We are subject to cyber security attacks. These cyber attacks can vary in scope and intent from attacks with the objective of compromising our systems, networks, and communications for economic gain or with the objective of disrupting, disabling or otherwise compromising our maritime and/or shoreside operations. The attacks can encompass a wide range of methods and intent, including phishing attacks, generative artificial intelligence impersonation, illegitimate requests for payment, theft of intellectual property, theft of confidential or non-public information, installation of malware, installation of ransomware and theft of personal or business information. The frequency and sophistication of, and methods used to conduct, these attacks, have increased over time.
A successful cyber security attack may target us directly, or it may be the result of a third party's inadequate care, or resulting from vulnerabilities in licensed software. In either scenario, the Company may suffer damage to its systems and data that could interrupt our operations, adversely impact our brand reputation, and expose us to increased risks of governmental investigation, litigation, fines, and other liability, any of which could adversely affect our business. Furthermore, responding to such an attack and mitigating the risk of future attacks could result in additional operating and capital costs in technology, personnel, monitoring and other investments.
We are also subject to various risks associated with the collection, handling, storage, and transmission of sensitive information. In the regular course of business, we collect employee, customer, and other third-party data, including personally identifiable information and individual payment data, for various business purposes. Although we have policies and procedures in place to safeguard such sensitive information, this information has been and could be subject to cyber security attacks and the aforementioned risks. In addition, we are subject to federal, state, and international laws relating to the collection, use, retention, security and transfer of personally identifiable information and individual payment data. Those laws include, among others, the European Union General Data Protection Regulation and similar state agencies that impose additional cyber security requirements. Complying with these and other applicable laws has caused, and may cause, us to incur substantial costs or require us to change our business practices, and our failure to do so may expose us to substantial fines, penalties, restrictions, litigation, or other expenses and adversely affect our business. Further, any changes to laws or regulations, including new restrictions or requirements applicable to our business, or an increase in enforcement of existing laws and regulations, could expose us to additional costs and liability and could limit our use and disclosure of such information.
While we continue to evolve our cyber security practices in line with our business' reliance on technology and the changing external threat landscape, and we invest time, effort and financial resources to secure our systems, networks and communications, our security measures cannot provide absolute assurance that we will be successful in preventing or defending from all cyber security attacks or incidents impacting our operation. There can be no assurance that any breach or incident will not have a material impact on our operations and financial results.
Any breach, theft, loss, or fraudulent use of guest, employee, third-party or company data, could adversely impact our reputation and brand and our ability to retain or attract new customers, and expose us to risks of data loss, business disruption, governmental investigation, litigation and other liability, any of which could adversely affect our business. Significant capital investments and other expenditures could be required to remedy the problem and prevent future breaches, including costs associated with additional security technologies, personnel, experts and credit monitoring services for those whose data has been breached. Further, if we or our vendors experience significant data security breaches or fail to detect and appropriately respond to significant data security breaches, we could be exposed to government enforcement actions and private litigation.