Mattel relies extensively on information technology systems across its operations, including for management of its supply chain, sale and delivery of its products and services, reporting its results of operations, collection and storage of consumer data, personal data of customers, employees and other stakeholders, and various other processes and transactions. If Mattel does not allocate and effectively manage the resources necessary to build, sustain, and protect an appropriate technology infrastructure, it could be subject to transaction errors, processing inefficiencies, loss of customers, business disruptions, shutdowns, or loss of or damage to intellectual property through security breach. Many of these systems are managed by third-party service providers. Mattel relies on such third parties to provide services on a timely and effective basis, but Mattel ultimately does not control their performance. Mattel uses third-party technology and systems for a variety of reasons, including, without limitation,encryption and authentication technology, employee email, content delivery to customers, regulatory compliance, back-office support, and other functions. A small and growing volume of Mattel's consumer products and services are web-based, and some are offered in conjunction with business partners or such third-party service providers. In addition, Mattel's distributors, suppliers, and other external business partners utilize their own information technology systems that are subject to similar risks to Mattel as described above. Their failure to perform as expected or as required by contract, or a cyber-attack on them that disrupts their systems, could result in significant disruptions and costs to Mattel's operations or, in the case of third-party service providers, a penetration of Mattel's systems. Mattel and its business partners and third-party service providers collect, process, store, and transmit consumer data, including personal and payment information, in connection with those products and services. Failure to follow applicable regulations related to those activities, or to prevent or mitigate data loss or other security breaches, including breaches of Mattel's business partners' technology and systems, can expose Mattel or its customers to a risk of loss or misuse of such information, which can adversely affect Mattel's operating results, result in regulatory enforcement, other litigation and potential liability for Mattel, and otherwise harm its business. Mattel's ability to effectively manage its business and coordinate the production, distribution, and sale of its products and services depends significantly on the reliability and capacity of these systems and third-party service providers.
Mattel has exposure to security risks similar to those faced by other large companies that have data stored on their information technology systems, such as security breaches, cyber-attacks, and other hacking activities such as denial of service, malware, and ransomware, and is not always successful in preventing attacks or other cyber incidents. For example, in July 2020, Mattel experienced a ransomware attack. That attack was contained, Mattel restored its operations, and no exfiltration of any sensitive business data or retail customer, supplier, consumer, or employee data was identified; however, there can be no assurance that Mattel will be able to mitigate negative impacts in the same way in the event of future attacks or other cyber incidents.
The systems and processes that Mattel has developed to protect personal information and prevent data loss and other security breaches, including systems and processes designed to prevent, detect, and minimize the impact of a security breach at a third-party provider as well as enhancements to the security of Mattel's systems and processes following the July 2020 ransomware attack, do not provide absolute security, and any failure or inadequacy of such systems or processes could have an adverse effect on Mattel's business, financial condition, and results of operations. While Mattel carries cyber and business continuity insurance commensurate with its size and the nature of its operations, there can be no guarantee that costs incurred as a result of cyber events will be covered completely. The recent global shift to remote work environments (including for Mattel's employees, customers, sellers, suppliers, vendors, and other third parties) may amplify these security risks or introduce additional security vulnerabilities. Additionally, AI may increase the frequency or efficacy of cyberattacks against Mattel.
Mattel's information systems require an ongoing commitment of significant resources to maintain, upgrade and enhance existing systems and develop or contract for new systems in order to keep pace with continuing changes in information processing technology, emerging cybersecurity risks and threats, evolving industry, legal and regulatory standards and requirements, and other changes in Mattel's business, among other things. Mattel has made and expects to continue to make significant investments in updating and integrating IT systems; however, those investments could turn out to be insufficient or fail to yield the expected results. If Mattel's or its third-party service providers' systems fail to operate effectively or are damaged, destroyed, or shut down, or there are problems with transitioning to upgraded or replacement systems, or there are future security breaches in these systems, any of which could occur as a result of natural disasters, software or equipment failures, telecommunications failures, loss or theft of equipment, acts of terrorism, circumvention of security systems, or other cyber-attacks, including denial-of-service attacks, Mattel could experience delays or decreases in product sales and reduced efficiency of its operations. Additionally, any of these types of events could lead to violations of privacy laws, loss of customers, or loss, misappropriation or corruption of confidential information, trade secrets, or data, which could expose Mattel to potential litigation, regulatory actions, sanctions, or other statutory penalties, any or all of which could adversely affect its business and cause it to incur significant losses and remediation costs.