Filing text · FY2024 10-K · filed Dec 13, 2024In the conduct of our business, we collect, use, transmit, store, and otherwise process data using information technology systems, including systems owned and maintained by us or our third-party providers. These data include confidential information and intellectual property belonging to us or our customers or other business partners, and personal information of individuals. All information technology systems are subject to disruptions, outages, failures, and security breaches or incidents, which may be caused by a variety of internal and external factors. We and our third-party providers have experienced, and expect to continue to experience, cybersecurity incidents. Cybersecurity incidents may range from physical attacks on our computer system or network infrastructure, to employee or contractor error or misuse or unauthorized use of information technology systems or confidential information, to individual attempts to gain unauthorized access to these information systems, to sophisticated cybersecurity attacks, or advanced persistent threats, any of which may target or impact us directly or indirectly through our third-party providers and global supply chain. Threat actors may also attempt to influence employees, suppliers and other third-party providers, or customers to disclose sensitive information in order to gain access to our, our customers' or business partners' data. Cybersecurity attacks are increasing in number and the attackers are increasingly organized and well-financed, or at times supported by state actors. Geopolitical tensions or conflicts, such as Russia's invasion of Ukraine and increasing tension with China, may create a heightened risk of cybersecurity attacks. To the extent artificial intelligence capabilities improve and are increasingly adopted by threat actors, they may be used to identify vulnerabilities and craft increasingly sophisticated cybersecurity attacks. Artificial intelligence and deepfake technologies could be used to attack information systems by creating more effective phishing emails or social engineering and by exploiting vulnerabilities in electronic security programs utilizing false image or voice recognition. Vulnerabilities, technical errors and other risks may be introduced through the use of artificial intelligence by us, our customers, suppliers and other business partners and third-party providers, or through the use of third-party hardware and software. [removed] Although we are not aware of any cybersecurity incidents impacting our information systems that have been determined to have a material impact on us to date, we continue to devote significant resources to network security, data encryption, and other measures to protect our systems and data from unauthorized access or misuse, and we may be required to expend greater resources in the future, especially in the face of evolving and increasingly sophisticated cybersecurity threats and laws, regulations, and other actual and asserted obligations to which we are or may become subject relating to privacy, data protection, and cybersecurity. We may be unable to anticipate, prevent, or remediate future attacks, vulnerabilities, breaches, or incidents, and in some instances we may be unaware of vulnerabilities or cybersecurity breaches or incidents or their magnitude and effects, particularly as attackers are increasingly able to circumvent controls and remove forensic evidence. Cybersecurity incidents, including cybersecurity incidents on third-party provider networks, may result in business disruption; delay in the development and delivery of our products; disruption of our manufacturing processes, internal communications, interactions with customers and suppliers and processing and reporting financial results; the theft or misappropriation of intellectual property; corruption, loss of, or inability to access (e.g., through ransomware or denial of service) confidential information and critical data (i.e., that of our company and our third-party providers and customers); reputational damage; private claims, demands, and litigation or regulatory investigations, enforcement actions, or other proceedings related to contractual or regulatory privacy, cybersecurity, data protection, or other confidentiality obligations; diminution in the value of our investment in research, development and engineering; and increased costs associated with the implementation of cybersecurity measures to detect, deter, protect against, and recover from such incidents. Our efforts to comply with, and changes to, laws, regulations, and contractual and other actual and asserted obligations concerning privacy, cybersecurity, and data protection, including developing restrictions on cross-border data transfer and data localization, could result in significant expense, and any actual or alleged failure to comply could result in inquiries, investigations, and other proceedings against us by regulatory authorities or other third parties. Customers and third-party providers increasingly demand rigorous contractual provisions regarding privacy, cybersecurity, data protection, confidentiality, and intellectual property, which may increase our overall compliance burden.