← Back to HPE filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Our operations and financial results are subject to various risks and uncertainties, including those described in Part I, Item 1A, “Risk Factors” in our Annual Report on Form 10-K for the fiscal period ended October 31, 2025, which could adversely affect our business, financial condition, results of operations, cash flows, and the trading price of our common stock, including certain risks, which have been modified as follows:
System security risks, data protection incidents, cyberattacks and systems integration issues could disrupt our internal operations or IT services provided to customers, and any such disruption could reduce our revenue, increase our expenses, damage our reputation, and adversely affect our stock price.
In the ordinary course of business, we store sensitive data, including intellectual property, personal data, our proprietary business information and that of our employees, contractors, customers, vendors, partners, suppliers, and other third parties with whom we do business. In addition, we store sensitive data through cloud-based services that may be hosted by third parties and in data center infrastructure maintained by third parties. We have been, and expect to be, subject to cyberattacks and other attempted intrusions into our networks and systems by a wide range of actors, including, but not limited to, nation state actors, criminal enterprises, terrorist organizations, and other organizations or individuals, as well as errors, wrongful conduct or malfeasance by employees and third-party service providers, (collectively, “malicious parties”) who have at times been able to circumvent or bypass our cyber security measures. Geopolitical tensions or conflicts may also heighten the risk of such cyberattacks or exacerbate system vulnerabilities, considering our continued hybrid work environment and our globally dispersed operations, employees, contractors, suppliers, developers, partners, and other third parties.
Despite our security measures, our information systems, infrastructure, and data have experienced security incidents and breaches and may be subject to or vulnerable to security incidents and breaches in the future, including ransomware and distributed denial-of-service attacks. These attacks have not resulted in material negative impacts to HPE, nor have any of HPE’s consumers, customers, or employees informed HPE that these attacks resulted in material harm to them. While we investigate and remediate incidents, there can be no assurance that we can remediate all incidents completely, that we won’t make errors or fail to take necessary actions, or that the threat actor will not identify alternative means of intrusion or opportunities to otherwise utilize the information it accessed to adversely affect our business or results of operations. It has taken and may continue to take considerable time for us to investigate and evaluate the full impact of incidents, particularly for sophisticated attacks, limiting our ability to provide prompt, full, and reliable information about the incident to our customers, partners, regulators, and the public. The costs associated with cybersecurity tools and infrastructure and competition for
62
Table of Contents
cybersecurity and IT talent have limited, and may in the future continue to limit, our ability to efficiently identify, eliminate, or remediate cyber or other security vulnerabilities or problems or enact changes to minimize the attack surface of our network. Furthermore, our efforts to address these problems, at times, have not been, and may in the future not be, successful and have resulted and could result in interruptions, delays, cessation of service, compromise of sensitive information, and loss of existing or potential customers, any of which may impede our sales, manufacturing, distribution or other critical functions.
Additional impacts from cybersecurity incidents have included and could include reimbursement of remediation costs to our customers, suppliers, or distributors; lost revenue resulting from the unauthorized use of proprietary information or the failure to retain or attract business partners following an incident; increased insurance premiums; and damage to our competitiveness, reputation, stock price, and long-term shareholder value. To the extent we carry insurance coverage for such possibilities, we cannot be certain that any such coverage will be adequate or otherwise protect us with respect to claims, expenses, fines, penalties, business loss, data loss, litigation, regulatory actions, or other impacts arising from security breaches or incidents, or that such coverage will continue to be available on acceptable terms or at all.
The cybersecurity threat landscape is rapidly evolving and becoming increasingly sophisticated, and there can be no assurance that our controls and procedures will be sufficient to address future threats or remediate future incidents. Further, there has been an increase in the frequency and sophistication of attacks, and we expect these activities to continue to increase, including malicious actors potentially leveraging AI to develop malicious code or sophisticated phishing attempts. It is possible that such incidents may embolden other malicious actors to perpetrate future attacks that may result in material misappropriation, system disruptions or shutdowns, malicious alteration, or destruction of our confidential or personal information or that of third parties. Additionally, the proliferation of generative AI models within the internal systems, processes, and tools of HPE, our suppliers, our customers, or other third parties with whom we do business may create new attack methods for threat actors. The emergence of deepfakes and advanced social engineering tactics presents new challenges in preventing deception and unauthorized access, underscoring the importance of advanced verification and detection mechanisms. Zero-day vulnerabilities may include newly discovered security flaws in software that are exploited before patches are released, requiring proactive monitoring and immediate remediation efforts. Quantum computing also presents an evolving risk to our business as quantum computing capable of breaking current cryptographic methods may become available sooner than previously anticipated. Such advances in computing capabilities, new discoveries in the field of cryptography, or other developments may have the potential to break traditional cryptographic methods on which we rely, thereby necessitating the shift to quantum-resistant encryption techniques. We may need to expend significant resources to evaluate and transition certain cryptographic implementations to quantum-resistant techniques and these actions may not be sufficient to protect against security breaches or to address problems caused by any breach of our systems or data.
Malicious parties may continue to be able to otherwise develop and deploy viruses, worms, ransomware, and other malicious software programs, including those enabled by AI, that attack our products or otherwise exploit any security vulnerabilities of our products, including within our cloud-based environments and offerings, such that we may be unable to anticipate such malicious parties’ techniques, implement adequate preventative measures, or remediate any intrusion on a timely or effective basis even if our security measures are appropriate, reasonable, and comply with applicable legal requirements. Advanced persistent threats can include highly sophisticated intrusions by threat actors aiming to establish prolonged access within our network. Such intrusions have in the past gone, and could in the future go, undetected in our environments for a period of time, and we may discover additional impacts of earlier incidents that we believe were remediated including where combinations of otherwise low severity vulnerabilities are exploited together in unforeseen ways. Given resource limitations, operational constraints, and our broad and diverse network environment, when vulnerabilities are discovered, we evaluate the risk, prioritize our responses, apply patches or take other remediation actions and notify customers, business partners, and suppliers, as appropriate. Exploitation of vulnerabilities and critical security defects have occurred and may occur in the future if we fail to patch certain security vulnerabilities in time to prevent successful disruptions of our infrastructure or exposure of information, or the failure of third-party providers to remedy vulnerabilities or security defects, or customers not deploying security releases or deciding not to upgrade products, services or solutions, could, in each case, result in claims of liability against us, damage our reputation or otherwise harm our business.
With our business increasingly providing aaS offerings, malicious parties could target such services, potentially resulting in an increased risk of compromise of customer or employee data resulting in regulatory exposure. Incidents involving our cyber or physical security measures or the accidental loss, inadvertent disclosure, or unapproved dissemination of proprietary information, intellectual property, or sensitive, confidential, or personal data about us, our clients, or our customers, including the potential loss or disclosure of such data as a result of fraud or other forms of deception, could expose us, our customers, or the individuals affected to a risk of loss or misuse of this information; result in regulatory fines, litigation, and potential liability for us; damage our brand and reputation; or otherwise harm our business. We also could lose existing or potential customers of services or other IT solutions or incur significant expenses in connection with our customers’ system failures or any actual or perceived security vulnerabilities in our products and services. In addition, the cost and operational consequences of managing an incident and implementing further data protection measures could be significant.
63
Table of Contents
Additionally, we have acquired and may continue to acquire companies with cybersecurity vulnerabilities, gaps or different security standards, which expose us to related cybersecurity, operational, and financial risks. Further, as our products and services in some instances are integrated with our customers' systems and processes, even if we are successful in identifying vulnerabilities, a successful attack on us could compromise customers’ IT systems and sensitive data, despite active monitoring and development of tools designed to identify and remediate such vulnerabilities. There is no guarantee that a series of issues may not be determined to be material in the aggregate at a future date even if they may not be material individually at the time of their occurrence.
Our suppliers, vendors, partners, and other third parties with whom we do business also face similar cybersecurity threats, risks, and concerns as those set forth above, which introduces vulnerabilities to our business and operations, including our manufacturing supply chain. Although HPE requires strict cybersecurity and data controls through its contractual agreements with third parties, if these third parties do not have adequate safeguards or their safeguards fail, it has previously and may in the future result in breaches of their systems, networks, or applications, potentially leading to breaches of our networks and systems or unauthorized access to or disclosure of our and/or our customers' confidential data, thereby compromising us and our customers. While HPE relies on independent audit reports, in addition to our own security assessments and diligence of third parties with whom we do business as part of our third-party risk management practices, these efforts may not detect or identify all cybersecurity risks or vulnerabilities.