6 unchanged sentences
Other than as set forth below, there have been no material changes to the risks described in such Annual Report on Form 10-K.
+Added: Our ability to continue as a going concern depends on, among other factors, our financial condition and operating performance, which are subject to prevailing economic and competitive conditions and certain financial, business and other factors beyond our control.
+Added: Based on our liquidity position at June 30, 2024 and our current forecast of operating results and cash flows, absent any other action, management determined that there is substantial doubt about our ability to continue as a going concern over the twelve months following the filing of this Quarterly Report on Form 10-Q, principally driven by our current debt service obligations, historical negative cash flows and recurring losses.
+Added: Our ability to continue as a going concern is dependent on our ability to service our debt obligations under the Term Loan as they become due, which, in turn, is dependent on, among other factors, our financial condition and operating performance, which are subject to prevailing economic and competitive conditions and certain financial, business and other factors beyond our control.
+Added: Our determination that we may be unable to continue as a going concern may materially harm our business and reputation and may make it more difficult for us to obtain financing for the continuation of our operations, including through equity financings, incurring additional debt or otherwise, which in turn, may adversely impact our financial condition, results of operations and cash flows.
+Added: In the near term, to meet our cash obligations as they come due, we are evaluating strategies to obtain funding for future operations.
+Added: These strategies may include, but are not limited to, obtaining equity financing, debt and/or further restructuring of operations to grow revenues and decrease operating expenses, which include capturing past cost reduction and potential future cost synergies from our past acquisitions.
+Added: In addition, management recently commenced a formal process to divest the Asset, which transaction management intends to close within the twelve months following the filing of this Quarterly Report on Form 10-Q.
+Added: If consummated, this transaction is expected to generate substantial cash proceeds to be used to pay down a portion of the Term Loan and fund future operations.
+Added: There is no assurance that such transaction will close in the subsequent twelve-month period, or at all, and as a result, these cash flows have been excluded from management’s plans to remediate the doubt of going concern.
+Added: The going concern assumption contemplates the realization of assets and satisfaction of liabilities in the normal course of business.
+Added: We may not be able to access additional equity under acceptable terms, and may not be successful in future operational restructurings or at growing our revenue base.
+Added: If we are unable to capture past cost reduction and potential future cost synergies from our past acquisitions or consummate the sale of the Asset on terms favorable to us, or at all, we would likely not have sufficient cash on hand or available liquidity to service our current debt obligations, and our ability to execute on our operating plans may be materially adversely impacted.
+Added: If we become unable to continue as a going concern, we may have to dispose of other or additional assets and might realize significantly less value than the values at which they are carried on our condensed consolidated financial statements.
+Added: These actions may cause stockholders to lose all or part of their investment in our common stock.
+Added: If we cannot continue as a going concern, adjustments to the carrying values and classification of our assets and liabilities and the reported amounts of income and expenses could be required and could be material.
The security or operation of our platform, networks, computer systems or data, or those of third parties upon which we rely, may be breached or otherwise disrupted, and any such breach or other disruption could have an adverse effect on our business and reputation.
In the ordinary course of business, we process proprietary, confidential, and sensitive data, including proprietary and confidential business data, trade secrets, intellectual property, sensitive third-party data, business plans, transactions, financial information, and biometric data (collectively, sensitive information).
−Removed: Certain data privacy and security obligations may require us to implement and maintain specific security measures or industry-standard or reasonable security measures to protect our information technology systems and sensitive information.
−Removed: In particular, the data processed and stored in our platform, networks, and computer systems by customers in the government market may contain highly sensitive data that is subject to protection under government regulations, and we are obligated to comply with stringent requirements related to the security of such data, such as FedRAMP and Criminal Justice Information Services (“CJIS”) security requirements.
−Removed: Individuals or entities may attempt to penetrate our network, computer system or platform security, or that of our third-party hosting and storage providers and other third parties upon which we rely, and could gain access to our sensitive information, including customer data.
+Added: Certain data privacy and security obligations may require us to implement and maintain specific security measures or industry-standard or reasonable security measures designed to protect our information technology systems and sensitive information.
+Added: In particular, the data processed and stored in our platform, networks, and computer systems by customers in the government market may contain highly sensitive data protected under government regulations, and we are obligated to comply with stringent requirements related to the security of such data, such as FedRAMP and Criminal Justice Information Services (“CJIS”) security requirements.
+Added: Individuals or entities have in the past and may in the future attempt to penetrate our network, computer system or platform security, or that of our third-party hosting and storage providers and other third parties upon which we rely, and could gain access to our sensitive information, including customer data.
Some actors now engage and are expected to continue to engage in cyber-attacks, including without limitation, nation-state actors for geopolitical reasons and in conjunction with military conflicts and defense activities.
−Removed: During times of war and other major conflicts, we, the third parties upon which we rely, and our customers may be vulnerable to a heightened risk of these attacks, including retaliatory cyber-attacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell and distribute our services.
+Added: During times of war and other major conflicts, we, the third parties upon which we rely, and our customers may be vulnerable to a heightened risk of these attacks,
+Added: including retaliatory cyber-attacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell and distribute our services.
For example, we have operations and third parties upon which we rely to support our business located in unstable regions and regions experiencing (or expected to experience) geopolitical or other conflicts, including in the Middle East, where businesses have experienced an increase in cyberattacks in relation to the Israel/Hamas conflict.
−Removed: In addition, our network, computer system or platform may be subject to a variety of evolving threats, including but not limited to computer malware (including as a result of advanced persistent threat intrusions), viruses, worms and computer hacking, fraudulent use attempts, phishing and other social engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake), denial-of-service attacks, credential stuffing attacks, credential harvesting, personnel misconduct or error, ransomware attacks, supply-chain attacks, adware, attacks enhanced or facilitated by AI, and other similar threats, all of which have become more prevalent in our industry.
+Added: In addition, our network, computer system or platform are subject to a variety of evolving threats, including but not limited to computer malware (including as a result of advanced persistent threat intrusions), viruses, worms and computer hacking, fraudulent use attempts, phishing and other social engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake), denial-of-service attacks, credential stuffing attacks, credential harvesting, personnel misconduct or error, ransomware attacks, supply-chain attacks and disruptions, adware, attacks enhanced or facilitated by AI, and other similar threats, all of which have become more prevalent in our industry.
In particular, severe ransomware attacks are becoming increasingly prevalent and can lead to significant interruptions in our operations, loss of sensitive information and income, reputational harm, and diversion of funds.
Extortion payments may alleviate the negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to, for example, applicable laws or regulations prohibiting such payments.
−Removed: Our data and information systems may also fail for reasons other than malicious activity, including but not limited to software bugs, server malfunctions, software or hardware failures, loss of data or other information technology assets, telecommunications failures, earthquakes, fires, and floods.
+Added: It may be difficult and/or costly to detect, investigate, mitigate, contain, and remediate a security incident.
+Added: Our efforts to do so may not be successful.
+Added: Actions taken by us or the third parties with whom we work to detect, investigate, mitigate, contain, and remediate a security incident could result in outages, data losses, and disruptions of our business.
+Added: Threat actors may also gain access to other networks and systems after a compromise of our networks and systems .
+Added: Our data and information systems or those of third party service providers on which we rely may also fail for reasons other than malicious activity, including but not limited to software bugs, server malfunctions, software or hardware failures, service outages, loss of data or other information technology assets, telecommunications failures, earthquakes, fires, and floods.
Remote work has become more common and has increased risks to our platform, network, computer systems, and data, as more of our employees utilize network connections, computers and devices outside our premises or network, including working at home, while in transit and in public locations.
1 unchanged sentence
Furthermore, we may discover security issues that were not found during due diligence, and it may be difficult to integrate companies into our information technology environment and security program.
−Removed: These and other threats, attacks, disruptions, or accidents could result in the unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure, access or misappropriation of our proprietary or confidential information, including of our customers and their employees or third parties, and/or damage to our or our third party service providers’ platform, network, or computer systems.
−Removed: For instance, we were recently made aware of an article posted by a security researcher which identified a temporary vulnerability related to two Azure environments related to a limited number of government customers.
−Removed: This vulnerability was not present in our commercial environment, which operates on a different system.
−Removed: The vulnerability was remediated in March 2024, but we have notified our potentially affected customers and are currently investigating the matter.
+Added: These and other threats, attacks, disruptions, outages, or accidents involving us or our third party service providers could result in the unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure, access, unavailability or misappropriation of our proprietary or confidential information, including of our customers and their employees or third parties, and/or damage to our or our third party service providers’ platform, network, or computer systems.
+Added: For instance, in the second quarter of 2024, we were made aware of an article posted by a security researcher which identified a temporary vulnerability related to two Azure environments related to a limited number of government customers.
+Added: The vulnerability was remediated as of June 30, 2024, and we notified our potentially affected customers.
+Added: Our investigation into and response to the matter and this issue has concluded and has not resulted in the loss of any of our customers.
While we have implemented security measures designed to protect against security incidents, there can be no assurance that these measures will be effective.
4 unchanged sentences
These vulnerabilities could be exploited and result in a security incident.
−Removed: Applicable data privacy and security obligations may require us to notify relevant stakeholders of security incidents.
−Removed: Such disclosures are costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences.
+Added: Applicable data privacy and security obligations may require us, or we may voluntarily choose, to notify relevant stakeholders, including affected individuals, customers, regulators, and investors, of security incidents or vulnerabilities, or to take other actions, such as providing credit monitoring and identity theft protection services.
+Added: Such disclosures and related actions are costly, and the disclosure or the failure to comply with such applicable requirements could lead to adverse consequences.
An actual or perceived security breach of our platform, network or computer systems, or those of our technology service providers or third party vendors, could result in adverse consequences such as the loss of business, financial losses, reputational damage, negative publicity, government enforcement actions (for example, regulatory investigations, orders, fines, penalties, audits, and inspections), additional reporting requirements and/or oversight, litigation (including class claims), indemnity obligations, damages for contract breach, civil and criminal penalties (including for violation of applicable laws, regulations or contractual obligations), restrictions on processing sensitive data (including personal data), diversion of management attention, interruptions in our operations (including availability of data), significant costs, fees and other monetary payments for remediation, and other similar harms.
Our contracts may not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our data privacy and security obligations.
−Removed: We cannot be sure that our insurance coverage will be adequate or sufficient to protect us from or to mitigate liabilities arising out of our privacy and security practices, that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims.
+Added: We cannot be sure that our insurance coverage will be adequate or sufficient to protect us from or to mitigate liabilities arising out of our privacy and security
+Added: practices, that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims.
If we fail or are perceived to have failed to maintain the reliability, security and availability of our platform, network, or computer systems, or if customers believe that our platform does not provide adequate security for the storage of sensitive information or its transmission over the Internet, we may lose existing customers and we may not be able to attract new customers, negatively impacting our ability to grow and operate our business.
7 unchanged sentences
Even if such an incident is unrelated to our security practices, it could result in our incurring significant economic and operational costs in investigating, remediating, and implementing additional measures to further protect our customers from their own vulnerabilities, and could result in reputational harm.
−Removed: In addition to security breaches, third parties may gather, collect, or infer sensitive information about us from public sources, data brokers, or other means that reveal competitively sensitive details about our organization and could be used to undermine our competitive advantage or market position.
+Added: In addition to experiencing a security incident, third parties may gather, collect, or infer sensitive information about us from public sources, data brokers, or other means that reveal competitively sensitive details about our organization and could be used to undermine our competitive advantage or market position.
Additionally, our sensitive information or sensitive information of our customers could be leaked, disclosed, or revealed as a result of or in connection with the use of generative AI technologies by our employees, personnel, or vendors.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.