Our business is highly dependent on the security and efficacy of our infrastructure, computer and data management systems to provide secure processing, transmission, storage and retrieval of confidential and proprietary information.
Cyber security risks for financial institutions have significantly increased in recent years in part because of the proliferation of new technologies and the use of the Internet and telecommunications technologies to conduct financial transactions. Financial institutions have been subject to, and are likely to continue to be the target of, cyber-attacks, including computer viruses, malicious or destructive code, phishing attacks, denial of service or other security breaches that could result in the unauthorized release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary and other information of the institution, its employees, customers or third parties, or otherwise materially disrupt network access or business operations.
We have experienced cyber security incidents in the past, although not material, and we anticipate that, as a larger bank, we could experience further incidents. There can be no assurance that we will not suffer material losses or other material adverse consequences relating to technology failure, cyber-attacks or other information or security breaches.
In addition, there have been instances where financial institutions have been victims of fraudulent activity in which criminals pose as customers to initiate wire and automated clearinghouse transactions from customer accounts. Although we have policies and procedures in place to verify the authenticity of our customers, there can be no assurance that such policies and procedures will prevent all fraudulent transfers. Such activity could result in financial liability and harm to our reputation.
Misuse of our technology by our employees could also result in fraudulent, improper or unauthorized activities on behalf of customers or improper use of confidential information. We may not be able to prevent employee errors or misconduct, and the precautions we take to detect these types of activity might not be effective in all cases. Employee errors or misconduct could subject us to civil claims for negligence or regulatory enforcement actions, including fines and restrictions on our business.
As cyber threats and other fraudulent activity continues to evolve, we may be required to expend significant additional resources to continue to modify and enhance our protective measures, or to investigate and remediate any information security vulnerabilities or incidents. Any of these matters could result in our loss of customers and business opportunities, significant disruption to our operations and business, misappropriation or destruction of our confidential information and/or that of our customers, or damage to our customers' computers or systems, and could result in a violation of applicable privacy laws and other laws, litigation exposure, regulatory fines, penalties or intervention, loss of confidence in our security measures, reputational damage, reimbursement or other compensatory costs, and additional compliance costs. In addition, any of the matters described above could adversely impact our results of operations and financial condition.