We rely on vendors and other third-parties to provide us with services that are essential to our ability to provide clients with our products and services. These services range from core infrastructure, such as utilities, communications and web hosting services, to systems that allow us to execute and process transactions entered into by our clients.
If these vendors or other third-parties suffer operations issues, including as a result of cyber attacks, and they are unable to continue to provide these services to us, we may be exposed to a variety of risks, including loss of revenue if our clients cannot trade with us, increased costs if we are required to employ alternative solutions and reputational harm.
In addition, some of our vendors hold sensitive information on our behalf, including personally identifiable information relating to our clients. If this data were to be compromised, either as a result of a cyber attack or otherwise, we could be in breach of our obligations to our clients, as well as applicable data protections laws, which could materially adversely affect our results of operations and reputation.
Cyber attacks directed at our vendors may also make us more vulnerable to being targeted for cyber attacks ourselves if the bad actors are able to obtain information relating to our company and / or systems.
If one of our vendors experiences a cyberbreach of its own systems or has data that it holds misappropriated, we could be exposed to a number of additional risks, including:
- heightened risk that we will not be able to comply with applicable regulatory requirements;- increased risk that external parties will be able to execute fraudulent transactions using our systems;- losses from fraudulent transactions, as well as potential liability for losses suffered by our clients;- increased operational costs to remediate the consequences of the external party's security breach; and - reputational harm arising from the perception that our systems may not be secure.
In some cases, operational issues or security breaches affecting our vendors may require us to take steps to protect the integrity of our own operational systems or to safeguard confidential information that we hold, including restricting the ability of our clients to trade or have access to their accounts. These actions could potentially diminish customer satisfaction and confidence in us, materially adversely affecting our results of operations.
For example, on January 31, 2023, we were notified by ION Group, one of our vendors which provides back office trade processing services relating to certain of our listed derivatives businesses, that it had experienced a cybersecurity incident, which rendered certain of its services inaccessible to us and its other clients. As a result of the incident, we imposed restrictions on clients of our UK subsidiary relating to the trading of listed derivatives. During February 2023, these services were restored and the restrictions on clients' activities were lifted.
Furthermore, the widespread and expanding interconnectivity among financial institutions, clearing banks, CCPs, payment processors, financial technology companies, securities exchanges, clearing houses and other financial market infrastructures increases the risk that the disruption of an operational system involving one institution or entity, including due to a cyber attack, may cause industry-wide operational disruptions that could materially affect our ability to conduct business.