As part of our normal course of business, we collect, retain, process, and transmit sensitive and confidential customer, associate, and company information. We also engage third-party vendors that provide technology, systems, and services to facilitate our collection, retention, processing, and transmission of this information. We face risk that our facilities and systems and those of our third-party vendors are vulnerable to cybersecurity threats, security breaches, system failures, acts of vandalism, fraud, misappropriation, malware, ransomware, and other malicious or harmful code, misplaced or lost data, programming and/or human errors, insider threats, or other similar events. The ever-evolving and increasingly sophisticated methods of cyber-attack may be difficult or impossible to anticipate and/or detect. Our ability to monitor our vendors and service providers' data security is limited, and, in any event, third parties may be able to circumvent those security measures, resulting in the unauthorized access to, misuse, acquisition, disclosure, loss, alteration, or destruction of our and our customers' and associates' data, including confidential, sensitive, and other information about individuals. Any data security incident involving the breach, misappropriation, loss, or other unauthorized disclosure of sensitive and/or confidential information, whether by us or our vendors, the failure or unavailability of technology systems, or ineffectiveness of business continuity or disaster recovery plans in the event of the foregoing events could disrupt our operations, damage our reputation and customers' willingness to shop in our stores or on our website, violate applicable laws, regulations, orders and agreements, and subject us to additional costs and liabilities which could be material. While we maintain insurance coverage designed to address certain aspects of cyber risks, such insurance coverage may be insufficient to cover all losses or all types of claims that may arise. In addition, the regulatory environment related to data privacy and cybersecurity is constantly changing, with new and increasingly demanding requirements applicable to our business. Maintaining our compliance with those requirements, including recently enacted state consumer privacy laws, may increase our compliance costs, require changes to our business practices, limit our ability to use and collect data, impact our customers' shopping experience, reduce our business efficiency, and subject us to additional regulatory scrutiny or data breach litigation.