← Back to FLNC filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
There have been no material changes to the risk factors previously disclosed in Part I, Item 1A. “Risk Factors” of our 2025 Annual Report, other than as set forth below. You should carefully consider the risks described below and described in Part I, Item 1A. "Risk Factors" of our 2025 Annual Report along with our unaudited condensed consolidated financial statements and the related notes, as well as our other public filings with the SEC, before making an investment decision. Our business, financial condition, and results of operations could be materially and adversely affected by any of these risks or uncertainties.
Our business depends on our ability to implement improvements to and properly maintain and protect the continuous operation and data integrity of our technology infrastructure, data and other business systems and the inability to do so may have a material adverse effect on our reputation and harm our business prospects, financial conditions, and operating results.
Our business is highly dependent on maintaining effective information and operational technology systems as well as the integrity of the data we use to serve our customers and operate our business. Because of the large amount of data that we collect and manage, it is possible that hardware failures or errors in our systems could result in data loss or corruption or cause the information that we collect to be incomplete or contain inaccuracies that our customers or other parties may regard as significant. If our data were found to be inaccurate or unreliable due to fraud or other error, or if we, or any of the third-party service providers we engage, were to fail to maintain information systems and data integrity effectively, we could experience operational disruptions that may impact our operations and hinder our ability to provide services, establish appropriate pricing, establish reserves, report financial results timely and accurately and maintain regulatory compliance, among other things. If any such failure of our information technology systems or data integrity were to result in the theft, corruption or other harm to the data or operations of our customers, our ability to retain and attract customers may be harmed.
We must continue to invest in long-term solutions that will enable us to anticipate customer needs and expectations, enhance the customer experience, act as a differentiator in the market, and protect against cybersecurity risks and threats. Despite implementation of reasonable security measures designed to prevent cybersecurity risks and threats, we are vulnerable to potential harm and damages from computer viruses, natural disasters, fire, power loss, telecommunications failures, personnel misconduct or theft, human error, unauthorized access, physical or electronic security breaches, cyber-attacks (including malicious and destructive code, misconfigurations, “bugs” or other vulnerabilities in commercial software that is integrated into our (or our suppliers’) IT systems, products, or services, social engineering attacks, phishing attacks, ransomware, and denial of service attacks), and other similar disruptions and incidents. Such harm, damages, attacks, security breaches or disruptions may be perpetrated by bad actors internally or externally (including computer hackers, persons involved with organized crime, or foreign state or foreign state-supported actors) and create risks that threaten the confidentiality, integrity, and availability for our (as well as our suppliers’ and our customers’) internal networks, IT infrastructure, operational technology, and other business systems and the data and information they store and process. Additionally, we are unable to comprehensively apply patches or confirm that measures are in place to mitigate all such vulnerabilities, or that patches will be applied before vulnerabilities are exploited by a threat actor. Cybersecurity threat actors employ a wide variety of methods and techniques that are constantly evolving, increasingly sophisticated, and difficult to detect and successfully defend against, including artificial intelligence that circumvent security controls, evade
57
Table of Contents
detection and remove forensic evidence. Geopolitical tensions or conflicts, such as Russia’s invasion of Ukraine, and heightened tensions in the Middle East, may further heighten the risk of cyber-attacks. We have experienced such cybersecurity incidents in the past, and any future incidents could expose us to claims, litigation, regulatory or other governmental investigations, administrative fines, and potential liability. Moreover, while we have implemented remedial measures in response to such incidents, we cannot guarantee that such measures will prevent all incidents in the future. Any system failure, accident, or security breach could result in disruptions to our operations. A material breach in the security of our IT systems and operational technology could include the theft of our trade secrets, customer information, human resources information, or other confidential data, including but not limited to personal information. Material breaches could also include denial of service attacks resulting in disruption to our or our supplier’s supply chain systems, or targeted attacks against the control plane of remotely serviced battery energy storage systems within our customers’ environments, resulting in operational disruption to energy storage or physical damage to batteries.
We and our third-party service providers experience varying degrees of cyberattacks and other security incidents. For example, in June and July 2026, we experienced a cybersecurity incident involving social engineering attacks targeting certain employees in which a threat actor obtained confidential information from certain of our corporate IT systems. We initiated our incident response protocols and notified law enforcement, and we are notifying customers whose confidential information was impacted. Based on our investigation to date, our operations were not affected, and we have not identified any impact to customer environments. Although this incident and prior incidents have not had a material effect on our business operations or financial performance, we cannot guarantee that future cyberattacks and cybersecurity incidents, if successful, will not have a material effect on our business or financial results. To the extent that any disruption or security breach results in the compromise of our products, the control plane of one or more of our serviced customer sites, or a loss or damage to our data, or an inadvertent disclosure of confidential, proprietary personal, or customer information, it could cause significant damage to our reputation, affect our relationships with our customers and strategic partners, lead to claims against us from governments and private plaintiffs (including class actions), and adversely affect our business.
In 2023, the SEC issued final rules related to cybersecurity risk management, strategy governance, and incident disclosure, which further increased our regulatory burden and the cost of compliance. In addition, many governments have enacted laws requiring companies to provide notice of cybersecurity incidents involving certain types of data, including personal information. For example, laws in all 50 U.S. states and in the EU and UK may require businesses to notify regulators and/or individuals whose personal information has been impacted as a result of a data breach or security incident. Complying with such numerous and complex regulations in the event of a data breach or security incident would be expensive and difficult, and failure to comply with these regulations could subject us to regulatory scrutiny and additional liability. These laws may be subject to alterations and revisions, and if we fail to comply with our obligations under such laws in the jurisdictions in which we operate, we could be subject to regulatory action and lawsuits (including class actions). We may also have other obligations, for example, under contracts, to notify customers or other counterparties of a security incident, including a data breach. Regardless of our contractual protections, if an actual or perceived cybersecurity breach of security measures, unauthorized access to our system or the systems of the third-party vendors that we rely upon, or any other cybersecurity threat occurs, we may incur liability, costs, or damages, contract termination, our reputation may be compromised, our ability to attract new customers could be negatively affected, and our business, financial condition, and results of operations could be materially and adversely affected. Any compromise of our security could also result in a violation of applicable domestic and foreign security, privacy or data protection, consumer protection, and other laws, regulatory or other governmental investigations, enforcement actions, and legal and financial exposure, including potential contractual liability. In addition, we may be required to incur significant costs to protect against and remediate damage caused by these disruptions or security breaches in the future. While we carry cyber insurance, we cannot be certain that our coverage will be adequate for liabilities actually incurred, that insurance will continue to be available to us on commercially reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim.