Item 1A. Risk Factors
Item 1A. Risk Factors
We have described under the heading “Risk Factors” in Part I, Item 1A of our Annual Report on Form 10-K for the year ended July 1, 2022 a number of risks and uncertainties that could cause our actual results of operations and financial condition to vary materially from past, or from anticipated future, results of operations and financial condition. Except as discussed below, there have been no material changes from these risk factors previously described in our Annual Report on Form 10-K for the year ended July 1, 2022. These risks and uncertainties are not the only risks facing us. Additional risks and uncertainties not presently known to us or that we currently deem immaterial may also adversely affect our business, financial condition, results of operations or the market price of our common stock.
The compromise, damage or interruption of our technology infrastructure, systems or products by cyber incidents, data security breaches, other security problems, design defects or system failures could have a material negative impact on our business.
We experience cyber incidents of varying degrees on our technology infrastructure and systems and, as a result, unauthorized parties have obtained in the past, and may obtain in the future, access to our computer systems and networks, including cloud-based platforms. As disclosed in Part I, Item 2, Management’s Discussion and Analysis of Financial Condition and Results of Operations , an unauthorized third party gained access to a number of our systems in March 2023, which caused disruption to parts of our business operations and resulted in various investigation, recovery, and remediation expenses. In addition, the technology infrastructure and systems of some of our suppliers, vendors, service providers, cloud solution providers and partners have in the past experienced, and may in the future experience, such incidents. Cyber incidents can be caused by ransomware, computer denial-of-service attacks, worms, and other malicious software programs or other attacks, including the covert introduction of malware to computers and networks, and the use of techniques or processes that change frequently, may be disguised or difficult to detect, or are designed to remain dormant until a triggering event, and may continue undetected for an extended period of time. Cyber incidents have in the past resulted from, and may in the future result from, social engineering or impersonation of authorized users, and may also result from efforts to discover and exploit any design flaws, bugs, security vulnerabilities or security weaknesses, intentional or unintentional acts by employees or other insiders with access privileges, intentional acts of vandalism or fraud by third parties and sabotage. In some instances, efforts to correct vulnerabilities or prevent incidents have in the past and may in the future reduce the functionality or performance of our computer systems and networks, which could negatively impact our business. We believe malicious cyber acts are increasing in number and that cyber threat actors are increasingly organized and well-financed or supported by state actors, and are developing increasingly sophisticated systems and means to not only infiltrate systems, but also to evade detection or to obscure their activities. Geopolitical tensions or conflicts may create heightened risk of cyber incidents.
Our products are also targets for malicious cyber acts, including those products utilized in cloud-based environments as well as our cloud service offerings. Our cloud services have in the past and may in the future be taken offline as a result of or in order to prevent or mitigate cyber incidents. While some of our products contain encryption or security algorithms to protect third-party content or user-generated data stored on our products, these products could still be hacked or the encryption schemes could be compromised, breached, or circumvented by motivated and sophisticated attackers. Further, our products contain sophisticated hardware and operating system software and applications that may contain security problems, security vulnerabilities, or defects in design or manufacture, including “bugs” and other problems that could interfere with the intended operation of our products. To the extent our products include design defects, suffer system failure or are hacked, or if the encryption schemes are compromised or breached, this could harm our business by requiring us to employ additional resources to fix the errors or defects, exposing us to litigation and indemnification claims and hurting our reputation.
54
Table of Contents
As discussed in Part I, Item 2, Management’s Discussion and Analysis of Financial Condition and Results of Operations with respect to the March 2023 cyber incident, if efforts to breach our infrastructure, systems or products are successful or we are unable to protect against these risks, we could suffer interruptions, delays, or cessation of operations of our systems, and loss or misuse of proprietary or confidential information, IP, or sensitive or personal information. Compromises of our infrastructure, systems or products could also cause our customers and other affected third parties to suffer loss or misuse of proprietary or confidential information, IP, or sensitive or personal information, and could harm our relationships with customers and other third parties and subject us to liability. As a result of actual or perceived breaches, we have in the past experienced and may in the future experience additional costs, notification requirements, civil and administrative fines and penalties, indemnification claims, litigation, or damage to our brand and reputation. All of these consequences could harm our reputation and our business and materially and negatively impact our operating results and financial condition.
55
Table of Contents
Item 6. Exhibits
The exhibits listed in the Exhibit Index below are filed with, or incorporated by reference in, this Quarterly Report on Form 10-Q, as specified in the Exhibit List, from exhibits previously filed with the Securities and Exchange Commission. Certain agreements listed in the Exhibit Index that we have filed or incorporated by reference may contain representations and warranties by us or our subsidiaries. These representations and warranties have been made solely for the benefit of the other party or parties to such agreements and (i) may have been qualified by disclosures made to such other party or parties, (ii) were made only as of the date of such agreements or such other date(s) as may be specified in such agreements and are subject to more recent developments, which may not be fully reflected in our public disclosures, (iii) may reflect the allocation of risk among the parties to such agreements and (iv) may apply materiality standards different from what may be viewed as material to investors. Accordingly, these representations and warranties may not describe the actual state of affairs at the date hereof and should not be relied upon.
56
Table of Contents
EXHIBIT INDEX
Exhibit
Number Description
3.1
Amended and Restated Certificate of Incorporation of Western Digital Corporation, as amended to date (Filed as Exhibit 3.1 to the Company’s Quarterly Report on Form 10-Q (File No. 1-08703) with the Securities and Exchange Commission on February 8, 2006)
3.2
Amended and Restated By-Laws of Western Digital Corporation, as amended effective as of February 10, 2021 (Filed as Exhibit 3.1 to the Company’s Current Report on Form 8-K (File No. 1-08703) with the Securities and Exchange Commission on February 12, 2021)
3.3 Certificate of Designations, Preferences and Rights of Series A Convertible Perpetual Preferred Stock (Filed as Exhibit 3.1 to the Company’s Current Report on Form 8-K (File No. 1-08703) with the Securities and Exchange Commission on February 1, 2023)
10.1
Investment Agreement, dated January 31, 2023, by and between Western Digital Corporation and AP WD Holdings, L.P.†
10.2
Investment Agreement, dated January 31, 2023, by and among Western Digital Corporation, Elliott Associates, L.P. and Elliott International, L.P.†
10.3
Registration Rights Agreement, dated January 31, 2023, by and among Western Digital Corporation, AP WD Holdings, L.P., Elliott Associates, L.P. and Elliott International, L.P. (Filed as Exhibit 10.3 to the Company’s Current Report on Form 8-K (File No. 1-08703) with the Securities and Exchange Commission on February 1, 2023)
10.4
Amended and Restated Letter Agreement, dated January 31, 2023, by and between Western Digital Corporation and Elliott Investment Management L.P. (Filed as Exhibit 10.4 to the Company’s Current Report on Form 8-K (File No. 1-08703) with the Securities and Exchange Commission on February 1, 2023)
31.1
Certification of Principal Executive Officer Pursuant to Section 302 of the Sarbanes-Oxley Act of 2002†
31.2
Certification of Principal Financial Officer Pursuant to Section 302 of the Sarbanes-Oxley Act of 2002†
32.1
Certification of Chief Executive Officer Pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002**
32.2
Certification of Chief Financial Officer Pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002**
101.INS XBRL Instance Document - the instance document does not appear in the Interactive Data File because its XBRL tags are embedded within the Inline XBRL document
101.SCH XBRL Taxonomy Extension Schema Document†
101.CAL XBRL Taxonomy Extension Calculation Linkbase Document†
101.LAB XBRL Taxonomy Extension Label Linkbase Document†
101.PRE XBRL Taxonomy Extension Presentation Linkbase Document†
101.DEF XBRL Taxonomy Extension Definition Linkbase Document†
104 Cover Page Interactive Data File - formatted in Inline XBRL and contained in Exhibit 101
† Filed with this report.
** Furnished with this report.
57
Table of Contents
SIGNATURES
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this Quarterly Report on Form 10-Q to be signed on its behalf by the undersigned thereunto duly authorized.
WESTERN DIGITAL CORPORATION
By: /s/ Gene Zamiska
Gene Zamiska
Senior Vice President, Global Accounting and Chief Accounting Officer
(Principal Accounting Officer and Duly Authorized Officer)
Dated: May 10, 2023
58
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.