Item 1A. Risk Factors
Item 1A. Risk Factors
The following updates the risk factors previously disclosed under Item 1A of the Company’s Annual Report on Form 10-K for the year ended December 31, 2020.
Breaches and failures of, and other disruptions to, the Company’s information technology systems may disrupt the Company’s operations, result in monetary losses and harm the Company’s reputation.
The Company relies on information technology (“IT”) systems for a wide range of activities involved in the delivery of its products and services, including, but not limited to the following:
• process title insurance applications and policy issuances;
• perform due diligence on land titles;
• manage substantial cash, investment assets, bank deposits, trust assets and escrow account balances on behalf of the Company and its customers;
• manage billing, collections and payables, including insurance premiums and agent commissions;
• manage accounting and financial reporting; and
• manage payroll and human resources information.
The Company’s IT systems may be disrupted or fail, and information stolen or otherwise misappropriated, for a number of reasons, including:
• hacking, computer viruses, malware, ransomware or other cyberattacks;
• software “bugs”, hardware defects or human error;
• natural disasters, like fires, or pandemics; or
• power loss.
Any of these events could disrupt operations both internally and externally, which may result in the loss of revenues. These events could also result in the unauthorized release of proprietary and/or non-public information, or even defalcation of corporate or client funds.
Like all companies, the Company’s IT systems have been, and likely will continue to be, the target of computer viruses, cyberattacks, phishing attacks and other malicious activity. For example, during the third quarter of 2021 , the Company detected a ransomware attack believed to be limited to one entity that required a temporary interruption to the impacted entity’s computer network as the issue is being remediated. Promptly upon detection, the Company launched an investigation and initiated response protocols, including the engagement of external cybersecurity professionals and legal counsel. Although the Company is in the early stages of assessing the incident, based on the information currently known, the Company does not believe the ransomware attack will have a material impact on the Company's business, financial position and results of operations. While the Company has not experienced a known material breach to date, the occurrence or scope of such events is not always immediately apparent and there can be no assurance that we will not suffer additional attacks or incur more serious financial consequences or expense in the future. The Company invests resources in maintaining the security of its systems and adapting to evolving security threats. There is, however, no guarantee that its security measures will be adequate to prevent all cyberattacks. There is similarly no guarantee that the Company’s backup systems or disaster recovery procedures will be adequate to mitigate losses due to IT system disruptions in a timely fashion, and the Company may incur significant expense in correcting IT system emergencies. The Company’s reputation may also be damaged in the event of a serious IT breach or failure. Furthermore, as technology develops, and as cybercriminals become more capable, the difficulty and expense of maintaining IT security and redundancy may increase.
To the extent the Company’s IT systems store non-public personal information, and information about its employees, security breaches may expose the Company to other serious liabilities and reputational harm if such data is misappropriated. Non-public personal information may include, but is not limited to, names, addresses, social security numbers, and banking information.
39
Furthermore, the Company is required by law and by certain contracts, particularly contracts with financial institutions, to notify various parties, consumers and customers in the event that confidential or personal information may have been or was accessed by unauthorized third parties. Such an event could potentially result in a breach of contract, and any required notifications could result in, among other things, the loss of customers, negative publicity, distraction of management, fines, lawsuits for breach of contract, regulatory inquiries or involvement and a decline in sales.
The Company seeks to mitigate the financial risk associated with unauthorized disclosure of non-public information by maintaining cyber liability insurance coverage. As cybercriminals continue to become more sophisticated, the costs to insure against cyberattacks may rise.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.