Item 1A. RISK FACTORS
6K characters. Original on sec.gov · Markdown
Item 1A. RISK FACTORS
In addition to the other information set forth in this report and the risk factor noted below, you should carefully consider the factors discussed in Part I—Item 1A. "Risk Factors" in our Annual Report, which could materially affect our business, financial condition and/or future results. The risks described in our Annual Report and herein are not the only risks facing us.
Additional risks and uncertainties not currently known to us or that we currently deem to be immaterial may also materially adversely affect our business, financial condition, cash flows and/or future results.
A breach of our information systems could cause material financial or reputational harm.
Our information systems have been, and may continue to be in the future, the target of cyber-attacks or other security breaches, which, if successful, could, among other things, cause a disruption to our operations, expose us to the loss of key business, employee, customer or vendor information, cause us to breach our legal, regulatory or contractual obligations, generate a disruption in the continuity of our business applications and services, create an inability to access or rely upon critical business records, cause reputational damage, or impact the costs or ability to obtain adequate insurance coverage. These breaches may result from human errors, equipment failure, or fraud or malice on the part of employees or third parties. A breach of our information systems, including the March 2021 cybersecurity incident disclosed in Part 1 - Item 2. Management's Discussion and Analysis of Financial Condition and Results of Operations in this report, could subject us to litigation, including class action or derivative lawsuits, regulatory fines, and penalties, any of which could have a significant negative impact on our cash flows, competitive position, financial condition or results of operations. If our information systems suffer outages, we could experience delays and disruptions in our business, including brewery operations, production and shipments, such as those we experienced with the March 2021 cybersecurity incident. In addition, if our information systems suffer severe damage, disruption or shutdown, such as those we experienced with the March 2021 cybersecurity incident, we could experience delays in reporting our financial results, and we may lose revenue and profits as a result of our inability to timely invoice and collect payments from our customers. We have seen an increase in the number of such attacks recently as a large number of our employees are working remotely and accessing our technology infrastructure remotely as a result of the coronavirus pandemic. In addition, the March 2021 cybersecurity incident may embolden other individuals or groups to target our information systems and impact the costs or ability for us to obtain adequate insurance coverages moving forward. Further, such attacks may originate from nation states or attempts by outside parties, hackers, criminal organizations or other threat actors.
We expend significant financial resources to protect against threats and cyber-attacks and may be required to further expend financial resources to alleviate problems caused by physical, electronic and cyber security breaches, including the potential for increased ongoing expenses related to the March 2021 cybersecurity incident and to address possible increased information system attacks as a result of the incident. As techniques used to breach security are growing in frequency and sophistication and are generally not recognized until launched against a target, regardless of our expenditures and protection efforts, we may not be able to implement security measures in a timely manner or, if and when implemented, these measures could be circumvented. We could also be required to spend significant financial and other resources to remedy the damage caused by a security breach or to repair or replace networks and information systems, which could have a material adverse effect on our business and financial results. For example, we incurred certain incremental net one-time costs of $2.4 million in the nine months ended September 30, 2021 related to consultants, experts and data recovery efforts, net of insurance recoveries.
Misuse, leakage or falsification of information could result in a violation of data privacy laws and regulations, such as the European Union's General Data Protection Regulation, damage our reputation and credibility or expose us to increased risk of lawsuits, loss of existing or potential future customers and/or increases in our security costs, any of which could have a material adverse effect on our business and financial results. In addition, we may suffer financial and reputational damage because of lost or misappropriated confidential information and may become subject to legal action and increased regulatory oversight or consumers may avoid our brands due to negative publicity. In the event of a breach resulting in loss of data, such as personally identifiable information or other such data protected by data privacy or other laws, we may be liable for damages, fines and penalties for such losses under applicable regulatory frameworks despite not handling the data. Further, the regulatory framework around data custody, data privacy and breaches varies by jurisdiction and is an evolving area of law. We may not be able to limit our liability or damages in the event of such a loss.
ITEM 2. UNREGISTERED SALES OF EQUITY SECURITIES AND USE OF PROCEEDS
None.
ITEM 3. DEFAULTS UPON SENIOR SECURITIES
None.
ITEM 4. MINE SAFETY DISCLOSURES
Not applicable.
Previous: Item 4. CONTROLS AND PROCEDURES · Next: Item 5. OTHER INFORMATION