RMR relies on information technology and systems, including the Internet and cloud-based infrastructures and services, commercially available software and its internally developed applications, to process, transmit, store and safeguard information and to manage or support a variety of its business processes (including managing our building systems), including financial transactions and maintenance of records, which may include personal identifying information of employees, tenants and guarantors and lease data. If we or our third party vendors experience material security or other failures, inadequacies or interruptions in our or their information technology and systems, we could incur material costs and losses and our operations could be disrupted. RMR takes various actions, and incurs significant costs, to maintain and protect the operation and security of information technology and systems, including the data maintained in those systems. However, these measures may not prevent the systems' improper functioning or a compromise in security, such as in the event of a cyberattack or the improper disclosure of personally identifiable information.
Security breaches, computer viruses, attacks by hackers, online fraud schemes and similar breaches have created and can create significant system disruptions, shutdowns, fraudulent transfer of assets or unauthorized disclosure of confidential information. The risk of a security breach or disruption, particularly through cyberattack or cyber intrusion, including by computer hackers, foreign governments and cyber terrorists, has generally increased as the intensity and sophistication of attempted attacks and intrusions from around the world have increased. The cybersecurity risks to us or our third party vendors are heightened by, among other things, the evolving nature of the threats faced, advances in computer capabilities, new discoveries in the field of cryptography and new and increasingly sophisticated methods used to perpetrate illegal or fraudulent activities, including cyberattacks, email or wire fraud and other attacks exploiting security vulnerabilities in RMR's or other third parties' information technology networks and systems or operations. Although most of RMR's staff returned to its offices during the pandemic, flexible working arrangements have resulted in a higher extent of remote working than it experienced prior to the pandemic. This and other possible changing work practices have adversely impacted, and may in the future adversely impact, RMR's ability to maintain the security, proper function and availability of its information technology and systems since remote working by its employees could strain its technology resources and introduce operational risk, including heightened cybersecurity risk. Remote working environments may be less secure and more susceptible to hacking attacks, including phishing and social engineering attempts that have sought, and may seek, to exploit remote working environments. In addition, RMR's data security, data privacy, investor reporting and business continuity processes could be impacted by a third party's inability to perform in a remote work environment or by the failure of, or attack on, their information systems and technology. Any failure by RMR or other third party vendors to maintain the security, proper function and availability of RMR's information technology and systems could result in financial losses, interrupt our operations, damage our reputation, cause us to be in default of material contracts and subject us to liability claims or regulatory penalties, any of which could materially and adversely affect our business and the value of our securities.