Item 1A. Risk Factors
Item 1A. Risk Factors
Other than as set forth below, there have been no material changes in the risk factors faced by the Company from those disclosed in the Company’s Annual Report on Form 10-K for the year ended December 31, 2025.
Our business is heavily reliant on information technology systems, facilities, and processes; and a disruption in those systems, facilities, and processes, or a breach, including cyber-attacks, in the security of our systems, could have significant, negative impacts on our business, result in the disclosure of confidential information, and create significant financial and legal exposure for us.
Our businesses are dependent on our ability and the ability of our third-party service providers to process, record and monitor a large number of transactions and personally identifiable information. If the financial, accounting, data processing or other operating systems and facilities fail to operate properly, become disabled, experience security breaches or have other significant shortcomings, our results of operations could be materially, adversely affected.
Although we and our third party service providers devote significant resources to maintain and regularly upgrade our systems and processes that are designed to protect the security of computer systems, software, networks and other technology assets and the confidentiality, integrity and availability of information belonging to us and our customers, there is no assurance that our security systems and those of our third-party service providers will provide absolute security. Financial services institutions and companies engaged in data processing have reported breaches in the security of their websites or other systems, some of which have involved sophisticated and targeted attacks intended to obtain unauthorized access to confidential information, destroy data, disable or degrade service, or sabotage systems, often through the introduction of computer viruses or malware, cyber-attacks and other means. Certain financial institutions in the United States have also experienced attacks from technically sophisticated and well-resourced third parties that were intended to disrupt normal business activities by making internet banking systems inaccessible to customers for extended periods. These “denial-of-service” attacks have not breached our data security systems, but require substantial resources to defend, and may affect customer satisfaction and behavior. We, our customers, regulators and other third parties, including other financial services institutions and companies engaged in data processing, have been subject to, and are likely to continue to be the target of, cyber-attacks. The techniques used in cyber-attacks change rapidly and are increasingly sophisticated, including through the use of generative artificial intelligence and deepfakes, and we expect in the future through the use of quantum computing, and we may not be able to anticipate cyber-attacks or data security breaches.
74
Despite our efforts and those of our third party service providers to ensure the integrity of our systems, it is possible that we may not be able to anticipate or to implement effective preventive measures against all security breaches of these types, especially because the techniques used change frequently or are not recognized until launched, and because security attacks can originate from a wide variety of sources, including persons who are involved with organized crime or associated with external service providers or who may be linked to terrorist organizations or hostile foreign governments. Those parties may also attempt to fraudulently induce employees, customers or other users of our systems to disclose sensitive information in order to gain access to our data or that of our customers or clients. These risks may increase in the future as artificial intelligence continues to evolve and we continue to increase our mobile payments and other internet-based product offerings and expand our internal usage of web-based products and applications. Furthermore, because certain of our employees are working, or may work, remotely, there is an increased risk of disruption to our systems because remote networks and infrastructure may not be as secure as in our office environment. If our security systems were penetrated or circumvented, it could cause serious negative consequences for us, including significant disruption of our operations, misappropriation of our confidential information or that of our customers, or damage our computers or systems and those of our customers and counterparties, and could result in violations of applicable privacy and other laws, financial loss to us or to our customers, loss of confidence in our security measures, customer dissatisfaction, significant litigation exposure, and harm to our reputation, all of which could have a material adverse effect on us.
Additionally, as cyber-attacks continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities or incidents.
If we are unsuccessful in developing new, and adapting our current, products and services so that they respond to changing industry standards and customer preferences, our business may suffer.
We provide a variety of commercial and consumer banking, as well as other financial, products and services designed to meet a broad range of needs. While many of these products and services are traditional both in their characteristics and their delivery channels, advancements in technology, changes in the regulatory environment, and evolving customer preferences require that we continuously evaluate the terms under which we provide our existing products and services (including, among other things, interest rates and loan covenants), the methods by which we deliver them (including the use of online and mobile banking), whether to partner with a FinTech company or other third-party vendor to provide products and services, and the potential for new products and services in order to remain competitive. These efforts, though, could require substantial investments, and we can provide no assurance that we will develop new products and services, or adequately adapt our existing products and services, in a timely or successful manner. Our inability to do so could harm our business and adversely affect our results of operations and reputation. Furthermore, any new line of business and/or new product or service could require the establishment of new key and other controls and have a significant impact on our existing system of internal controls. Failure to successfully manage these risks in the development and implementation of new lines of business and/or new products or services could have a material adverse effect on our business and, in turn, our financial condition and results of operations.
Recently, the financial services industry has experienced rapid developments in artificial intelligence, including agentic artificial intelligence. The use of artificial intelligence models developed by third parties introduces risks related to how those models are developed, trained, and deployed, including unauthorized material in training data and limited visibility into risk mitigation steps. The legal and regulatory environment for artificial intelligence is uncertain and rapidly involving, potentially increasing compliance costs and risks of noncompliance. We may be exposed to the risk that generative artificial intelligence models may produce incorrect outputs, release confidential information, reflect biases, or otherwise cause harm. Their complexity may make it challenging to understand all outputs and comply with documentation or explanation requirements. Further, regulators have warned financial institutions of an increased risk of cyber attacks with the use of artificial intelligence. Any of these risk could adversely affect our business, expose us to liability or other adverse legal or regulatory consequences, or otherwise adversely affect our financial results.
75