As part of normal operations, we and our third-party vendors and partners, receive and maintain confidential and personally identifiable information ("PII") about our customers and employees, and confidential financial, intellectual property, and other information. We regard the protection of our customer, employee, and company information as critical. The regulatory environment surrounding information security and privacy is very demanding, with the frequent imposition of new and changing requirements some of which involve significant costs to implement and significant penalties if not followed properly. Despite our efforts and technology to secure our computer network and systems, a cybersecurity breach, whether targeted, random, or inadvertent, and whether at the hands of cyber criminals, hackers, rogue employees or other persons, may occur and could go undetected for a period of time, resulting in a material disruption of our computer network, a loss of information valuable to our business, including without limitation customer or employee PII, and/or theft. A similar cybersecurity breach to the computer networks and systems of our third-party vendors and partners, including those that are cloud-based, over which we have no control, may occur, and could lead to a material disruption of our computer network and/or the areas of our business that are dependent on the support, services and other products provided by our third-party vendors and partners. Our computer networks and our business may be adversely affected by such a breach of our third-party vendors and partners, which could result in a decrease in our e-commerce sales and/or a loss of information valuable to our business, including, without limitation, PII of customers or employees. Such a cyber-incident could result in any of the following:
- theft, destruction, loss, misappropriation, or release of confidential financial and other data, intellectual property, customer awards, or customer or employee information, including PII such as payment card information, email addresses, passwords, social security numbers, home addresses, or health information;- operational or business delays resulting from the disruption of our e-commerce sites, computer networks or the computer networks of our third-party vendors and partners and subsequent material clean-up and mitigation costs and activities;- negative publicity resulting in material reputation or brand damage with our customers, vendors, third-party partners or industry peers;- loss of sales, including those generated through our e-commerce websites; and - governmental penalties, fines and/or enforcement actions, payment and industry penalties and fines and/or class action and other lawsuits.
Any of the above risks, individually or in aggregate, could materially damage our reputation and result in lost sales, governmental and payment card industry fines, and/or class action and other lawsuits. Although we carry cybersecurity insurance, in the event of a cyber-incident, that insurance may not be extensive enough or adequate in scope of coverage or amount to reimburse us for damages we may incur. Further, a significant breach of federal, state, provincial, local or international privacy laws could have a material adverse effect on our reputation.