Item 1A. Risk Factors
Item 1A. Risk Factors
As a smaller reporting company, the Company is not required to provide the information contained in this item pursuant to Regulation S-K. However, information regarding the Company’s risk factors appears in Part I, Item 1A. of its Annual Report on Form 10-K for the year ended December 31, 2022 (the "Annual Report"). These risk factors describe some of the assumptions, risks, uncertainties, and other factors that could adversely affect the Company’s business or that could otherwise result in changes that differ materially from management’s expectations. Other than as set forth hereinbelow, there have been no material changes to the risk factors contained in the Annual Report.
The occurrence of cybersecurity incidents, or a deficiency in our cybersecurity or in those of any of our third-party service providers, could negatively impact our business by causing a financial loss, significant disruption to our operations, a compromise or corruption of our confidential information or damage to our business relationships or reputation, all of which could negatively impact our business, financial condition and results of operations.
In September 2023, we experienced a cybersecurity incident resulting from a fraudulent email sent to our finance department which resulted in our initiating a $0.7 million electronic payment to a fraudulent bank account. We are awaiting receipt of a formal response from the recipient's bank (Chase Bank) following its investigation into this matter and we are pursuing all channels through our bank to recover these funds. We have also initiated, and are pursuing, a claim under our cybersecurity insurance coverage to recover this amount. Despite our ongoing efforts, there is no assurance that we will recover this amount. As a result of this incident, we immediately launched an internal investigation, and engaged a cybersecurity consultant to fully assess the incident and recommend remediation measures.
As cybersecurity threats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any security vulnerabilities. While we have implemented the remediation measures recommended by our cybersecurity consultant, such measures may not prevent all such events in the future. We will continually assess cybersecurity threats and make investments to increase internal protection, detection, and response capabilities to address this risk. To date, other than the incident described above, we have not experienced any material impact to our financial condition, business or operations resulting from cybersecurity attacks. However, because of the frequently changing attack techniques, along with the increasing volume and sophistication of the attacks, there is the potential for us to be adversely impacted. This impact could result in reputational, competitive, operational or other business harm as well as financial losses and costs, all of which could negatively impact our business, financial condition and results of operations.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.