Use of our marketplaces and brand direct solutions involves the storage and transmission of consumers' information, including personal information, and security breaches could expose us to a risk of loss or exposure of this information which could result in potential liability, litigation and remediation costs, as well as reputational harm, all of which could materially adversely affect our business and financial results. For example, unauthorized parties could steal our users' names, email addresses, physical addresses, phone numbers and other information that we collect when providing consumer engagements and referrals. While we use encryption and authentication technology licensed from third parties designed to effect secure transmission of such information, we cannot guarantee the security of the transfer and storage of the personal information we collect from advertisers.
Like all information systems and technology, our websites and information systems may be subject to computer viruses, break-ins, phishing, impersonation attacks, attempts to overload our servers with denial-of-service or other attacks, ransomware and similar incidents or disruptions from unauthorized use of our computer systems, as well as unintentional incidents causing data leakage, any of which could lead to interruptions, delays or website shutdowns, or could cause loss of critical data or the unauthorized disclosure, access, acquisition, alteration or use of personal or other confidential information. Although we have a chief information officer who coordinates our cybersecurity measures, policies and procedures, and our chief information officer reports to the Board regarding these matters at least quarterly, we cannot be certain that our efforts will be able to prevent breaches of the security of our information systems and technology. In addition, although we have cybersecurity insurance, we may not be able to retain such insurance on economic terms in the future or at all, and we cannot be certain that our insurance will cover us fully for any losses that we may experience, including with respect to any potential ransomware attacks we may experience. If we experience compromises to our security that result in websites performance or availability problems, the complete shutdown of our websites or the loss or unauthorized disclosure, access, acquisition, alteration or use of confidential information, consumers and advertisers may lose trust and confidence in us, and consumers and advertisers may decrease the use of our website or stop using our website entirely. Further, outside parties may attempt to fraudulently induce employees, consumers or advertisers to disclose sensitive information in order to gain access to our information or consumers' or advertisers' information. Because the techniques used to obtain unauthorized access, disable or degrade service, or sabotage systems change frequently, often are not recognized until launched against a target, and may originate from less regulated and remote areas around the world, we may be unable to proactively address these techniques or to implement adequate preventative measures.
Any or all of the issues above could adversely affect our ability to attract new users and increase engagement by existing users, cause existing users to curtail or stop use of our marketplaces and brand direct solutions, cause existing advertisers to cancel their contracts or subject us to governmental or third-party lawsuits, investigations, regulatory fines or other actions or liability, thereby harming our business, results of operations and financial condition. Although we are not aware of any material information security incidents to date, we have detected common types of attempts to attack our information systems and data using means that have included viruses and phishing.
There are numerous federal, state and local laws in the United States and around the world regarding privacy and the collection, processing, storing, sharing, disclosing, using, cross-border transfer and protecting of personal information and other data, the scope of which are changing, subject to differing interpretations, and which may be costly to comply with, may result in regulatory fines or penalties, and may be inconsistent between countries and jurisdictions or conflict with other rules.
We are subject to the terms of our privacy policies and privacy-related obligations to third parties. We strive to comply with all applicable laws, policies, legal obligations and industry codes of conduct relating to privacy and data protection, to the extent possible. However, it is possible that these obligations may be interpreted and applied in new ways or in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices or that new regulations could be enacted. Any failure or perceived failure by us to comply with our privacy policies, our privacy-related obligations to consumers or other third parties, or our privacy-related legal obligations, or any compromise of security that results in the unauthorized release or transfer of sensitive information, which could include personally identifiable information or other user data, may result in governmental investigations, enforcement actions, regulatory fines, litigation or public statements against us by consumer advocacy groups or others, and could cause consumers and advertisers to lose trust in us, all of which could be costly and have an adverse effect on our business. In addition, new and changed rules and regulations regarding privacy, data protection and cross-border transfers of consumer information could cause us to delay planned uses and disclosures of data to comply with applicable privacy and data protection requirements. Moreover, if third parties that we work with violate applicable laws or our policies, such violations also may put consumer or advertiser information at risk and could in turn harm our reputation, business and operating results. This risk exists both with respect to our vendors and partners (who may employ less rigorous compliance standards than our own) and our clients (who may have expectations on their legal right to freely make use of consumer data which we may provide them).
We currently operate primarily in the United States. To the extent that we determine to expand our business internationally, we will encounter additional risks, including different, uncertain or more stringent laws relating to consumer protection and data privacy rights.