We face growing risks and costs related to cybersecurity threats to our operations, our data and customer, franchisee, employee and independent sales agent data, including but not limited to:
- the failure or significant disruption of our operations from various causes, including human error, computer malware, ransomware, insecure software, zero-day threats, threats to or disruption of joint venture partners or of third-party vendors who provide critical services, or other events related to our critical information technologies and systems;- the increasing level and sophistication of cybersecurity attacks, including distributed denial of service attacks, data theft, fraud or malicious or negligent acts on the part of trusted insiders, social engineering, or other unlawful tactics aimed at compromising the systems and data of our businesses, officers, employees, franchisees and company owned brokerage independent sales agents and their customers (including via systems not directly controlled by us, such as those maintained by our franchisees, affiliated independent sales agents, joint venture partners and third party service providers, including our third-party relocation service providers); and - the reputational, business continuity and financial risks associated with a loss of data or material data breach (including unauthorized access to, or destruction or corruption of, our proprietary business information or personal information of our customers, employees and independent sales agents), the transmission of computer malware, cyberattacks, or the diversion of homesale transaction closing funds.
In the ordinary course of our business, we and our third-party service providers, our franchisee and company owned brokerage independent sales agents and our relocation operations collect, store and transmit sensitive data, including our proprietary business information and intellectual property and that of our clients as well as personal information, sensitive financial information and other confidential information of our employees, customers and the customers of our franchisee and company owned brokerage sales agents.
Third parties, including vendors or suppliers that provide essential services for our global operations, could also be a source of security risk to us if they experience a failure of their own security systems and infrastructure. We increasingly rely on third-party data processing, storage providers, and critical infrastructure services, including but not limited to cloud solution providers. The secure processing, maintenance and transmission of this information is critical to our operations and with respect to information collected and stored by our third-party service providers, we are reliant upon their security procedures, which may not be as robust as our own procedures. A breach or attack affecting one of our third-party service providers or partners could harm our business even if we do not control the service that is attacked.
Moreover, the real estate industry is actively targeted by cyber-attacker attempts to conduct electronic fraudulent activity directed at participants in real estate services transactions. These attacks, when successful, can result in fraud, including wire fraud related to the diversion of home sale transaction funds, or other harm, which could result in significant claims and reputational damage to us, our brands, franchisees, and independent sales agents and could also result in material increases in our operational costs. Further, these threats to our business may be wholly or partially beyond our control as our franchisees as well as our customers, franchisee and company owned brokerage independent sales agents and their customers, joint venture partners and third-party service providers may use e-mail, computers, smartphones and other devices and systems that are outside of our security control environment. In addition, real estate transactions involve the transmission of funds by the buyers and sellers of real estate, and consumers or other service providers selected by the consumer may be the subject of direct cyber-attacks that result in the fraudulent diversion of funds, notwithstanding efforts we have taken to educate consumers with respect to these risks.
Cybersecurity incidents, depending on their nature and scope, could result in, among other things, the misappropriation, destruction, corruption or unavailability of critical systems, data and confidential or proprietary information (our own or that of third parties, including personal information and financial information) and the disruption of business operations. The potential consequences of a material cybersecurity incident include regulatory violations of applicable U.S. and international privacy and other laws, reputational damage, loss of market value, litigation with third parties (which could result in our exposure to material civil or criminal liability), diminution in the value of the services we provide to our customers, and increased cybersecurity protection and remediation costs (that may include liability for stolen assets or information), which in turn could have a material adverse effect on our competitiveness and results of operations.
Our security systems and IT infrastructure may not adequately protect against all potential security breaches, cyber-attacks, or other unauthorized access to personal information, including ransomware incidents. We, our third-party service providers, franchisees, franchisee and company owned brokerage independent sales agents, and joint venture partners have experienced and expect to continue to experience these types of threats and incidents. Cyberattacks have led and will likely continue to lead to increased costs to us with respect to preventing, investigating, mitigating, insuring against and remediating these incidents and risks, as well as any related attempted or actual fraud. Our corporate errors and omissions and cybersecurity breach insurance, or that of applicable third parties, may be insufficient to compensate us for losses that may occur.
Moreover, we are required to comply with growing laws and regulations both in the United States and in other countries where we do business that regulate cybersecurity, privacy and related matters. With an increased percentage of our business occurring virtually, there is an increased risk of a potential violation of these expanding laws and regulations. Any significant violations of such laws and regulations could result in the loss of new or existing business, litigation, regulatory investigations, the payment of fines and/or penalties (which may not be covered by cybersecurity breach insurance) and damage to our reputation. Any of the foregoing could have a material adverse effect on our business, financial condition, and results of operations.