Item 1A. Risk Factors
Item 1A. Risk Factors.
There have been no material changes to our risk factors previously disclosed in Part I, Item 1A. “Risk Factors” of our 2022 Form 10-K, except for the updated risk factor included below, which should be read in conjunction with the risk factors set forth in our 2022 Form 10-K.
68
Table of Contents
Our information technology systems have been and in the future may be adversely affected by cybersecurity events, disruptions, damage, failure and risks associated with implementation and integration.
Our industry has become increasingly supported by and dependent on digital technologies. Our strategy of operating large, long-lived, geographically diverse assets has been increasingly dependent on our ability to become fully integrated and highly automated. Many of our business and operational processes are heavily dependent on traditional and emerging technology systems to conduct day-to-day operations, improve safety and efficiency, and lower costs.
As our dependence on information systems, including those of our third-party service providers and vendors, grows, we become more vulnerable to an increasing threat of continually evolving cybersecurity risks. In recent years, cybersecurity events have increased in frequency and magnitude and the methods used to gain unauthorized access change frequently, making it increasingly difficult for us to prevent cybersecurity incidents or detect and remediate incidents in a timely and effective manner. Attacks have included and may include, but are not limited to, installation of malicious software, phishing, ransomware, social engineering tactics and credential attacks, insider threats, denial of service attacks, unauthorized access to data and other advanced and sophisticated cybersecurity breaches and threats, including those that increasingly target critical operational technologies and process control networks and those that use artificial intelligence. Such attacks may be perpetrated by a variety of bad actors, some of which may reside in jurisdictions where law enforcement measures to address such attacks are ineffective.
We have experienced targeted and non-targeted cybersecurity events in the past and may experience them in the future. In August 2023, we determined that we were subject to a cybersecurity incident that affected certain of our information systems, resulting in temporary disruptions to parts of our operations. We performed an investigation of the impact of the incident and incurred an immaterial amount of expenses in conjunction with the investigation. However, we cannot guarantee that events of a similar nature will not occur in the future.
Cybersecurity threats could subject us to manipulation or improper use of our systems and networks, production downtimes, loss of sales, communication interruption or other disruptions and delays to our operations or to the transportation of products or infrastructure utilized by our operations, unauthorized release of proprietary, commercially sensitive, confidential or otherwise protected information, a misappropriation or loss of funds, the corruption of data, significant health and safety consequences, environmental damage, loss of intellectual property, fines, penalties, litigation, regulatory or governmental investigation, liability under or termination of our contracts with third parties, damage to our reputation or financial losses from remedial actions, any of which could have a material adverse effect on our cash flows, results of operations and financial condition, and which could adversely impact the effectiveness of our internal controls over financial reporting. We do not maintain cyber risk insurance, and the lack of, or insufficiency of, insurance coverage could adversely affect our cash flows and overall profitability.
While the August 2023 cybersecurity incident and other cybersecurity events have not had a material impact on us, including our financial condition or results of operations, as of September 30, 2023, there can be no assurance that we will not experience any such impact or additional interruptions to our operations in the future. Given the unpredictability of the timing and the evolving nature and scope of information technology disruptions, the various procedures and controls we use to monitor and protect against these threats and to mitigate our potential risks to such threats have not been in some instances and may not be sufficient in preventing future cybersecurity events from materializing. Further, as cybersecurity threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate vulnerabilities to cybersecurity threats.
We could also be adversely affected by system or network disruptions if new or upgraded information technology systems are defective, not installed properly or not properly integrated into our operations. System modification failures could have a material adverse effect on our business, financial position and results of operations and could, if not successfully implemented, adversely impact the effectiveness of our internal controls over financial reporting.
Further, we increasingly depend on our information technology infrastructure for electronic communications among our locations, personnel, customers and suppliers around the world, including as a result of remote working and flexible working arrangements. These information technology systems, some of which are managed by third parties that we do not control, may be susceptible to damage, disruptions or shutdowns because of failures during the process of upgrading or replacing software, databases or components thereof, cutover activities in our restructuring
69
Table of Contents
and simplification initiatives, power outages, hardware failures, telecommunication failures, user errors, catastrophic events or other problems.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.