A Dark Vector Cognition product

Item 1A. Risk Factors

9K characters. Original on sec.gov · Markdown

Item 1A. Risk Factors

A description of certain factors that may affect our future results and risk factors is set forth in our Annual Report on Form 10-K for the year ended December 31, 2022. Except as set forth below, there have been no material changes to those factors previously disclosed in our 2022 Annual Report on Form 10-K.

The failure to maintain the integrity of our information and other systems or customer information can result in damage to our reputation, subject us to fines, payment of damages, lawsuits and restrictions on our use of data, and have a material adverse effect on our business, financial condition, and results of operations. We collect and process information relating to our employees, guests, and others for various business purposes, including marketing and promotional purposes. The collection and use of personal data are governed by privacy laws and regulations enacted by the various states, the United States and other jurisdictions around the world. Privacy laws and regulations continue to evolve and on occasion may be inconsistent (or conflict) between jurisdictions. Various federal, state and foreign legislative or regulatory bodies may enact or adopt new or additional laws and regulations concerning privacy, data retention, data transfer, and data protection. For example, California has a comprehensive privacy law, known as the California Consumer Privacy Act of 2018 (“CCPA”), which provides some of the strongest privacy requirements in the United States. The CCPA was amended by the California Privacy Rights Act that went into effect in 2023. In addition, new privacy requirements went into effect in 2023 in Colorado, Connecticut, Utah, and Virginia. Outside the United States, the European Union has adopted a data protection regulation known as the General Data Protection Regulation that provides data subjects with significant privacy-related rights and imposes operational and compliance requirements on organizations with significant penalties for non-compliance. Other jurisdictions including Canada and China have also amended or adopted new privacy laws and/or requirements which often include similar requirements and obligations. There may be risks and uncertainties associated with these and other privacy laws and regulations including their interpretation and implementation, as well as the potential extraterritorial effect of certain privacy laws and regulations.

Compliance with applicable privacy laws and regulations increases our operating costs and could adversely impact our ability to market our products, properties and services to our guests. In addition, non-compliance with applicable privacy laws and regulations by us (or in some circumstances non-compliance by third parties engaged by us), including accidental loss, inadvertent disclosure, unapproved dissemination or a breach of security on systems storing our customer data can result in damage to our reputation, subject us to fines, payment of damages, lawsuits or restrictions on our use or transfer of data, and have a material adverse effect on our business, financial condition, and results of operations. We rely on proprietary and commercially available systems, software, and tools to provide security for processing of customer and employee information, such as payment card and other confidential or proprietary information. Our data security measures are reviewed and evaluated regularly; however, they might not protect us against increasingly sophisticated and aggressive threats, like the Cybersecurity Issue that affected us in September 2023.

We also rely extensively on our information and other systems and those of third parties to process transactions, maintain and communicate information, and manage our businesses, including at our properties and on our website and digital platforms. Disruptions in these systems, through cyber-attacks or otherwise, have in the past and can in the future be expected to impact our ability to service our customers and adversely affect our business, financial condition, and results of operations. This can occur notwithstanding the data security measures and disaster recovery plans that we have in place. Further, our systems are not fully redundant and our disaster recovery planning cannot account for all possible scenarios.

There has been an increase in criminal cybersecurity attacks against companies (and third-party service providers) where systems have been breached, businesses disrupted, and customer, employee, and other company information has been compromised or destroyed. Our systems and data, including those we maintain with our third-party service providers, have been subject to cybersecurity breaches in the past of varying degrees and are expected to be subject to cybersecurity breaches in the future.

Our third-party information system and other service providers face risks relating to cybersecurity similar to ours, and we do not directly control any of such parties’ information security or other operations. A significant theft, loss or fraudulent use of customer or company data maintained by us or by a third-party service provider could have an adverse effect on our reputation, cause a material disruption to our operations, and result in remediation expenses, regulatory

penalties and litigation by customers and other parties whose information was subject to such attacks, all of which could have a material adverse effect on our business, results of operations and cash flows.

While we maintain cybersecurity insurance to assist in the cost of recovery from a significant cyber event, such coverage may not be sufficient. A cybersecurity incident also could require that we expend significant additional resources on remediation, restoration, and enhancement of our information technology and other systems.

By way of example, in September 2023, we had a Cybersecurity Issue affecting certain of our systems, in which criminal actors obtained certain personal information of some of our customers. Among other things, this issue resulted in system shutdowns that created operational disruptions at our domestic properties, adversely affected revenues, and subjected us to litigation. For more information, see “Cybersecurity Issue” in Part I, Item 2 - “Management’s Discussion and Analysis of Financial Condition and Results of Operations” as well as “Cybersecurity litigation” in Part I, Item 1, Note 9 to the accompanying consolidated financial statements.

Item 2. Unregistered Sales of Equity Securities and Use of Proceeds

The following table provides information about share repurchases of our common stock during the quarter ended September 30, 2023:

Total Number of Shares PurchasedAverage Price Paid per Share (1)Total Number of Shares Purchased as Part of a Publicly Announced ProgramDollar Value of Shares that May Yet be Purchased Under the Program**(1)**
Period(In thousands)
July 1, 2023 — July 31, 20231,710,723$44.481,710,723$1,285,060
August 1, 2023 — August 31, 20238,673,762$44.208,673,762$900,828
September 1, 2023 — September 30, 20232,175,000$43.512,175,000$806,163

(1) In accordance with applicable disclosure requirements, the “Average Price Paid per Share” figures presented above exclude commissions and other expenses, such as excise taxes, and is calculated on an execution date basis. In contrast, the $2.0 billion amount authorized by the Board of Directors under the February 2023 stock repurchase plan included the cost of commissions as part of the authorized repurchase amount. Figures presented under “Dollar Value of Shares that May Yet be Purchased Under the Program” indicate the total amount of authorized capacity remaining, calculated to include commissions (and exclude excise taxes) in accordance with the amount authorized by the Board of Directors.

In February 2023, we announced that the Board of Directors had authorized a $2.0 billion stock repurchase plan, and, in November 2023, we announced that the Board of Directors had authorized a $2.0 billion stock repurchase plan. Under the stock repurchase plans, we may repurchase shares from time to time in the open market or in privately negotiated agreements. Repurchases of common stock may also be made under a Rule 10b5-1 plan, which would permit common stock to be purchased when we might otherwise be precluded from doing so under insider trading laws. The timing, volume and nature of stock repurchases will be at the sole discretion of management, dependent on market conditions, applicable securities laws, and other factors, and may be suspended or discontinued at any time. All shares we repurchased during the quarter ended September 30, 2023 were purchased pursuant to our publicly announced stock repurchase plan and have been retired.

Previous: Item 4. Controls and Procedures · Next: Item 5. Other Information