Peoples collects, processes and stores sensitive consumer data by utilizing computer systems and telecommunications networks operated by both Peoples and third-party service providers. Peoples' dependence upon automated systems to record and process Peoples' transactions poses the risk that technical system flaws, employee errors, tampering or manipulation of those systems, or attacks by third parties will result in losses and may be difficult to detect. Peoples has security and backup and recovery systems in place, as well as a business continuity plan, designed to ensure the computer systems will not become inoperable, to the extent possible. Peoples also routinely reviews documentation of such controls and backups related to third-party service providers. Peoples' inability to use or access these information systems at critical points in time could unfavorably impact the timeliness and efficiency of Peoples' business operations.
Information security risks have increased due to the sophistication and activities of organized crime, hackers, terrorists and other external parties and the use of online, telephone, and mobile banking channels by clients. In recent years, several banks have experienced denial of service attacks in which individuals or organizations flood the bank's website with extraordinarily high volumes of traffic, with the goal and effect of disrupting the ability of the bank to process transactions. Other businesses have been victims of ransomware attacks in which the business becomes unable to access the business' own information and is presented with a demand to pay a ransom in order to once again have access to the business' information. Peoples could be adversely affected if one of its employees or a third-party service provider causes a significant operational break-down or failure, either as a result of human error or where an individual purposefully sabotages or fraudulently manipulates Peoples' operations or systems. Peoples may not be able to prevent employee or third-party errors or misconduct, and the precautions Peoples takes to detect this type of activity might prove ineffective. Peoples is further exposed to the risk that the third-party service providers may be unable to fulfill their contractual obligations (or will be subject to the same risks as Peoples is). These disruptions may interfere with service to Peoples' customers, cause additional regulatory scrutiny and result in a financial loss or liability.
Any compromise to Peoples' information security could impair Peoples' reputation and deter Peoples' clients from using Peoples' banking services. Information security breaches can also disrupt the operation of information systems on which Peoples and its customers depend, adversely affecting business operations. Such events can result in costly remediation measures and litigation or governmental investigation and responding to security breaches can place unanticipated demands on the time and attention of management. Peoples relies on security systems to provide the protection and authentication necessary to secure transmission of data against damage by theft, fire, power loss, telecommunications failure or similar catastrophic event, as well as from security breaches, ransomware, denial of service attacks, viruses, worms, and other disruptive problems caused by hackers. Computer break-ins, phishing and other disruptions of customer or vendor systems could also jeopardize the security of information stored in and transmitted through Peoples' computer systems and network infrastructure.
Peoples' associates also confront the risk of being compromised by emails sent by perpetrators posing as company executives or vendors in order to dupe Peoples' personnel into sending large sums of money to accounts controlled by the perpetrators. Peoples requires all employees to complete annual information security awareness training to increase their awareness of these risks and to engage them in Peoples' mitigation efforts. If these precautions are not sufficient to protect Peoples' systems from data breaches or compromises, Peoples' reputation and business could be adversely affected.
In addition, there have been instances where financial institutions have been victims of fraudulent activity in which criminals pose as customers to initiate wire and automated clearinghouse transactions out of customer accounts. Although Peoples has policies and procedures in place to verify the authenticity of its customers, Peoples cannot ensure that such policies and procedures will prevent all fraudulent transfers.
Peoples depends on the services of a variety of third-party vendors to meet data processing and communication needs, and Peoples has contracted with third parties to run their proprietary software on Peoples' behalf. While Peoples performs reviews of security controls instituted by the vendor in accordance with industry standards and institutes Peoples' own internal security controls, Peoples relies on continued maintenance of the controls by the outside party to safeguard customer data.
Additionally, Peoples issues debit cards which are susceptible to compromise at the point of sale via the physical terminal through which transactions are processed and by other means of hacking. The security and integrity of these transactions are dependent upon the retailers' vigilance and willingness to invest in technology and upgrades. Issuing debit cards to Peoples' clients exposes Peoples to potential losses which, in the event of a data breach at one or more major retailers may adversely affect Peoples' business, financial condition, and results of operations.
Peoples is also at risk of the impact of natural disasters, terrorism and international hostilities on Peoples' systems or from the effects of outages or other failures involving power or communications systems operated by others.
Peoples has implemented security controls to prevent unauthorized access to its computer systems, and Peoples requires that its third-party service providers maintain similar controls. However, Peoples' management cannot be certain that these measures will be successful. A security breach of the computer systems and loss of confidential information, such as customer account numbers and related information, could result in a loss of customers' confidence and, thus, loss of business. Peoples could also lose revenue if competitors gain access to confidential information about Peoples' business operations and use such confidential information to compete with Peoples. While Peoples maintains specific "cyber" insurance coverage, which would apply in the event of various breach scenarios, the amount of coverage may not be adequate in any particular case. Furthermore, because cyber threat scenarios are inherently difficult to predict and can take many forms, some breaches may not be covered under Peoples' cyber insurance coverage.
Further, Peoples may be affected by data breaches at retailers and other third parties who participate in data interchanges with Peoples and its customers that involve the theft of customer credit and debit card data, which may include the theft of Peoples' consumer and business debit card PIN numbers and commercial card information used to make purchases at such retailers and other third parties. Such data breaches could result in Peoples incurring significant expenses to reissue debit cards and cover losses, which could result in a material adverse effect on Peoples' operations.
All of the types of cybersecurity incidents discussed above could result in damage to Peoples' reputation, loss of customer business, increased costs of incentives to customers or business partners in order to maintain their relationships, litigation, increased regulatory scrutiny and potential enforcement actions, repairs of system damage, increased investments in cybersecurity (such as obtaining additional technology, making organizational changes, deploying additional personnel, training personnel and engaging consultants), increased insurance premiums, and loss of investor confidence and a reduction in the price of Peoples' common shares, all of which could result in financial loss and material adverse effects on Peoples' results of operations and financial condition.