Moody’s Operations and Infrastructure May Malfunction or Fail.
Moody’s ability to conduct business may be materially and adversely impacted by a disruption in the infrastructure that supports its businesses and the communities in which Moody’s is located, including New York City, the location of Moody’s headquarters, major cities worldwide in which Moody’s has offices, and locations in China used for certain Moody’s back office work. This may include a disruption involving physical or technological infrastructure (whether or not controlled by the Company), including the Company’s electronic delivery systems, data center facilities, or the Internet, used by the Company or third parties with or through whom Moody’s conducts business. Many of the Company’s products and services are delivered electronically and the Company’s customers depend on the Company’s ability to receive, store, process, transmit and otherwise rapidly handle very substantial quantities of data and transactions on computer-based networks. Some of Moody’s operations require complex processes and, although the Company has instituted extensive controls to reduce the risk of error inherent in our operations, such risk cannot be completely eliminated. The Company’s customers also depend on the continued capacity, reliability and security of the Company’s telecommunications, data centers, networks and other electronic delivery systems, including its websites and connections to the Internet. The Company’s employees also depend on these systems for internal use. Any significant failure, compromise, cyber-breach, interruption or a significant slowdown of operations of the Company’s infrastructure, whether due to human error, capacity constraints, hardware failure or defect, natural disasters, fire, power loss, telecommunication failures,break-ins, sabotage, intentional acts of vandalism, acts of terrorism, political unrest, war or otherwise, may impair the Company’s ability to deliver its products and services.
Moody’s efforts to secure and plan for potential disruptions of its major operating systems may not be successful. The Company relies on third-party providers to provide certain essential services. While the Company believes that such providers are reliable, the Company has limited control over the performance of such providers. To the extent any of the Company’s third-party providers ceases to provide these services in an efficient, cost-effective manner or fails to adequately expand its services to meet the Company’s needs and the needs of the Company’s customers, the Company could experience lower revenues and higher costs. Additionally, although the Company maintains processes to prevent, detect and recover from a disruption, the Company also does not have fully redundant systems for most of its smaller office locations andlow-risk systems, and its disaster recovery plan does not include restoration ofnon-essential services. If a disruption occurs in one of Moody’s locations or systems and its personnel in those locations or those who rely on such systems are unable to utilize other systems or communicate with or travel to other locations, such persons’ ability to service and interact with Moody’s customers may suffer. The Company cannot predict with certainty all of the adverse effects that could result from the Company’s failure, or the failure of a third party, to efficiently address and resolve these delays and interruptions. A disruption to Moody’s operations or infrastructure may have a material adverse effect on its reputation, business, operating results and financial condition.
The Company is Exposed to Risks Related to Cybersecurity and Protection of Confidential Information.
The Company’s operations rely on the secure processing, storage and transmission of confidential, sensitive, proprietary and other types of information relating to its business operations and confidential and sensitive information about its customers and employees in the Company’s computer systems and networks, and in those of its third party vendors. The cyber risks the Company faces range from cyber-attacks common to most industries, to more advanced threats that target the Company because of its prominence in the global marketplace, or due to its ratings of sovereign debt. Breaches of Moody’s or Moody’s vendors’ technology and systems, whether from circumvention of security systems, denial-of-service attacks or other cyber-attacks, hacking, “phishing” attacks, computer viruses, ransomware, or malware, employee or insider error, malfeasance, social engineering, physical breaches or other actions, may result in manipulation or corruption of sensitive data, material interruptions or malfunctions in the Company’s or such vendors’ web sites, applications, data processing, or disruption of other business operations, or may compromise the confidentiality and integrity of material information held by the Company (including information about Moody’s business, employees or customers), as well as sensitive personally identifiable information (PII), the disclosure of which could lead to identity theft. Measures that Moody’s takes to avoid, detect, mitigate or recover from material incidents can be expensive, and may be insufficient, circumvented, or may become ineffective. To conduct its operations, the Company regularly moves data across national borders, and consequently is subject to a variety of continuously evolving and developing laws and regulations in the United States and abroad regarding privacy, data protection and data security. The scope of the laws that may be applicable to Moody’s is often uncertain and may be conflicting, particularly with respect to foreign laws. For example, the European Union’s General Data Protection Regulation (“GDPR”), which became effective on May 25, 2018, greatly increased the jurisdictional reach of European Union privacy law and added a broad array of requirements for processing personal data, including the public disclosure of significant data breaches. Failure to comply with GDPR requirements could result in penalties of up to 4% of annual worldwide revenue. Additionally, other countries have enacted or are enacting data localization laws that require data to stay within their borders. Further, California recently enacted legislation, the California Consumer Privacy Act (“CCPA”), that will, among other things, require covered companies to provide new disclosures to California consumers, and afford such consumers new abilities to opt-out of certain sales of personal information, when it goes into effect on January 1, 2020. Legislators have stated that they intend to propose amendments to the CCPA before it goes into effect, and it remains unclear what, if any, modifications will be made to this legislation or how it will be interpreted. The effects of the CCPA potentially are significant, however, and may require us to modify our data processing practices and policies and to incur substantial costs and expenses. All of these evolving