Financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information and cyber security risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer system. These risks are heightened further by the advent of new artificial intelligence technologies that may be adapted to increase the effectiveness of cyberattacks and their proper use may be necessary to aid in the defense of such attacks. A major information or cyber security incident or an increase in fraudulent activity could lead to reputational damage to our brand and material legal, regulatory and financial exposure, and could reduce the use and acceptance of our services.
Our operations rely on the secure processing, transmission and storage of confidential information in our computer systems and networks regarding our customers and their accounts. To provide these products and services, we use information systems and infrastructure that we and third-party service providers operate. As a financial institution, we are also subject to and examined for compliance with an array of data protection laws, regulations and guidance, as well as to our own internal privacy and information security policies and programs.
Cybersecurity incidents may include unauthorized access to our digital systems for purposes of misappropriation of assets, gaining access to sensitive information, corrupting data, or causing operational disruption. Although our information technology structure continues to be subject to cyber-attacks, we have not, to our knowledge, experience a breach of cyber-security. Such an event could compromise our confidential information, as well as that of our customers and third parties with whom we interact with and may result in negative consequences.
While we have policies and procedures designated to prevent or limit the effects of a possible security breach of our information systems, if unauthorized persons were somehow to get access to confidential information in our possession or to our proprietary information, it could result in significant legal and financial exposure, damage to our reputation or a loss of confidence in the security of our systems that could adversely affect our business. Though we have insurance against some cyber-risks and attacks, it may not be sufficient to offset the impact of a material loss event.