Item 1A. Risk Factors
Item 1A. Risk Factors
As of the date of this Quarterly Report on Form 10-Q, there have been no material changes from the risk factors disclosed in Part I, Item 1A, “Risk Factors” of our Annual Report on Form 10-K for the year ended December 31, 2021, filed with the SEC on March 1, 2022, except as set forth immediately below.
We are subject to governmental export and import requirements that could subject us to liability and restrict our ability to sell our products and services, which could impair our ability to compete in international markets.
We are subject to export controls and economic sanctions laws and regulations that restrict selling, shipping or transmitting our products and services and transferring our technology outside the United States. These requirements also restrict domestic release of software and technology to foreign nationals. In addition, we are subject to customs and other import requirements that regulate imports that are important for our business. If we fail to comply with the U.S. Export Administration Regulations or other U.S. or non-U.S. export requirements (collectively, the “Export Regulations”), we could be subject to substantial civil and criminal penalties, including fines for the Company and the possible loss of the ability to engage in exporting and other international transactions. Due to the nature of our business and technology, the Export Regulations may also subject us to governmental inquiries regarding transactions between us and certain foreign entities.
We believe that current Export Regulations do not materially impact our business at this time, but we cannot predict the impact that additional regulatory changes may have on our business in the future. The Export Regulations are fluid. For example, in October 2022 the U.S. Bureau of Industry and Security (the “BIS”) promulgated broad, novel restrictions that could cover supply of our products and other aspects of our business in connection with China. Also, BIS has placed certain entities on its entity list (the “Entity List”), which restricts supply of items to or in connection with the named entities. Further, in some circumstances the Export Administration Regulations require a license to export an item if the recipient will use the item to design or produce an item for a Huawei-affiliated company or certain other organizations on the Entity List. These regulations can also require licenses for exports that involve Chinese military or intelligence-related end users or end uses.
40
Table of Contents
Future changes in the Export Regulations, including changes in the enforcement and scope of such regulations, may create delays in the introduction of our products or services in international markets or could prevent our customers with international operations from deploying our products or services globally. In some cases, such changes could prevent the export or import of our products or services to certain countries, governments or persons altogether. Any such delays or restrictions could adversely affect our business, financial condition and results of operations.
We are exposed to risks related to information technology infrastructure, information management and protection, cybersecurity threats, and cyber incidents.
We are heavily reliant on our technology and infrastructure, as well as the public cloud to an increasing degree, to provide our products and services to our customers. Additionally, we must frequently expand our internal information system to meet increasing demand in storage, computing and communication, which may result in increased costs. Our internal information system is expensive to expand and must be highly secure due to the sensitive nature of our customers’ information that we transmit. Building and managing the support necessary for our growth places significant demands on our management and resources. These demands may divert these resources from the continued growth of our business and implementation of our business strategy.
We have experienced in the past, and may experience in the future, interruptions in our information systems on which our global operations depend. We may in the future experience unplanned downtime of the infrastructure that delivers our SaaS products. Further, we may face attempts by others to gain unauthorized access through the Internet to our information technology systems whether hosted by us or service providers, to intentionally hack, interfere with, or cause physical or digital damage to or failure of such systems (such as significant viruses or worms), which attempts we or they may be unable to prevent. Our security measures may also be breached due to employee errors, malfeasance, or otherwise. Further, territorial invasions like Russia’s invasion of Ukraine can lead to cybersecurity attacks on technology companies, such as ours, located far outside of the conflict zone. In the event of prolonged business interruptions due to geopolitical events, we could incur significant losses, require substantial recovery time and experience significant expenditures in order to resume our business operations.
In addition, we collect, use, store or disclose (collectively, “process”) an increasingly large amount of personal information, including from employees and customers, in connection with the operation of our business. The personal information we process is subject to an increasing number of federal, state, local and foreign laws regarding privacy and data security, as well as contractual commitments. Any failure or perceived failure by us to comply with such obligations may result in governmental enforcement actions, fines, litigation, or public statements against us by consumer advocacy groups or others and could cause our customers to lose trust in us, which could have an adverse effect on our reputation and business. Additionally, changes to applicable privacy or data security laws could impact how we process personal information, and therefore limit the effectiveness of our solutions or our ability to develop or deliver new products or services. For example, the European Union General Data Protection Regulation imposes stringent data protection requirements and provides for significant penalties for noncompliance of up to the greater of €20 million or four percent of worldwide annual revenues. Regulation is also increasingly occurring at the U.S. state level to supplement federal legislative action or inaction, as indicated by the California Consumer Privacy Act (the “CCPA”), which first became enforceable in 2020, and similar statutes that have been adopted in other states.
41
Table of Contents
Despite our on-going efforts to enhance our network security measures, our information systems are susceptible to computer viruses, cyber-related security breaches and similar disruptions from unauthorized intrusions, tampering, misuse, criminal acts including phishing, or other events or developments that we may be unable to anticipate or fail to mitigate and we are subject to the inherent vulnerabilities of network security measures. For example, in the middle of 2020, we became aware that a malicious third-party actor had fraudulently obtained one-time credentials to a limited set of hosts in a small, segregated part of our network due to a vulnerability in a third-party VPN device. Third parties may also attempt to influence employees, users, suppliers or customers to disclose sensitive information in order to gain access to our, our customers’ or our business partners’ data. Additionally, third parties with whom we work, such as vendors or developers, may violate applicable laws or our policies and such violations can place personal information of our customers at risk. We or our service providers could be unaware of an incident or its magnitude and effects until after it is too late to prevent it and the damage it may cause. Further, because the techniques used to obtain unauthorized access to the information systems change frequently, and may not be recognized until launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures.
The theft, unauthorized use, or a cybersecurity attack that results in the publication of our trade secrets and other confidential business information as a result of such an incident could negatively affect our competitive position, the value of our investment in product or research and development, and third parties might assert against us or our customers claims related to such losses of confidential or proprietary information or end-user data and/or system reliability. We carry insurance that provides some protection against the potential losses arising from a cybersecurity incident, but it will likely not cover all such losses, and the losses it does not cover may be significant. In any such event, our business could be subject to significant disruption, which could impact our revenues or cause customers to cease doing business with us, and we could suffer monetary and/or other losses, including reputational harm, which costs we may not be able to recover from our service providers. Our operations are dependent upon our ability to protect our technology infrastructure against damage from business continuity events that could have a significant disruptive effect on our operations.
Item 2. Unregistered Sales of Equity Securities and Use of Proceeds
There were no stock repurchases during the third quarter of 2022.
Item 3. Defaults Upon Senior Securities
None.
Item 4. Mine Safety Disclosures
None.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.