We face risks associated with security breaches or disruptions, whether through cyber-attacks or cyber intrusions over the Internet, malware, computer viruses, attachments to emails, or persons inside our organization. The risk of a security breach or disruption, particularly through cyber-attacks or cyber intrusion, including by computer hackers, foreign governments, and cyber terrorists, has generally increased as the number, intensity, and sophistication of attempted attacks and intrusions around the world have increased. In the normal course of business, we and our service providers (including service providers engaged in providing web hosting, property management, leasing, accounting and payroll software/services) collect and retain certain personal information provided by our residents, employees, and vendors. We also rely extensively on computer systems to process transactions and manage our business.
Even the most well-protected information, networks, systems, and facilities remain potentially vulnerable because the techniques used in such attempted security breaches evolve and generally are not recognized until launched against a target. In some cases, these breaches are designed to be undetected and, in fact, may not be detected. Accordingly, we and our service providers may be unable to anticipate these techniques or to implement adequate security barriers or other preventative measures, thereby making it impossible to entirely mitigate this risk. The risk of a breach or security failure, particularly through cyber-attacks or cyber-intrusion, has generally increased because of the rise in new technologies and the increased sophistication and activities of the perpetrators of attempted attacks and intrusions. A security breach or other significant disruption involving computer networks and related systems could cause substantial costs and other negative effects, including litigation, remediation costs, costs to deploy additional protection strategies, compromising of confidential information, and reputational damage adversely affecting investor confidence.
The costs of mitigating cybersecurity risks are significant and are likely to increase in the future. These costs include, but are not limited to, retaining services of cybersecurity experts, maintaining insurance, compliance costs arising out of existing and future cybersecurity, data protection, privacy laws, regulations, and related reporting obligations, and costs related to maintaining data backups and other damage-mitigation services.
We previously suffered a ransomware attack on our information technology systems. The incident did not have a material impact on our business, operations, or financial results. However, despite every measure we take to address cybersecurity matters, and although we have not experienced any material losses relating to any cyber-attack, we cannot assure you that we will not suffer losses related to cyber-attacks in the future.