Farmer Mac relies heavily on technology and information systems, including from third parties, for the secure collection, processing, transmission, and storage of confidential, proprietary, and personal information in its information systems (and those of third parties) to conduct and manage its business operations. These technology and information systems encompass an integrated set of hardware, software, infrastructure, and personnel organized to facilitate the planning, control, coordination, operations, and decision-making processes within Farmer Mac. As the importance and complexity of Farmer Mac's technology and information systems has increased, and as new technologies are developed that are used by its customers, Farmer Mac, or its service providers to support its business and operations, the risks posed to Farmer Mac's information systems and data from cybersecurity attacks that threaten the confidentiality, integrity, or availability of Farmer Mac's information technology assets and resources and its data have increased. Like many other financial institutions, Farmer Mac and its third party service providers face regular attacks by threat actors attempting to gain unauthorized access to, or disrupt, its information systems and access or acquire its data, including from organized criminal groups, hackers, nation states, activists, insiders, and other unauthorized third parties. These threats come from a variety of different sources, including cyber-attacks, computer viruses, malware, exploits of system and network vulnerabilities, human error, phishing, ransomware, and distributed denial of service attacks. The threats Farmer Mac faces and the methods used to gain unauthorized access to or disrupt its information systems and data, or those of its service providers, are evolving. Farmer Mac is not always able to prevent or recognize attacks, and Farmer Mac's existing cybersecurity defenses may not be sufficient to detect attacks in a timely manner. Also, Farmer Mac may be unable to implement effective preventive measures or proactively address these threats until after a cybersecurity incident has been discovered. Moreover, any employees or agents of Farmer Mac's (or its third-party customers or vendors) who have authorized access to confidential, proprietary, or personal information could also intentionally, inadvertently, or erroneously disseminate the information to unauthorized third parties.
Farmer Mac's current information security program with cybersecurity procedures, policies, practices, and controls, may not be sufficient to prevent unauthorized access to its information technology assets or data, which could lead to a significant disruption to business operations; unauthorized access to or acquisition, destruction, alteration, release, theft, or loss of confidential, proprietary, or personal data; fraud (on Farmer Mac and/or its customers); extortion; financial and economic loss or costs; errors in its financial statements; impairment of its liquidity; harm to employees, customers, or vendors; liability or service interruptions to its customers; loss of customers or vendors; violation of data protection laws and other litigation and legal risk; increased regulatory or legislative scrutiny; or reputational damage. Farmer Mac also could be subject to litigation and government enforcement actions as a result of any such failure. Any such claim or proceeding could cause us to incur significant unplanned expenses in excess of Farmer Mac's insurance coverage, which could adversely affect Farmer Mac's financial condition and results of operations. The amount and scope of insurance Farmer Mac maintains may not cover all expenses related to such claims. Also, Farmer Mac's service providers may also experience interruptions to their technology, facilities, and information systems that could adversely impact Farmer Mac and over which Farmer Mac may have limited or no control. Finally, the risk of unauthorized access to confidential, proprietary, or personal information through information system breaches or inadvertent dissemination may be heightened in a remote-working environment, which is currently more prevalent at Farmer Mac.