Failures to protect classified or other sensitive information, or cybersecurity incidents could result in significant liability or otherwise have an adverse effect on our business.
Our business requires us to use and protect classified, sensitive, and other protected information as well as business proprietary information and intellectual property (collectively, “sensitive information”). Our computer networks and other IT systems are designed to protect this information through the use of classified networks and other procedures. We routinely experience various cybersecurity incidents, including threats to our information technology infrastructure, unauthorized attempts to gain access to the Company’s sensitive information, and denial-of-service attacks, as do our customers, suppliers, subcontractors, and other business partners. The threats we face vary from attacks common to most industries to attacks by more advanced and persistent, highly organized adversaries, including nation states, which target us and other government contractors because we possess sensitive information. If we are unable to protect sensitive information, our customers or governmental authorities could question the adequacy of our threat mitigation and detection processes and procedures, and depending on the severity of the incident, U.S. government data, the Company’s data, customers’ data, our employees’ data, our intellectual property, and other sensitive information could be compromised. As a consequence of the persistence, sophistication, and volume of these attacks, we may not be successful in defending against all such attacks. Due to the evolving nature of these security threats and the national security aspects of much of the sensitive information we possess, the impact of any future incident cannot be predicted.
We have a number of suppliers and indirect suppliers with a wide variety of systems and cybersecurity capabilities and we may not be successful in preventing adversaries from exploiting possible weak links in our supply chain. We also must rely on this supply chain for detecting and reporting cyber incidents, which could affect our ability to report or respond to cybersecurity incidents in a timely manner. The costs related to cyber or other security threats or disruptions may not be fully insured or indemnified by other means. Further, these suppliers may incorporate generative artificial intelligence tools into their offerings without disclosing this use to us, and the providers of these generative artificial intelligence tools may not meet existing or rapidly evolving regulatory or industry standards with respect to privacy and data protection and may inhibit our or our vendors’ ability to maintain an adequate level of service and experience. If we or our third-party partners experience an actual or perceived breach or privacy or security incident because of the use of generative artificial intelligence, we may lose valuable confidential information and our reputation and the public perception of the effectiveness of our security measures could be harmed.
A material network breach in the security of the IT systems of the Company or third parties for any reason, including, but not limited to, human error, could include the theft of sensitive information, including, without limitation, our and our customers’ business proprietary and intellectual property. To the extent any security breach or human error results in a loss or damage to sensitive information, or an inappropriate or unauthorized disclosure of sensitive information, the breach could cause grave damage to the country’s national security and to our business. Threats, via insider threat or third parties, to our IT systems, are constantly evolving and there is no assurance that our efforts to maintain and improve our IT systems will be sufficient to meet current or future threats. Any event leading to a security breach or loss of, or damage to, sensitive information, whether by our employees or third parties, could result in negative publicity, significant remediation costs, legal liability, and damage to our reputation and could have a material adverse effect on our business, financial condition, results of operations, and cash flows. In an extreme case, the DOE could terminate our permit to access classified information resulting in the elimination of our ability to continue American Centrifuge work or performance of DOE contracts, including the HALEU Operation Contract.
See Part 1, Item 1C, Cybersecurity, for more information on our cybersecurity risk management and governance.