\n\nOur strategy for managing cybersecurity risk is multifaceted and includes, without limitation: (i) robust security policies and procedures, designed in part to comply with the Payment Card Industry Data Security Standard (PCI-DSS), (ii) an incident response plan backed with incident response support services, (iii) comprehensive system security vulnerability scanning, and oversight by a 24 hours a day, 7 days a week, 365 days a year Securities Operation Center; (iv) periodic cybersecurity awareness training and testing for employees and certain contractors; (v) risk management of our third-party suppliers, vendors, and other partners, which includes risk-based diligence and contractual provisions that generally allow for periodic auditing, and (vi) security assessments of any businesses that we acquire.\n\nAs part of our cybersecurity risk management program, we periodically engage third parties to evaluate and test our systems, run tabletop exercises to test our incident response processes, provide incident response support if needed, and certify our PCI-DSS compliance.\n\nWe face ongoing risks that, if realized, could materially impact our business, operations and financial results. See our risk factor disclosures in [Item 1A](#i6be358bd2457476b96cd2cdb3efc4931_16) of this Annual Report on Form 10-K under the heading “Information Technology and Systems,” which are incorporated by reference herein. To date, risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected the Company, including our business strategy, results of operations, or financial condition.\n\nGovernance\n\nThe Board of Directors of the Company (the “Board”), as a whole and through its committees, oversees the Company’s risk management process, including operational, financial, legal, strategic, marketing and brand reputation risks. The Technology and Cybersecurity Committee of the Board (the “Committee”) oversees risk management associated with the Company’s information technology use and protection, including data governance, privacy, compliance, and cybersecurity. The Committee comprises Board members with particular expertise in technology and management, equipping them to oversee cybersecurity risks effectively.\n\nThe Committee is responsible for the oversight of the Company’s policies and procedures intended to provide security, confidentiality, availability, and integrity of the Company’s information, including with respect to data privacy and the Company’s compliance with applicable data privacy and cybersecurity laws and regulations. The Committee also oversees the quality and effectiveness of the Company’s policies and procedures with respect to its information technology systems and provides oversight on the Company’s policies and procedures in maintaining preparedness for responding to any material incidents. The Committee also periodically coordinates with the Company’s Audit Committee, which reviews risks related to the Company’s information technology systems, including privacy, network security and data security.\n\nThe Company’s program to identify, assess, and manage cybersecurity risks is currently led by our Chief Information Officer, and leverages the expertise of our Chief Financial Officer and General Counsel. Our Chief Information Officer holds a Master of Business Administration degree from the University of Chicago's Booth School of Business and a bachelor's degree from Brooklyn College, City University of New York. He has over 25 years of technology leadership experience, including implementing effective information and cybersecurity programs. Our Chief Information Officer, who reports to our Chief Executive Officer, meets regularly with the executive leadership team regarding topics related to technology operations, including cybersecurity, and also periodically updates the Board and the Committee regarding the Company’s cybersecurity and data privacy risk mitigation plans.\n\n20\n\n[Table of Contents](#i6be358bd2457476b96cd2cdb3efc4931_7)\n\nWith respect to the prevention, detection, mitigation, and remediation of cybersecurity incidents, our information security team, under the direction of our Chief Information Officer, monitors our information systems, assesses the severity of any incidents it detects or that are otherwise reported, and follows escalation procedures embedded within our incident response plan to inform the Chief Information Officer, other members of management, the Committee, and the Board, each as needed."}