Our digital banking and network operations rely heavily on the secure processing, storage and transmission of confidential or sensitive information about us, our customers and third parties with whom we do business. Information security risks for financial institutions have increased and continue to increase in part because of the proliferation of new technologies, the use of the internet and cloud, mobile and telecommunications technologies to conduct financial transactions and the increased sophistication and activities of organized crime, activists, hackers, terrorist organizations, nation state actors and other external parties. Those parties may also attempt to fraudulently induce employees, customers or other users of our systems (including third parties) to disclose confidential or sensitive information in order to gain access to our data or that of our customers.
Our technologies, systems, networks and software, those of other financial institutions and other firms (such as hardware vendors, cloud providers and others), have been, and are likely to continue to be, the target of increasingly frequent cyber-attacks, malicious code, ransomware, denial of service attacks, phishing and other social engineering, other remote access attacks and physical attacks that could result in unauthorized access, misuse, loss, unavailability or destruction of data (including confidential customer information), account takeovers, identity theft and fraud, unavailability of service or other events. These types of threats may derive from human error, fraud or malice on the part of external or internal parties or may result from technological failure or otherwise. Further, our vulnerability to these types of threats may be increased to the extent employees work remotely or in hybrid work arrangements.
Despite our efforts to ensure the integrity of our systems through our information security and business continuity programs, we may not be able to anticipate or to implement effective preventive measures against all known and unknown security threats, attacks or breaches or events of these types, especially because the techniques used change frequently and are becoming increasingly more sophisticated or are not recognized until launched or vulnerabilities in software or hardware are unknown or are unable to be entirely addressed even after becoming known, and because:
- Security attacks can originate from a wide variety of sources and geographic locations and may be undetected for a period of time.
- We rely on many third-party service providers and network participants, including merchants, and, as such, a security breach or cyber-attack affecting one of these third parties could impact us. For example, the financial services industry continues to see attacks against the environments where personal and identifiable information is handled. For additional information see the risk factor "- Failure to manage our relationships with third-party service providers could result in our revenue or results of operations being materially adversely affected."- Our customers may use computers and mobile devices that are beyond our security control systems to access our products and services.
We are subject to increasing risk related to information and data security as we increase acceptance of the Discover card internationally, expand our suite of online digital banking products, enhance our mobile payment technologies, acquire new or outsource some of our business operations, expand our internal usage of web-based products and applications, and otherwise attempt to keep pace with rapid technological changes in the financial services industry. Our efforts to mitigate this risk increase our expenses. While we continue to invest in our information security defenses (including cybersecurity defenses), if our security systems or those of third parties are penetrated or circumvented such that the confidentiality, integrity or availability of information about us, our customers, transactions processed on our networks or on third-party networks on our behalf or third parties with which we do business is compromised, we could be subject to significant liability that may not be covered by insurance, including significant legal and financial exposure, actions by our regulators, damage to our reputation, or a loss of confidence in the security of our systems, products and services that could materially adversely affect our business.
Cyber-attacks that are successful, or are perceived to be successful, in compromising the data or disrupting the services of other peer financial institutions, whether or not we are impacted, could lead to a general loss of customer confidence, which could negatively impact market perception of our products and services. Media reports of attempted cyber-attacks, service disruptions or vulnerabilities in our information systems or security procedures or those of any of the third-party service providers we engage, could cause significant legal and financial exposure, lead to regulatory and legislative intervention and cause an overall negative effect in our business. For additional information on risks in this area, see the risk factors below regarding fraudulent activity, the introduction of new products and services, the use of third parties for outsourcing, technology generally, and laws and regulations addressing consumer privacy and data use and security.