Loading...
Loading...
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
Item 1A. Risk Factors
In addition to the other information set forth in this Quarterly Report on Form 10-Q, you should carefully consider the risks and uncertainties described under the heading Risk Factors in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2024 (our 2024 Form 10-K), as supplemented by the below risk factor update. The below risk factor updates the risk factor cacaptioned Security breaches, loss of data, cyberattacks, and other information technology failures could disrupt our operations, damage our reputation, and adversely affect our business, operations, and financial results. in our 2024 Form 10-K. There have been no other maQuarterial changes in our risk factors in the quarter ended March 31, 2025 from those disclosed in our 2024 ly Report on Form 10-K.
Security breaches, loss of data, cyberattacks, and other information technology failures could disrupt our operations, damage our reputation, and adversely affect our business, operations, and financial results.
Our business is highly dependent upon our information technology and telecommunications systems, including Q for the period ended March 31, 2025 (our underwriting and claims systems. We rely on these systems to interact with brokers and insureds, to underwrite business, to prepare policies and process premiums, to perform actuarial and other modeling functions, to process claims and make claims payments, and to prepare internal and external financial statements. Some of these systems may include or rely on third-party systems not located on our premises or under our control. Events such as natural catastrophes, terrorist attacks, industrial accidents, computer viruses and other cyber-attacks may cause our systems to fail or be inaccessible for extended periods of time. While we haQ1 10-Q). There have implemented business contingency plans and other reasonable plans to protect our systems, whether housed internally or through third-party cloud services, sustained or repeated system failures or service denials could severely limit our ability to write and process new and renewal business, provide customer service, pay claims in a timely manner or otherwise operate in the ordinary course of business.
Computer viruses, hackers, employee misconduct, and other external hazards could expose our systems to security breaches, cyber-attacks or other disruptions. While we have implemented security measures designed to protect against breaches of security and other interference with obeen no other material changes in our systems and networks, our systems and networks may be subject to breaches or interference and we, and our third-party service providers, will likely continue to experience cybersecurity incidents of varying degrees. For instance, we recently experienced a data incident in which attackers acquired certain of our data. We currently believe the breach irisk factors immaterial in nature, but we are continuing to investigate. At this time, there is no evidence that a nation-state actor or global hacker was involved or that there has been any misuse of this information. In the event that our investigation results in more significant exposure than we currently believe, our business may be adversely impacted. Any such event may result in operational disruptions as well as unauthorized access to, the disclosure of, or loss of our proprietary information or our customers data and information, which in turn may result in legal claims, regulatory scrutiny and liability, reputational damage, the incurrence of costs to eliminate or mitigate further exposure, the loss of customers or affiliated advisors, or other damage to our business. In addition, SEC and state law requirements regarding general public notification of such incidents could exacerbate the harm to our business, financial condition and results of operations. Even if we successfully protect our technology infrastructure and the confidentiality of sensitive data, we could suffer harm to our business and reputation if attempted security breaches are publicized. We cannot be certain that advances in criminal capabilities, discovery of new vulnerabilities, attempts to exploit vulnerabilities in our systems, data thefts, physical system or network break-ins or inappropriate access, or other developments will not compromise or breach the technology or other security measures protecting the networks and systems used in connection with on the six months ended June 30, 2025 from those disclosed in our 2024 Form 10-K and our business.
Third parties to whom we outsource certain of our functions are also subject to these risks. While we review and assess our third-party providers cybersecurity controls, as appropriate, and make changes to our business processes to manage these risks, we cannot ensure that our attempts to keep systems from being compromised and confidential information from being disclosed will always be successful. Moreover, our increased use of third-party services (e.g. cloud technology and software as a service) can make it more difficult to identify and respond to cyberattacks in any of the above situations due to the dynamic nature of these technologies. These risks could increase as vendors adopt and use more cloud-based software services rather than software services which can be run within our data centers.Q1 10-Q.