gain market share, which could compel us to match their pricing strategy or lose business. In addition, some of our competitors may be willing to lease certain types of products that we will not agree to lease, enter into customer leases that have services, as opposed to goods, as a significant portion of the lease value, or engage in other practices related to pricing, compliance, and other areas that we will not, in an effort to gain market share at our expense.
If we do not maintain the privacy and security of customer, employee or other confidential information, due to cybersecurity-related “hacking” attacks, intrusions into our systems by unauthorized parties or otherwise, we could incur significant costs, litigation, regulatory enforcement actions and damage to our reputation, any one of which could have a material adverse impact on our business, results of operations and financial condition.
Our business involves the collection, processing, transmission and storage of customers’ personal and confidential information, including social security numbers, dates of birth, banking information, credit and debit card information, data we receive from consumer reporting companies, including credit report information, as well as confidential information about our employees, among others. Much of this data constitutes confidential personally identifiable information (“PII”) which, if unlawfully accessed, either through a “hacking” attack or otherwise, could subject us to significant liabilities as further discussed below.
Companies like us that possess significant amounts of PII and/or other confidential information have experienced a significant increase in cyber security risks in recent years from increasingly aggressive and sophisticated cyberattacks, including hacking, computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing and impersonation), denial-of-service attacks and other attacks and similar disruptions from the unauthorized use of or access to information technology (“IT”) systems. Our IT systems are subject to constant attempts to gain unauthorized access in order to disrupt our business operations and capture, destroy or manipulate various types of information that we rely on, including PII and/or other confidential information. In addition, various third parties, including employees, contractors or others with whom we do business may attempt to circumvent our security measures in order to obtain such information, or inadvertently cause a breach involving such information. Any significant compromise or breach of our data security, whether external or internal, or misuse of PII and/or other confidential information may result in significant costs, litigation and regulatory enforcement actions and, therefore, may have a material adverse impact on our business, results of operations and financial condition. Further, if any such compromise, breach or misuse is not detected quickly, the effect could be compounded.
While we have implemented network security systems and processes (including engagement of third-party data security services) to protect against unauthorized access to or use of secured data and to prevent data loss and theft, there is no guarantee that these procedures are adequate to safeguard against all data security breaches or misuse of the data. We maintain private liability insurance intended to help mitigate the financial risks of such incidents, but there can be no guarantee that insurance will be sufficient to cover all losses related to such incidents, and our exposure resulting from any serious unauthorized access to, or use of, secured data, or serious data loss or theft, could far exceed the limits of our insurance coverage for such events. Further, a significant compromise of PII and/or other confidential information could result in regulatory penalties and harm our reputation with our customers and others, potentially resulting in a material adverse impact on our business, results of operations and financial condition.
The regulatory environment related to information security, data collection and use, and privacy is increasingly rigorous, with new and constantly changing requirements applicable to our business, and compliance with those requirements could result in additional costs. For example, the CCPA, which became effective in January 2020, has changed the manner in which our transactions with California residents are regulated with respect to the manner in which we collect, store and use consumer and employee data; expose our operations in California to increased regulatory oversight and litigation risks; and increase our compliance-related costs. These costs, including others relating to increased regulatory oversight and compliance, could be substantial and adversely impact our business, results of operations or financial condition.
24