Item 1A. RISK FACTORS
12K characters. Original on sec.gov · Markdown
Item 1A. RISK FACTORS
Investing in our securities involves risks. In addition to the risk factor below and information set forth in this Form 10-Q, you should carefully consider the risks and uncertainties described under the section “Risk Factors” in Part I, Item 1A of our Annual Report on Form 10-K filed with the SEC on January 31, 2023 and Part II, Item 1A of our Quarterly Report on Form 10-Q filed with the SEC on July 27, 2023, which could materially and adversely affect our business, financial condition or results of operations. Our business could be harmed by any of these risks or additional risks and uncertainties not presently known to us or that we currently believe to be immaterial. Our stock price could decline due to any of these risks.
Risks Related to the Operation of Our Business
If we or our third-party service providers experience an actual or perceived cybersecurity event, our platform may be perceived as not being secure, and we may lose customers or incur significant liabilities, which would harm our business and operating results.
Our operations involve the storage, transmission and processing of our customers’ confidential, proprietary and sensitive data, which may include personally identifiable information, protected health information, financial information and, in some cases, government information. While we have security measures and a data governance framework in place designed to protect customer information and prevent data loss, these protective mechanisms we have implemented may not be effective at preventing material breaches caused by intentional or unintentional action or inaction by employees or third parties, which may result in the unauthorized access or release of our instances and ultimately our or our customers’ data, IP and other confidential business information. Third parties have attempted to fraudulently induce employees, contractors, or users to disclose information or to gain access to our or our customers’ data, and we have been the target of increasingly sophisticated email and text message scams that attempt to acquire personal information or company assets. Further, we have experienced an increase in the number and sophistication of cyberattacks and security challenges as the growing number of employees, vendors and other third parties that remotely access our systems increase our exposure to attack.
Computer malware, ransomware, viruses, hacking, phishing and denial of service attacks by third parties have become more prevalent in our industry, and similar malicious attacks have been made against our and our third-party service providers’ systems in the past and may occur again in the future. Our employees have fallen victim to phishing attacks in the past and may again in the future. The frequency and sophistication of these attacks have increased, and it appears that cyber crimes and cyber criminal networks, some of which may be state-supported, have substantial resources and may target U.S. enterprises or our customers and their use of our products.
In addition, we have established extensive development and testing environments for our engineers developing new products and features. Security protocols in those environments have necessarily been less rigorous than in environments housing customer data, but a vulnerability or security defect arising out of our development and testing environment could become incorporated in code imported to our environments housing customer data. Similarly, in the unique circumstances where customer data may be utilized in developer environments for testing or learning, that data may be at greater risk. Because techniques used to sabotage, obtain unauthorized access to systems or prohibit authorized access to systems change frequently and generally may not be detected until successfully launched against a target, we have been and may continue to be unable to anticipate these techniques or to implement adequate preventative measures. This has included and may continue to include underlying infiltration of pre-existing systems, including those of our third-party service providers or customers, perpetrated by more sophisticated or state-supported attackers, including foreign cybersecurity attacks on U.S. technology companies and retaliatory cybersecurity attacks stemming from the Russian invasion of Ukraine or other geopolitical tensions. It may also include exploitation of vulnerabilities in third party or open source software code that may be incorporated into our own or our customers’ systems, such as the vulnerability in the Java logging library known as “log4j” identified in late 2021 that affected our industry. The occurrence of these and other more sophisticated or state-supported attack campaigns may increase as geopolitical tensions and intermittent warfare continue or escalate outside of the U.S. For example, due to the Russia-Ukraine conflict, conflict in the Middle East, rising tensions between the U.S. and North Korea and rising tensions with China, we and our customers, third-party vendors and service providers are subject to a heightened risk of cybersecurity attacks, phishing
attacks, viruses, malware, ransomware, hacking or similar breaches from state-supported actors, including attacks that could materially disrupt our systems and operations, supply chain, and ability to make available or sell our products and services.
We devote significant financial and personnel resources to implement and maintain security measures while meeting customer expectations as to the performance of our systems; however, as cybersecurity threats develop and grow more complex and sophisticated over time, such as in connection with geopolitical warfare, we will continue to make significant further investments to protect data and infrastructure, but a residual risk may remain despite our preventative efforts. A security breach suffered by us or our third-party service providers, an attack against our service availability or unauthorized access or loss of data could result in a disruption to our service, litigation, service level agreement claims, indemnification and other contractual obligations, regulatory investigations, government fines and penalties, reputational damage, loss of sales and customers, mitigation and remediation expenses and other significant costs and liabilities. In addition, we may incur significant economic and operational consequences in order to appropriately assess and respond to security incidents and to implement appropriate safeguards to protect against future incidents. We also cannot be certain that insurance coverage will continue to be available on acceptable terms or in sufficient amounts to cover the potentially significant losses that may result from a security incident or an insurer will not deny coverage as to any future claim.
Additionally, as we increase reliance on third-party and public cloud infrastructure, we depend in part on third-party security measures to protect against unauthorized access, cyberattacks and the mishandling of data. However, our ability to monitor our third-party service providers’ data security is limited. Employee error or malfeasance in configuring, maintaining, and using services offered by third-party providers may affect our ability to monitor and secure such services.
While our software is delivered with certain preset configurations, we empower our customers to configure the Now Platform in the manner that best suits their business needs. Further, in most instances, our customers are responsible for administering access to the data held in their particular instance for their employees and service providers. In configuring our platform, ServiceNow employees and customers have made errors in the past and may do so again in the future. We are aware that, on occasion, our customers and ServiceNow have configured certain settings on our platform, or retained preset configurations, in a manner not aligned with their preferred security levels, which can result in, and has resulted in, information being made more widely accessible than intended. Such misconfigurations can be, and have been, identified publicly, increasing the risk of data being exposed unintentionally. We have worked and will continue to work closely with our customers to help them evaluate their security configurations, including providing guidance and taking action designed to help customers align configuration settings with their business needs. In addition, as needed, we have evaluated and modified our own internal configurations, as well as the configurations of the services provided to us by third parties, and will continue to do so. While we offer tools and support, customers are not required to utilize them and may experience a data exposure or suffer a cybersecurity attack on their own systems, unrelated to our own, and allow a malicious actor access to the customer’s information held on our platform. Even if such a breach is unrelated to our security programs or practices, such breach could cause us reputational harm and require us to incur significant economic and operational consequences in order to adequately assess and respond to the breach, including further protecting our customers from their own vulnerabilities, and to implement appropriate safeguards to protect against future breaches. In addition, any misconfiguration or misuse of our software that results in unauthorized access to, or the misuse, loss or destruction of, our and our customers’ data or in a violation of our terms or applicable law may result in reputational harm or liability. Similar risks apply to a breach that results from misconfiguration or misuse of our providers’ services.
Digital supply chain attacks have increased in frequency and severity. We cannot guarantee that third parties and our supply chain infrastructure have not been compromised or that they do not contain exploitable defects or bugs that could result in a breach of or disruption to our platform, systems and network or the systems and networks of third parties that support us and our business. Third parties may also exploit vulnerabilities in, or obtain unauthorized access to, platforms, systems, networks, or physical facilities utilized by us or our third-party vendors or service providers. Furthermore, supply chain disruptions due to the Russian invasion of Ukraine (and resulting legal or regulatory developments) and any indirect effects may further complicate any existing supply chain constraints.
ITEM 2. UNREGISTERED SALES OF EQUITY SECURITIES AND USE OF PROCEEDS
Share repurchases of the Company’s common stock for the three months ended September 30, 2023 were as follows:
| Issuer Purchases of Equity Securities | Total Number of Shares Purchased as Part of Publicly Announced Program (in thousands) | Approximate Dollar Value of Shares that May Yet Be Purchased Under the Program*(1)* (in billions) | ||||||||||||||||||||||||
| Period | Total Number of Shares Purchased (in thousands) | Average Price Paid Per Share | ||||||||||||||||||||||||
| July 1 - 31 | 21 | $ | 579.49 | 21 | $ | 1.49 | ||||||||||||||||||||
| August 1- 31 | 479 | 562.40 | 479 | 1.22 | ||||||||||||||||||||||
| September 1 - 30 | — | — | — | 1.22 | ||||||||||||||||||||||
| Third Quarter 2023 | 500 | $ | 563.11 | 500 | $ | 1.22 |
(1) On May 16, 2023, the Board of Directors authorized a program to repurchase up to $1.5 billion of the Company’s common stock.
Previous: Item 4. CONTROLS AND PROCEDURES · Next: Item 5. OTHER INFORMATION