Our business is highly dependent on the security and efficacy of our infrastructure, computer and data management systems, as well as those of third parties with whom we interact. Cyber security risks for financial institutions have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists and other external parties, including foreign state actors. Our operations rely on the secure processing, transmission, storage and retrieval of confidential, proprietary and other information in our computer and data management systems and networks, and in the computer and data management systems and networks of third parties. We rely on digital technologies, computer, database and email systems, software, and networks to conduct our operations. In addition, to access our network and products and services, our customers and third parties may use personal mobile devices or computing devices that are outside of our network environment. We have taken measures to implement backup systems and other safeguards to support our operations, but our ability to conduct business may be adversely affected by any significant disruptions to us or to third parties with whom we interact.
Financial services institutions, and third parties whom they conduct business with, have been subject to, and are likely to continue to be the target of, cyber attacks, including computer viruses, malicious or destructive code, phishing attacks, denial of service or other security breaches that could result in the unauthorized release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary and other information of the institution, its employees or customers or of third parties, or otherwise materially disrupt network access or business operations. For example, denial of service attacks have been launched against a number of large financial institutions and several large retailers have disclosed substantial cyber security breaches affecting debit accounts of their customers. We have experienced cyber security incidents in the past, such as vendor malware attacks, phishing and other social engineering schemes designed to gain access to confidential information from our employees,customers or vendors and, although not material, we anticipate that we could experience further incidents. There can be no assurance that we will not suffer material losses or other material consequences relating to technology failure, cyber incidents or other information or security breaches.
In addition to external threats, insider threats also present a risk to us. Insiders, having legitimate access to our systems and the information contained in them, have the opportunity to make inappropriate use of the systems and information, or as a result of human error, misconduct or malfeasance, expose us to risk. We have policies, procedures, and controls in place designed to prevent or limit this risk, but we cannot guarantee that these policies, procedures and controls fully mitigate this risk. Additionally, a number of our employees have shifted to working from remote locations, which we expect to remain high for the foreseeable future, increasing the number of surfaces that require protection and the overall risks and exposures to cyber threats.
Moreover, we are subject to laws and regulations in the United States and other jurisdictions regarding privacy, data protection and data security and there continues to be heightened legislative and regulatory focus in this area. These laws and regulations are rapidly evolving and increasing in complexity and will require us to incur costs, some of which may be significant, to achieve and maintain compliance and could restrict our ability to provide certain products and services which could have an adverse effect on our business, financial condition and results of operations. Furthermore, as cybersecurity incidents increase in frequency and magnitude, we may be unable to obtain cybersecurity insurance in amounts and on terms we view as adequate for our operations.
As cyber threats continue to evolve, we may be required to expend significant additional resources to continue to modify and enhance our protective measures or to investigate and remediate any information security vulnerabilities or incidents. Any of these matters could result in our loss of customers and business opportunities, significant disruption to our operations and business, misappropriation or destruction of our confidential information and/or that of our customers, or damage to our customers' and/or third parties' computers or systems, and could result in a violation of applicable privacy laws and other laws, litigation exposure, regulatory fines, penalties or intervention, loss of confidence in our security measures, reputational damage, reimbursement or other compensatory costs, and additional compliance costs. In addition, any of the matters described above could adversely impact our results of operations and financial condition.