Item 4. Controls and Procedures

16K characters. Original on sec.gov · Markdown

Item 4. Controls and Procedures

The Company’s management, with the participation of the Company’s Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of the Company’s disclosure controls and procedures as of the end of the period covered by this Report. Based on that evaluation, the Chief Executive Officer and Chief Financial Officer concluded that the Company’s disclosure controls and procedures, as of the end of the period covered by this Report, were effective such that the information required to be disclosed by the Company in reports filed under the Exchange Act is (i) recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms and (ii) accumulated and communicated to management, including the Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions regarding required disclosure.

On Monday, August 14, 2023, the Company disclosed it had identified unauthorized activity on some of its Information Technology (IT) systems; see Note 2 in the condensed consolidated financial statements in this Report. That activity began on Friday, August 11, 2023 and after becoming aware of it that evening, the Company immediately began taking steps to stop and remediate the activity. The Company also took certain systems offline and engaged third-party cybersecurity experts to support its investigation and recovery efforts. The Company implemented its business continuity plans, including manual ordering and processing procedures at a reduced rate of operations in order to continue servicing its customers. However, the incident resulted in wide-scale disruptions to the Company’s business operations throughout the remainder of the quarter.

During the disruptions caused by the cyberattack, we deployed additional interim controls in response to taking certain systems offline during the period to maintain our internal control over financial reporting.

Other than the additional interim controls and procedures implemented in connection with the execution of the Company’s existing business continuity plans as a result of the cyberattack discussed above, no change in the Company’s internal control over financial reporting occurred during the first fiscal quarter of the fiscal year ending June 30, 2024, that has materially affected, or is reasonably likely to materially affect, the Company’s internal control over financial reporting.

PART II – OTHER INFORMATION

Item 1.A. Risk Factors

For information regarding Risk Factors, please refer to Item 1.A. in the Company’s Annual Report on Form 10-K for the fiscal year ended June 30, 2023, as supplemented by the following revised risk factor, and the information in “Cautionary Statement” included in this Report.

Failure of key technology systems, cyberattacks, privacy breaches or data breaches could have a material adverse effect on the Company’s business, financial condition, results of operations and reputation.

To conduct its business, the Company relies extensively on information and operational technology systems, many of which are managed, hosted, provided and/or used by third parties and their vendors. These systems include, but are not limited to, programs and processes relating to communicating within the Company and with customers, consumers, vendors, investors and other parties; ordering and managing materials from suppliers; converting materials to finished products; receiving and processing purchase orders and shipping products to customers; processing transactions; storing, processing and transmitting data, including personal confidential information and payment card industry data; hosting, processing and sharing confidential and proprietary research, business and financial information; and complying with financial reporting, regulatory, legal and tax requirements. Furthermore, the Company sells certain of its natural personal care products, vitamins, minerals, supplements and other products directly to consumers online and through websites, mobile apps and connected devices, and the Company also engages in online activities, including promotions, rebates and customer loyalty and other programs, through which it may receive personal information. Through the use of any of these information and operational technology systems or processes, the Company or its vendors have in the past and could in the future again experience cyberattacks, privacy breaches, data breaches or other incidents that may result in unauthorized access, disclosure and misuse of consumer, customer, employee, vendor or Company information, especially as the Company continues operating under a hybrid working model under which employees can work and access the Company’s technology infrastructure remotely. A breach or other breakdown in the Company’s technology, including a cyberattack, privacy breach, data breach or other incident involving the Company or any of the Company's third-party service providers or vendors could adversely affect the Company’s financial condition and results of operations.

On August 14, 2023, the Company disclosed that it had identified unauthorized activity on some of its IT systems and took immediate steps to stop and remediate the activity, including taking certain systems offline. The Company implemented its business continuity plans, including manual ordering and processing procedures at a reduced rate of operations in order to continue servicing its customers, which resulted in an elevated level of consumer product availability issues.

Based on the information currently available, the Company believes the cyberattack is contained due to the steps the Company has taken to address the incident. However, due to the order processing delays and elevated level of product outages, the incident has negatively impacted the Company's fiscal first quarter financial results, and is expected to negatively impact its fiscal 2024 financial results. See “Management’s Discussion and Analysis of Financial Condition and Results of Operations”. Based on its current assessment of the situation, the Company expects to experience ongoing, but lessening, operational impacts in the fiscal second quarter as it makes progress in returning to normalized operations. The cyberattack may also lead to additional regulatory scrutiny or litigation exposure.

The cyberattack also damaged portions of the Company’s IT infrastructure, which caused wide-scale disruption of the Company’s operations. The Company is repairing its infrastructure and is reintegrating the systems that it took offline. For more information regarding this incident, see “Management’s Discussion and Analysis of Financial Condition and Results of Operations” and “Note 2. Cyberattack”.

In addition to repairing its infrastructure as a result of the cyberattack, the Company is in the process of a multi-year phased upgrade of its digital capabilities, including enhancing operating efficiencies and transitioning to a cloud-based platform, as well as replacing its enterprise resource planning system. It also uses various other hardware, software and operating systems that may need to be upgraded or replaced in the near future as such systems cease to be supported by third-party service providers, and may be vulnerable to increased risks, including the risk of further security breaches, system failures and disruptions. Any such upgrade could take time, oversight and be costly to the Company, and may include potential challenges, such as the cost of training personnel, migration of data, the potential instability of the new system and cost overruns. If such systems are not successfully upgraded or replaced in a timely manner, system outages, disruptions or delays, or other issues may arise. If a new system does not function properly or is not adequately supported by third-party service providers and processes, it could adversely affect the Company’s business and operations, which, in turn, could adversely impact the Company’s results of operations and cash flows.

Despite the security measures the Company has in place, the information and operational technology systems, including those of our customers, vendors, suppliers and other third-party service providers with whom we have contracted, have, in the past,

ITEM 1.A. RISK FACTORS (Continued)

and may, in the future, be vulnerable to cyber-threats such as computer viruses or other malicious codes, security breaches, unauthorized access, phishing attacks and other disruptions from employee error, unauthorized uses, system failures, including Internet outages, unintentional or malicious actions of employees or contractors or cyberattacks by hackers, criminal groups, nation-states and nation-state-sponsored organizations and social-activist organizations. The Company’s information and operational technology systems and its third-party providers’ systems, have been, and will continue to be, subject to cyber-threats such as computer viruses or other malicious codes, ransomware, unauthorized access attempts, business email compromise, cyber extortion, denial of service attacks, phishing, social engineering, hacking and other cyberattacks attempting to exploit vulnerabilities. The Company has seen and may continue to see an increase in the number of such attacks, especially as the Company continues operating under a hybrid working model under which employees can work and access the Company’s technology infrastructure remotely. In addition, while we have purchased cybersecurity insurance, costs related to a cyberattack may exceed the amount of insurance coverage or be excluded under the terms of our cybersecurity insurance policy. As cyberattacks increase in frequency and magnitude, we may be unable to obtain cybersecurity insurance in amounts and on terms we view as appropriate for our operations.

The Company’s security efforts and the efforts of its third-party providers may not prevent or timely detect future attacks and resulting breaches or breakdowns of the Company’s, or its third-party service providers’, databases or systems. In addition, if the Company or its third-party providers are unable to effectively resolve such breaches or breakdowns on a timely basis, the Company may experience interruptions in its ability to manage or conduct business, as well as reputational harm, governmental fines, penalties, regulatory proceedings, and litigation and remediation expenses. In addition, such incidents could result in unauthorized disclosure and misuse of material confidential information, including personal identifying information.

Cyber-threats are becoming more sophisticated, are constantly evolving and are being made by groups and individuals with a wide range of expertise and motives, and this increases the difficulty of detecting and successfully defending against them. We have incurred, and will continue to incur, expenses to comply with privacy and data protection standards and protocols imposed by law, regulation, industry standards and contractual obligations. Increased regulation of data collection, use, and retention practices, including self-regulation and industry standards, changes in existing laws and regulations, including reporting requirements, enactment of new laws and regulations, increased enforcement activity, and changes in interpretation of laws, could increase our cost of compliance and operation, limit our ability to grow our business or otherwise harm our business.

In addition, data breaches or theft of personal information collected by the Company and its third-party service providers as well as data breaches or theft of Company information and assets have occurred in the past and may occur in the future. The Company is subject to the laws and regulations of various countries where it operates or does business related to solicitation, collection, processing, transferring, storing or use of consumer, customer, vendor or employee information or related data. These laws and regulations change frequently, and new legislation continues to be introduced and may be interpreted and applied differently from jurisdiction to jurisdiction and may create inconsistent or conflicting requirements. The changes introduced by data privacy and protection regulations increase the complexity of regulations enacted to protect business and personal data and they subject the Company to additional costs and have required, and may in the future require, costly changes to the Company’s security systems, policies, procedures and practices. These laws and regulations also may result in the Company incurring additional expenses and liabilities in the event of unauthorized access to or disclosure of personal data.

These risks also may be present to the extent any of our partners, distributors, joint venture partners or suppliers using separate information or operational technology systems, not integrated with the systems of the Company, suffers a cyberattack and could result in increased costs related to our involvement in investigations or notifications conducted by these third parties. These risks may also be present to the extent a business we have acquired, that does not use our information or operational technology systems, experiences a system shutdown, service disruption, or cyberattack.

Item 2. Unregistered Sales of Equity Securities and Use of Proceeds

In May 2018, the Board of Directors authorized the Company to repurchase up to $2,000 million in shares of common stock on the open market (the 2018 Open-Market Program), which has no expiration date.

In August 1999, the Board of Directors authorized a stock repurchase program to reduce or eliminate dilution upon the issuance of common stock pursuant to the Company’s stock compensation plans (the Evergreen Program). In November 2005, the Board of Directors authorized the extension of the Evergreen Program to reduce or eliminate dilution in connection with issuances of common stock pursuant to the Company’s 2005 Stock Incentive Plan. The Evergreen Program has no expiration date and has no specified limit as to dollar amount and therefore is not included in column [d] below.

The following table sets forth the purchases of the Company’s securities by the Company and any affiliated purchasers within the meaning of Rule 10b-18(a)(3) (17 CFR 240.10b-18(a)(3)) during the first quarter of fiscal year 2024.

[a][b][c][d]
PeriodTotal Number of Shares PurchasedAverage Price Paid per Share (1)Total Number of Shares Purchased as Part of Publicly Announced Plans or ProgramsMaximum Number (or Approximate Dollar Value) of Shares that May Yet Be Purchased Under the Plans or Programs
July 1 to 31, 2023—$——$993 million
August 1 to 31, 2023———$993 million
September 1 to 30, 2023———$993 million
Total—$——

(1)Average price paid per share in the period includes commission.

Previous: Item 3. Quantitative and Qualitative Disclosures About Market Risk · Next: Item 5. Other Information