Item 1C. Cybersecurity
16K characters. Original on sec.gov · Markdown
Item 1C. Cybersecurity
Risk Management and Strategy
The Company maintains robust and comprehensive processes, procedures and controls to protect and secure its information systems and data infrastructure from cybersecurity threats. The Company’s cybersecurity program is led by its Chief Information Security Officer (“CISO”). The Company’s cybersecurity program interfaces with other functional areas within the Company, including but not limited to the Company’s business segments and information technology, legal, risk management, human resources and internal audit departments, as well as external third-party partners, to identify and understand potential cybersecurity threats. The Company regularly assesses and updates its processes, procedures and management techniques in light of ongoing cybersecurity developments.
Internally, the CISO coordinates oversight of reviewing security alerts, identifying and monitoring ongoing and potential cybersecurity threats, evaluating strategic business impacts of cybersecurity threats and developing programs and initiatives to educate the Company’s employees regarding cybersecurity. The CISO also manages the Company’s Security Incident Response Plan (the “Incident Response Plan”), which outlines action steps for the preparation, identification, triage, analysis, containment, eradication, recovery and reflection stages of a cybersecurity incident. The Incident Response Plan serves as the charter for the Company’s Security Incident Response Team (the “Incident Response Team”), which includes a strategic team comprised of executives from various cross-functional management teams, as well as a tactical team comprised of internal technical support roles and external third-party service providers. The Incident Response Plan provides how the Incident Response Team will analyze and, as necessary, escalate cybersecurity incidents both internally and with third-party service providers based on type and severity of the specific incident.
The Company also requires cybersecurity training for all active employees, focusing on the appropriate protection and security of confidential company and third-party information. Additionally, the Company provides quarterly cybersecurity awareness training that covers a broad range of security topics, including secure access practice, phishing schemes, remote work and response to suspicious activities. In addition to online training, employees are educated through several methods, including event-triggered awareness campaigns, recognition programs, security presentations, company intranet articles, videos, system-generated communications, email publications and various simulation exercises.
The Company has engaged a third-party managed detection and response company to monitor the security of its information systems around-the-clock, including intrusion detection, and to provide instantaneous alerting should a cybersecurity event occur. The Company also maintains a cybersecurity insurance policy and has engaged a third-party digital forensics and incident response consultant and legal counsel on retainer.
The Company does not believe that any risks from cybersecurity threats, nor any previous cybersecurity incidents, have materially affected the Company. However, the sophistication of cyber threats continues to increase, and the preventative actions the Company has taken and continues to take to reduce the risk of cyber incidents and protect its systems and information may not successfully protect against all cyber incidents. For more information on how cybersecurity risk may materially affect the Company’s business strategy, results of operations, or financial condition, please refer to Item 1A Risk Factors.
Governance
The Company’s Audit Committee and Board of Directors provide ultimate oversight of the Company’s cybersecurity risk management. The Audit Committee regularly reviews and discusses with management the strategies, processes, procedures and controls pertaining to the management of the Company’s information technology operations, including cyber risks and cybersecurity. The Company’s Chief Information Officer (“CIO”) provides quarterly reports to the Audit Committee regarding the evolving cybersecurity risk landscape, including emerging risks, as well as the Company’s processes, program and initiatives for managing these risks.
The Company’s CISO reports directly to the CIO, who in turn reports to the CFO. The CISO maintains the certified information systems security professional (CISSP) certification and GIAC G2700 (Certified ISO 27000 Specialist) and has over 20 years of
experience in cybersecurity. Under the direction of the CISO, the Company’s cybersecurity department continuously analyzes cybersecurity and resiliency risks to our business, considers industry trends and implements controls, as appropriate, to mitigate these risks. The team consists of cybersecurity professionals holding multiple certifications such as the CISSP, CEH (Certified Ethical Hacker), GSOM (GIAC Security Operations Manager), GCIA (GIAC Certified Intrusion Analyst), GCFA (GIAC Certified Forensic Analyst), GNFA (GIAC Network Forensic Analyst), GCTI (GIAC Cyber Threat Intelligence), CISM (Certified Information Security Manager) and CISA (Certified Information Systems Auditor). This analysis drives the Company’s long- and short-term cybersecurity strategies, which are executed through a collaborative effort within the IT department and are communicated to the Board of Directors regularly.
I****tem 2. Properties
We have a broad network of distribution and manufacturing facilities in 43 states throughout the U.S. Based on available 2023 U.S. Census data, we have operations in 48 of the top 50 and 89 of the top 100 U.S. Metropolitan Statistical Areas, as ranked by single family housing permits in 2023.
Distribution centers typically include 10 to 15 acres of outside storage, a 45,000 square foot warehouse, 4,000 square feet of office space, and 15,000 square feet of covered storage. The outside area provides space for lumber storage and a staging area for delivery while the warehouse stores millwork, windows and doors, and other specialty building products. The distribution centers are usually located in industrial areas with low cost real estate and easy access to freeways to maximize distribution efficiency and convenience. Many of our distribution centers are situated on rail lines for efficient receipt of goods.
Our manufacturing facilities produce trusses, wall panels, engineered wood, windows, pre-hung doors and custom millwork. Where efficient, they are located on the same premises as our distribution facilities. Truss and panel manufacturing facilities vary in size from 30,000 square feet to 60,000 square feet with eight to 10 acres of outside storage for lumber and for finished goods. Our window manufacturing facility in Houston, Texas is approximately 200,000 square feet.
We own 153 actively operating facilities and contractually lease 418 actively operating facilities. These leases typically have an initial lease term of five to 15 years and most provide options to renew for specified periods of time. A majority of our leases provide for fixed annual rentals. Certain of our leases include provisions for escalating rent, as an example, based on changes in the consumer price index. Most of the leases require us to pay taxes, insurance and common area maintenance expenses associated with the properties. As described in Note 9 to the consolidated financial statements included in Item 8 of this annual report on Form 10-K, 115 of our leased facilities are subject to a sales-lease back transaction that is accounted for in our financial statements as owned assets with offsetting financing obligations.
In addition, we operate a fleet of approximately 18,800 rolling stock units which includes trucks, forklifts, and trailers used to deliver products from our distribution and manufacturing centers to our customers’ job sites. Through our emphasis on local market flexibility and strategically placed locations, we minimize shipping and freight costs while maintaining a high degree of local market expertise. Through knowledge of local homebuilder needs, customer coordination and rapid restocking ability, we reduce working capital requirements and guard against out-of-stock products. We believe that this reliability is highly valued by our customers and reinforces customer relationships.
I****tem 3. Legal Proceedings
The Company has a number of known and threatened construction defect legal claims. While these claims are generally covered under the Company’s existing insurance programs to the extent any loss exceeds the deductible, there is a reasonable possibility of loss that is not able to be estimated at this time because (i) many of the proceedings are in the discovery stage, (ii) the outcome of future litigation is uncertain, and/or (iii) the complex nature of the claims. Although the Company cannot estimate a reasonable range of loss based on currently available information, the resolution of these matters could have a material adverse effect on the Company's financial position, results of operations or cash flows.
In addition, we are involved in various other claims and lawsuits incidental to the conduct of our business in the ordinary course. We carry insurance coverage in such amounts in excess of our self-insured retention as we believe to be reasonable under the circumstances and that may or may not cover any or all of our liabilities in respect of such claims and lawsuits. Although the ultimate disposition of these other proceedings cannot be predicted with certainty, management believes the outcome of any such claims that are pending or threatened, either individually or on a combined basis, will not have a material adverse effect on our consolidated financial position, cash flows or results of operations. However, there can be no assurances that future adverse judgments and costs would not be material to our results of operations or liquidity for a particular period.
Although our business and facilities are subject to federal, state and local environmental regulation, environmental regulation does not have a material impact on our operations. We believe that our facilities are in material compliance with such laws and regulations. As owners and lessees of real property, we can be held liable for the investigation or remediation of contamination on such properties, in some circumstances without regard to whether we knew of or were responsible for such contamination. Our current expenditures with respect to environmental investigation and remediation at our facilities are minimal, although no assurance can be provided that more significant remediation may not be required in the future as a result of spills or releases of petroleum products or hazardous substances or the discovery of unknown environmental conditions.
I****tem 4. Mine Safety Disclosures
Not applicable.
P****ART II
I****tem 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Our common stock is traded on the NYSE under the symbol “BLDR”. The approximate number of stockholders of record of our common stock as of February 15, 2024, was 68.
We currently do not pay dividends. Any future determination relating to dividend policy will be made at the discretion of our board of directors and will depend on a number of factors, including restrictions in our debt instruments, as well as our future earnings, capital requirements, financial condition, prospects and other factors that our board of directors may deem relevant. Our debt agreements currently restrict our ability to pay dividends. See “Management’s Discussion and Analysis of Financial Condition and Results of Operations — Liquidity and Capital Resources” contained in Item 7 of this annual report on Form 10-K.
On December 18, 2023, the Company joined the S&P 500. As such, we have added the S&P 500 index to the comparison of 5-Year cumulative total returns in the graph below and have continued to present the Russell 2000 index in this Annual Report for 2023 as a transitional measure. The graph compares Builders FirstSource, Inc.’s cumulative 5-Year total shareholder return on common stock with the cumulative total returns of the S&P 500 index, Russell 2000 index, and the S&P 600 Building Products index. The graph tracks the performance of a $100 investment in our common stock and in each index (with the reinvestment of all dividends) from December 31, 2018, to December 31, 2023.

| 12/18 | 12/19 | 12/20 | 12/21 | 12/22 | 12/23 | |||||||||||||||||||
| Builders FirstSource, Inc. | 100.00 | 232.91 | 374.06 | 785.61 | 594.68 | 1,530.16 | ||||||||||||||||||
| Russell 2000 | 100.00 | 125.52 | 150.58 | 172.90 | 137.56 | 160.85 | ||||||||||||||||||
| S&P 500 | 100.00 | 131.49 | 155.68 | 200.37 | 164.08 | 207.21 | ||||||||||||||||||
| S&P 600 Building Products | 100.00 | 143.46 | 182.44 | 227.74 | 190.43 | 287.57 |
The stock price performance included in this graph is not necessarily indicative of future stock price performance.
The information regarding securities authorized for issuance under equity compensation plans appears in our definitive proxy statement for our annual meeting of stockholders to be held on June 4, 2024, under the caption “Equity Compensation Plan Information,” which information is incorporated herein by reference.
Company Stock Repurchases
The following table provides information with respect to our purchases of Builders FirstSource, Inc. common stock during the fourth quarter of fiscal year 2023:
| Period | Total Number of Shares Purchased | Average Price Paid per Share (including fees and taxes) | Total Number of Shares Purchased as Part of Publicly Announced Plans or Programs**(1)** | Approximate Dollar Value of Shares That May Yet be Purchased Under the Plans or Programs**(1)** | ||||||||||||
| October 1, 2023 — October 31, 2023 | 55,844 | $ | 124.57 | 55,193 | $ | 400,479,920 | ||||||||||
| November 1, 2023 — November 30, 2023 | 1,553,503 | 132.02 | 1,530,217 | 200,480,050 | ||||||||||||
| December 1, 2023 — December 31, 2023 | — | — | — | 200,480,050 | ||||||||||||
| Total | 1,609,347 | $ | 131.76 | 1,585,410 | $ | 200,480,050 |
(1)
In April 2023, the board of directors approved a share repurchase authorization in the amount of $1.0 billion.
In the fourth quarter of 2023, 1,585,410 shares were repurchased and retired pursuant to share repurchase plans authorized by our board of directors. The remaining 23,937 shares presented in the table above represent shares tendered in order to meet tax withholding requirements for restricted stock units vested. Share repurchases under the program may be made through a variety of methods, which may include open market purchases, block trades, accelerated share repurchases, trading plans in accordance with Rule 10b-5 or Rule 10b-18 under the Exchange Act, or any combination of such methods. The program does not obligate the Company to acquire any particular amount of its common stock, and the share repurchase program may be suspended or discontinued at any time at the Company’s discretion.
I****tem 6. Reserved
Previous: Item 1A. Risk Factors · Next: Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations