As part of our business, we collect, process and retain sensitive and confidential client and customer information in both paper and electronic form and rely heavily on communications and information systems for these functions. This information includes non-public, personally-identifiable information that is protected under applicable federal and state laws and regulations. Additionally, certain of these data processing functions are not handled by us directly, but are outsourced to third-party providers. We have experienced cyber-attacks in the past, none of which have had a material impact on our business or operations, and expect to continue to be the target of cyber-attacks. Our current facilities and systems, as well as those of our third-party service providers, may be vulnerable to security breaches, acts of vandalism and other physical security threats, computer viruses or compromises, ransomware attacks, misplaced or lost data, programming and/or human errors or other similar events. While we have policies, procedures and practices designed to prevent or limit the effect of the failure, interruption, or security breach of our communications and information systems, we cannot completely ensure that any such failures, interruptions, or security breaches will not occur or, if they do occur, that they will be adequately addressed. Any security breach involving the misappropriation, loss or other unauthorized disclosure of our confidential business, employee or customer information, whether originating with us, our vendors or retail businesses, could severely damage our reputation, expose us to the risks of civil litigation and liability, require the payment of regulatory fines or penalties or undertaking of costly remediation efforts with respect to third parties affected by a security breach, disrupt our operations, and have a material adverse effect on our business, financial condition and results of operations.
The cost of our day-to-day cybersecurity monitoring and protection systems and controls may increase over time. We may also need to expend substantial resources to comply with the data security breach notification requirements adopted by banking regulators and the states, which have varying levels of individual, consumer, regulatory or law enforcement notification and remediation requirements in certain circumstances in the event of a security breach.
Cybersecurity risks appear to be growing and, as a result, the cyber-resilience of banking organizations is of increased importance to federal and state banking agencies and other regulators. New or revised laws and regulations may significantly impact our current and planned privacy, data protection and information security-related practices, the collection, use, sharing, retention and safeguarding of consumer and employee information, and current or planned business activities. Compliance with current, proposed, or future privacy, data protection and information security laws to which we are subject could result in higher compliance and technology costs and could restrict our ability to provide certain products and services, which could materially and adversely affect our profitability.
As technology advances, the ability and speed to initiate transactions and access data has also become more widely distributed among mobile devices, personal computers, automated teller machines, remote deposit capture sites and similar access points, some of which are not controlled or secured by us. It is possible that we could have exposure to liability and suffer losses as a result of a security breach or cyber-attack that occurred through no fault of ours. Although we maintain specific "cyber" insurance coverage, the amount or form of coverage may not be adequate in any particular case. As cyber threats continue to evolve and increase, we may be required to spend significant additional resources to continue to modify or enhance our protective and preventative measures or to investigate and remediate any information security vulnerabilities.