Information security risks for financial institutions such as the Company and the Bank are significant due to the use of online, telephone and mobile banking channels by customers and the increased sophistication and activities of organized crime, hackers, terrorists and other external parties. Third parties with whom we or our customers do business also present operational and information security risks to us. We see an increasing trend of cyberattacks targeting providers in the financial services industry, as well as increased security breaches or failures of their own systems. Our operations rely on the secure processing, transmission and storage of confidential information in our computer systems and networks. Our businesses rely on our digital technologies, computer and email systems, software, and networks to conduct their operations. As our reliance on technology systems increases, the potential risks of technology-related interruptions in our operations or the occurrence of cyber incidents also increases. Our technologies, systems, networks and our customers' devices are periodically the target of cyberattacks, and may be the target of future cyberattacks, including through the introduction of computer viruses, and/or malicious code, or by means of phishing attacks, social engineering or other information security breaches. Malicious actors may also attempt to fraudulently induce employees, customers or other users of our systems to disclose sensitive information, including passwords and other identifying information, in order to gain access to data or our systems.
In recent years, there have been several well-publicized attacks on various companies, including in the financial services industry, and personal, proprietary, and public e-mail systems in which the perpetrators gained unauthorized access to confidential information and customer data, often through the introduction of computer viruses or malware, cyberattacks, phishing, social engineering or other means. Even if not directed at the Company or the Bank specifically, attacks on other entities with whom we do business or on whom we otherwise rely or attacks on financial or other institutions important to the overall functioning of the financial system could adversely affect, directly or indirectly, aspects of our business.
Information security risks continue to increase, in part because of the proliferation of new technologies, including artificial intelligence ("AI"), ongoing work-from-home arrangements, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists, activists, and other external parties, some of which may be linked to terrorist organizations or hostile foreign governments. We have expended substantial resources to protect our systems and, as cyber threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our systems or to investigate and remediate vulnerabilities. System enhancements and updates may also create risks associated with implementing and integrating new systems. Due to the complexity and interconnectedness of information technology systems, the process of enhancing our systems can itself create a risk of systems disruptions and security issues. Failure to properly utilize system enhancements that are implemented in the future could result in impairment charges and could result in significant costs to remediate or replace the defective components. In addition, we may incur significant training, licensing, maintenance, consulting and amortization expenses during and after systems implementations, and any such costs may continue for an extended period of time.
We may not be able to anticipate, detect, or implement effective preventative measures against all potential threats, particularly because the techniques used by cyber criminals change frequently, often are not recognized until launched and can be initiated from a variety of sources. In addition, a cybersecurity breach or cyberattack could persist for an extended period before being detected, which could exacerbate the harmful effects of a successful cyberattack. If one or more of the events described above occurs, this could result in the unauthorized release, gathering, monitoring, misuse, loss or destruction of our or our customers' confidential, proprietary and other information, the theft of customer assets through fraudulent transactions or disruption of our or our customers' or other third parties' business operations, which could result in legal or regulatory action, significant losses, increased compliance costs or reputational damage, any of which could adversely affect our business, financial condition or results of operations. Because the investigation of any information security breach is inherently unpredictable and would require substantial time to complete, the Company may not be able to quickly remediate the consequences of any breach, which may increase the costs, and enhance the negative consequences associated with a breach. In addition, to the extent the Company's insurance covers aspects of any breach, such insurance may not be sufficient to cover all of the Company's losses.
As cybersecurity and data privacy risks for banking organizations and other financial institutions have significantly increased in recent years, cybersecurity and data privacy issues have become the subject of increasing legislative and regulatory focus. We could be adversely affected if new legislation or regulations are adopted or if existing legislation or regulations are modified such that we are required to alter our systems or are required to change our business practices or privacy policies. If cybersecurity, data privacy, data protection, data transfer or data retention laws are implemented, interpreted or applied in a manner inconsistent with our current practices, we may be subject to fines, litigation or regulatory enforcement actions or ordered to change our business practices, policies or systems in a manner that adversely affects our results of operations.