Our business requires the collection and retention of large volumes of customer data, including payment card numbers and other personally identifiable information in various information systems that we maintain and in those maintained by third parties with whom we contract to provide data services. We also maintain important internal company data such as personally identifiable information about our employees and information relating to our operations. The integrity and protection of that customer and company data is important to us. As customer, public, legislative and regulatory expectations and requirements regarding operational and information security have increased, our operating systems and infrastructure must continue to be safeguarded and monitored for potential failures, disruptions and breakdowns.
Our technologies, systems, networks and software, and those of other financial institutions have been, and are likely to continue to be, the target of cybersecurity threats and attacks, which may range from uncoordinated individual attempts to sophisticated and targeted measures directed at us. These cybersecurity threats and attacks may include, but are not limited to, attempts to access information, including customer and company information, malicious code, computer viruses and denial of service attacks that could result in unauthorized access, misuse, loss or destruction of data (including confidential customer information), account takeovers, unavailability of service or other events. These types of threats may result from human error, fraud or malice on the part of external or internal parties, intelligence-gathering by foreign governments, or from accidental technological failure internally or by our vendors. Further, to access our products and services our customers may use computers and mobile devices that are beyond our security control systems. The risk of a security breach or disruption, particularly through cyber-attack or cyber intrusion, including by computer hackers, has increased as the number, intensity and sophistication of attempted attacks and intrusions around the world have increased.
Our customers and employees have been, and will continue to be, targeted by parties using fraudulent emails and other communications in attempts to misappropriate passwords, payment card numbers, bank account information or other personal information or to introduce viruses or other malware through "trojan horse" programs to our customers' devices. These communications may appear to be legitimate messages sent by the Bank or other businesses, but direct recipients to fake websites operated by the sender of the email or request that the recipient send a password or other confidential information via email or download a program. Despite our efforts to mitigate these threats through product improvements, use of encryption and authentication technology to secure online transmission of confidential consumer information, and customer and employee education, such attempted frauds against us or our merchants and our third party service providers remain a serious issue. The pervasiveness of cyber security incidents in general and the risks of cyber-crime are complex and continue to evolve. In light of several recent high-profile data breaches involving other companies' losses of customer personal and financial information, we believe this risk could cause customer and/or Bank losses, damage to our brand, and increase our costs through the ongoing cost of technology investments to improve security, as well as the potential financial and reputational impact of a cyber security incident involving the Company.
Although we make significant efforts to maintain the security and integrity of our information systems and have implemented various measures to manage the risk of a security breach or disruption, there can be no assurance that our security efforts and measures will be effective or that attempted security breaches or disruptions would not be successful or damaging. Even the most well-protected information, networks, systems and facilities remain potentially vulnerable because attempted security breaches, particularly cyber-attacks and intrusions, or disruptions will occur in the future, and because the techniques used in such attempts are constantly evolving and generally are not recognized until launched against a target, in some cases are designed not to be detected and, in fact, may not be detected. Accordingly, we may be unable to anticipate these techniques or to implement adequate security barriers or other preventative measures, and thus making it virtually impossible for us to entirely mitigate this risk. A security breach or other significant disruption could: 1) disrupt the proper functioning of our networks and systems and therefore our operations and/or those of certain of our customers; 2) result in the unauthorized access to, and destruction, loss, theft, misappropriation or release of confidential, sensitive or otherwise valuable information of ours or our customers, including account numbers and other financial and personal information; 3) result in a violation of applicable privacy, data breach and other laws, subjecting the Bank to additional regulatory scrutiny and exposing the Bank to civil litigation, governmental fines and possible financial liability; 4) require significant management attention and resources to remedy the damages that result; or 5) harm our reputation or cause a decrease in the number of customers that choose to do business with us or reduce the level of business that our customers do with us. The occurrence of any such failures, disruptions or security breaches could have a negative impact on our results of operations, financial condition, and cash flows as well as damage our brand and reputation.