Item 1A. RISK FACTORS
8K characters. Original on sec.gov · Markdown
Item 1A. RISK FACTORS
In addition to the other information set forth in this report, readers should carefully consider the factors discussed in Item 1A—Risk Factors in the Form 10-K, and in the Company’s other filings with the SEC, which could materially affect the Company’s business, financial condition, cash flows or future results. Other than as set forth below, there have been no material changes from the risk factors previously disclosed in Item 1A—Risk Factors in the Form 10-K.
We are, and may in the future be, subject to physical and cyber attacks.
As owners and operators of critical infrastructure, we face a heightened risk of physical and cyber attacks from internal or external sources. Our water and wastewater systems may be vulnerable to disability or failures as a result of physical or cyber attacks, acts of war or terrorism, vandalism and other causes. Our operational and information technology systems are also vulnerable to unauthorized external or internal access, due to hacking, viruses, social engineering attacks, acts of violence, war or terrorism, and other causes. Unauthorized access to confidential information located or stored on these systems could negatively and materially impact our reputation, customers, employees, suppliers and other third parties. Such unauthorized access could be caused through, among other causes, failure to follow established policies and procedures on the part of our employees, agents, vendors, suppliers, contractors or other third parties. Further, third parties, including vendors, suppliers and contractors, who perform certain services for us or administer and maintain our networks and sensitive information, could also be targets of cyber attacks and unauthorized access to their operational or information technology systems, and any cyber incident affecting our third-party business partners could significantly disrupt our operations. By way of example, on October 7, 2024, we disclosed that, on October 3, 2024, we identified unauthorized activity within our information technology computer networks and systems, which we determined to be the result of a cybersecurity incident. See Part I, Item 2—Management's Discussion and Analysis of Financial Condition and Results of Operations—Other Matters—Cybersecurity Incident for more information regarding this incident.
While we believe that we have appropriate security measures and safeguards to protect our operational and information technology systems, the recent cybersecurity incident that we experienced demonstrated that those protections alone may not prevent a cyber attack, and we cannot guarantee that such protections will be completely successful in preventing or mitigating a future cyber attack. Although the Company is unable to predict the full impact of this incident, the Company does not expect that the incident will have a material effect on the Company or its financial condition or results of operations. An understanding of the full scope, nature and impact of this incident remains subject to our ongoing investigation. The Company remains subject to various risks due to this incident, including those related to the adequacy of processes during the period of disruption, diversion of management’s attention, and litigation and regulatory scrutiny, including from putative class action lawsuits that have been filed in connection with the recent incident. Cybersecurity events could cause our operations to be disrupted, property to be damaged, and customer and other confidential information to be lost or stolen; we could experience substantial loss of revenues, response costs and other financial loss; we would likely suffer a loss or redirection of management time, attention and resources from our regular business operations; we may be subject to increased regulatory requirements; we would likely experience litigation and other claims against us; and we may suffer damage to our reputation, any of which could have a negative impact on our business, financial condition, results of operations and cash flows. Applicable laws and regulations or contracts may require us to report cybersecurity events or breaches of securely maintained confidential data, which may cause us to incur costs related to legal claims or proceedings and regulatory fines or penalties. These types of events, and their resulting impacts, either to our facilities or assets, those of third parties, or the industry in general, may also cause us to incur additional security and insurance related costs. In addition, in the ordinary course of business, we collect and retain sensitive information, including personally identifiable information, about our customers and employees. In many cases, we outsource administration of certain functions to vendors that have been and will continue to be targets of cyber attacks. Any theft, loss or fraudulent use of customer, employee or proprietary data as a result of a cyber attack on us or a vendor, supplier, contractor or other third-party business partner could also subject us to significant litigation, liability and costs, as well as adversely impact our reputation with customers and regulators, among others.
We have obtained insurance to provide coverage for a portion of the losses and damages that may result from a physical attack, cyber attack or a security breach, but such insurance is subject to a number of exclusions and may not cover the total loss or damage caused by an attack or a breach. We have incurred, and may continue to incur, certain expenses related to the cybersecurity incident, including expenses to respond to, remediate and investigate this matter. Although we maintain cybersecurity insurance, the full scope of the costs and related impacts of the recent cybersecurity incident remain subject to investigation, and thus we cannot be certain of the extent to which such coverage or third-party indemnification will cover such costs. In the future, adequate insurance may not be available at rates that we believe are reasonable, and the costs of responding to and recovering from a physical attack, cyber attack or security breach incident may not be covered by insurance or recoverable in rates.
ITEM 2. UNREGISTERED SALES OF EQUITY SECURITIES AND USE OF PROCEEDS
In February 2015, the Board of Directors authorized an anti-dilutive stock repurchase program to mitigate the dilutive effect of shares issued through the Company’s dividend reinvestment and direct stock purchase plan and employee stock purchase and executive compensation activities. The program allows the Company to purchase up to 10 million shares of its outstanding common stock over an unrestricted period of time in the open market or through privately negotiated transactions. The program is conducted in accordance with Rule 10b-18 of the Exchange Act, and, to facilitate these repurchases, the Company enters into Rule 10b5-1 stock repurchase plans with a third-party broker, which allow the Company to repurchase shares of its common stock at times when it otherwise might be prevented from doing so under insider trading laws or because of self-imposed trading blackout periods. Subject to applicable regulations, the Company may elect to amend or cancel the program or the stock repurchase parameters at its discretion to manage dilution.
The Company did not repurchase shares of common stock during the three months ended September 30, 2024. From April 1, 2015, the date repurchases under the anti-dilutive stock repurchase program commenced, through September 30, 2024, the Company repurchased an aggregate of 4,860,000 shares of common stock under the program, leaving an aggregate of 5,140,000 shares available for repurchase under this program.
ITEM 3. DEFAULTS UPON SENIOR SECURITIES
None.
ITEM 4. MINE SAFETY DISCLOSURES
Not applicable.
Previous: Item 4. CONTROLS AND PROCEDURES · Next: Item 5. OTHER INFORMATION