In the ordinary course of business, Arrow relies on electronic communications and information systems to conduct its operations and to store sensitive data. Arrow employs an in-depth, layered, defensive approach that leverages people, processes and technology to manage and maintain cybersecurity controls. Arrow employs a variety of preventative and detective tools to monitor, block, and provide alerts regarding suspicious activity, as well as to report on any suspected advanced persistent threats. Arrow has implemented and regularly reviews and updates extensive systems of internal controls and procedures as well as corporate governance policies and procedures intended to protect its business operations, including the security and privacy of all confidential customer information. In addition, Arrow relies on the services of a variety of vendors to meet data processing and communication needs. No matter how well designed or implemented its controls are, Arrow cannot provide an absolute guarantee to protect its business operations from every type of cybersecurity or other security problem in every situation, whether as a result of systems failures, human error or negligence, cyberattacks, security breaches, fraud or misappropriation. Any failure or circumvention of these controls could have a material adverse effect on Arrow's business operations and financial condition. Notwithstanding the strength of defensive measures, the threat from cyberattacks is severe, attacks are sophisticated and increasing in volume, and attackers respond rapidly to changes in defensive measures. While to date, Arrow has not experienced a significant compromise, significant data loss or any material financial losses related to cybersecurity attacks or other security problems, Arrow's systems and those of its customers and third-party service providers are under constant threat. Risks and exposures related to cybersecurity attacks or other security problems are expected to remain high for the foreseeable future due to the rapidly evolving nature and sophistication of these threats and issues, as well as due to the expanding use of Internet banking, mobile banking and other technology-based products and services by Arrow and customers.
The computer systems and network infrastructure that Arrow uses are always vulnerable to unforeseen disruptions, including theft of confidential customer information ("identity theft") and interruption of service as a result of fire, natural disasters, explosion, general infrastructure failure, cyberattacks or other security problems. These disruptions may arise in Arrow's internally developed systems, or the systems of our third-party service providers or may originate from the actions of our consumer and business customers who access our systems from their own networks or digital devices to process transactions. Information security and cyber security risks have increased significantly in recent years because of consumer demand to use the Internet and other electronic delivery channels to conduct financial transactions. Cybersecurity risk and other security problems are a major concern to financial services regulators and all financial service providers, including Arrow. These risks are further exacerbated due to the increased sophistication and activities of organized crime, hackers, terrorists and other disreputable parties. Arrow regularly assesses and tests security systems and disaster preparedness, including back-up systems, but the risks are substantially escalating. As a result, cybersecurity and the continued enhancement of Arrow's controls and processes to protect its systems, data and networks from attacks or unauthorized access remain a priority. Accordingly, Arrow may be required to expend additional resources to enhance its protective measures or to investigate and remediate any information security vulnerabilities or exposures. Any breach of Arrow's system security could result in disruption of its operations, unauthorized access to confidential customer information, significant regulatory costs, litigation exposure and other possible damages, loss or liability. Such costs or losses could exceed the amount of available insurance coverage, if any, and would adversely affect Arrow's earnings. Also, any failure to prevent a security breach or to quickly and effectively deal with such a breach could negatively impact customer confidence, damaging Arrow's reputation and undermining its ability to attract and keep customers. In addition, if Arrow fails to observe any of the cybersecurity requirements in federal or state laws, regulations or regulatory guidance, Arrow could be subject to various sanctions, including financial penalties.