Our information technology ("IT") networks and related systems are essential to the operation of our business and our ability to perform day-to-day operations and, in some cases, may be critical to the operations of certain of our tenants. While we maintain some of our own critical IT networks and related systems, we also depend on third parties to provide important software, technologies, tools and a broad array of services and operational functions, including payroll, human resources, electronic communications and finance functions. In the ordinary course of our business, we and our third-party service providers collect, process, transmit and store sensitive information and data, including intellectual property, our proprietary business information and that of our customers, suppliers and business partners, as well as personally identifiable information.
We, and our third-party service providers like all businesses, are subject to cyberattacks and security incidents, which threaten the confidentiality, integrity, and availability of our systems and information resources. Those attacks and incidents may be due to intentional or unintentional acts by employees, customers, contractors or third parties, who seek to gain unauthorized access to our or our service providers' systems to disrupt operations, corrupt data, or steal confidential or personal information through malware, computer viruses, ransomware, software or hardware vulnerabilities, social engineering (e.g., phishing attachments to e-mails) or other vectors.
The risk of a cybersecurity attack, breach or operational disruption, particularly through a cyber incident, including by computer hackers, foreign governments or cyber terrorists, has generally increased. Attack methodologies change frequently or are not recognized until launched, and we may be unable to investigate or remediate incidents because attackers increasingly use techniques and tools, including artificial intelligence, that circumvent controls, avoid detection, and remove obscure forensic evidence. There can be no assurance that our cybersecurity risk management program, security controls and security process, or those of our third-party services providers will be fully implemented, complied with, or effective or that attempted security breaches or disruptions would not be successful or damaging.
We have in the past experienced adverse events that have not resulted, and are not expected to result, in a material impact on the Company's business operations or financial results. For example, in February 2023, the Company experienced a criminal ransomware attack affecting data contained on legacy servers of Weingarten Realty Investors ("WRI"). The Company acquired WRI in August 2021. The affected servers and exfiltrated data were on the WRI network. The WRI network is separate and is not connected to the Company's network. The Company promptly initiated an investigation and its response protocols, including deploying containment measures such as taking affected systems offline, implementing enhanced monitoring technology and data recovery processes. The Company also notified federal law enforcement, engaged the services of cybersecurity and forensics professionals, and restored affected systems. The WRI network data is historical and stored for archival purposes. We have acquired in the past and may acquire in the future companies with cybersecurity vulnerabilities or unsophisticated security measures, which could expose us to significant cybersecurity, operational, and financial risks.
A cyber incident could materially affect our operations and financial condition by:
- disrupting the proper functioning of our networks and systems and, therefore, our operations and/or those of certain of our tenants;- resulting in misstated financial reports, violations of loan covenants and/or missed reporting deadlines;- resulting in our inability to properly monitor our compliance with the rules and regulations regarding our qualification as a REIT;- resulting in the unauthorized access to, and destruction, loss, theft, misappropriation or release of proprietary, confidential, sensitive or otherwise valuable information of ours or others, which others could use to compete against us or for disruptive, destructive or otherwise harmful purposes and outcomes;- resulting in our inability to maintain the building systems relied upon by our tenants for the efficient use of their leased space;- requiring significant management attention and resources to remediate systems, fulfill compliance requirements and/or to remedy any damages that result;- subjecting us to regulatory enforcement, including investigative costs and fines or penalties;- subjecting us to litigation claims for negligence, breach of contract or other agreements or other causes of action, potentially resulting in remedies such as damages, credits, penalties or termination of leases or other agreements; or - damaging our reputation among our tenants, investors and associates.
The occurrence or perception of a cyberattack or security incident could result in operational interruption, damage to our relationship with our tenants, and confidential data exposure. In addition, federal and state governments and agencies have enacted, and continue to develop, broad data protection legislation, regulations, and guidance that require companies to increasingly implement, monitor and enforce reasonable cybersecurity measures. These governmental entities and agencies are aggressively investigating and enforcing such legislation, regulations and guidance across industry sectors and companies. We may be required to expend significant capital and other resources to address an attack or incident, including those as a result of the February 2023 incident involving the WRI legacy servers, and our insurance may not cover some or all of our losses resulting from an attack or incident. These losses may include payments for investigations, forensic analyses, legal advice, public relations advice, system repair or replacement, or other services, in addition to any remedies or relief that may result from legal proceedings. The incurrence of these losses, costs or business interruptions may adversely affect our reputation as well as our financial condition, results of operations and cash flows.