← Back to IPGP filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
In addition to the other information in this Quarterly Report on Form 10-Q, you should carefully consider the factors discussed in Item 1A of Part I of our Annual Report on Form 10-K for the year ended December 31, 2025, which could materially and adversely affect our financial condition, results of operations or cash flows, or cause our actual results to differ materially from those projected in any forward-looking statements. We may also face other risks and uncertainties that are not presently known, are not currently believed to be material, or are not identified in our Annual Report or Quarterly Reports because they are common to all businesses.
Except as set forth below, there have been no material changes to the risk factors previously disclosed in our Annual Report on Form 10-K for the year ended December 31, 2025.
Our use of artificial intelligence technologies may expose us to operational, legal, regulatory and reputational risks.
We use, and may increasingly incorporate, artificial intelligence (“AI”) and machine-learning technologies, including generative AI, in certain business processes, third-party services and products. The use of these technologies may expose us to new or increased risks, including evolving compliance requirements, government investigations or enforcement actions, claims or disputes, concerns regarding responsible use, and the potential exposure or compromise of confidential information or information systems, any of which could adversely affect our business, reputation and financial results.
Our employees or third-party service providers may use unauthorized AI and machine-learning technologies in violation of our policies or without our knowledge in performing services for us. The use of these technologies in third-party services and in the development or operation of our products, services and business processes could result in the loss or unauthorized disclosure of intellectual property or confidential information and expose us to claims involving intellectual property infringement or misappropriation, data privacy or cybersecurity. AI-generated outputs may also be inaccurate, misleading, incomplete or biased, even when they appear credible, and reliance on such outputs could lead to operational errors, unintended outcomes, legal or regulatory exposure, and harm to our business and reputation.
The following risk factors have been updated:
Our information systems are subject to cyber-attacks, interruptions and failures. If unauthorized access is obtained to our information systems, we may incur significant legal and financial exposure and liabilities.
Like many multinational corporations, we maintain several information technology systems, including software products licensed from third parties. These systems vary from country to country. Any system, network or internet failures, misuse by system users, hacking or other unauthorized access by third parties, disruptions or loss of license rights could disrupt our ability to manufacture and ship products on a timely and accurate basis or to report our financial information in compliance with the timelines mandated by the SEC. We also may experience unplanned interruptions or outages affecting our primary enterprise resource planning system as it continues to age, which may make the system increasingly difficult to support and maintain effectively. Any disruptions, delays or deficiencies affecting this system could substantially interrupt our business, including our ability to process and record routine business transactions. Any of these events could divert management's attention from the underlying business, harm our operations and adversely affect our financial results. In addition, a significant failure of our various information technology systems could adversely affect our ability to complete an evaluation of our internal controls and attestation activities pursuant to Section 404 of the Sarbanes-Oxley Act of 2002 under the updated framework issued in 2013.
As part of our day-to-day business, we store our data and certain data about our customers, employees and service providers in our information technology system. While our system is designed with access security, if a third party gains unauthorized access to our data or technology, including information regarding our customers, employees and service providers, such security breach could expose us to a risk of loss of this information, loss of business, litigation and possible liability. Our security measures may be breached as a result of third-party action, including intentional misconduct by computer hackers, employee error, malfeasance or otherwise. Additionally, third parties may attempt to fraudulently induce employees or customers into disclosing sensitive information such as usernames, passwords or other information in order to gain access to our customers' data or our data, including our intellectual property and other confidential business information, employee
32
Table of Contents
information or our information technology systems. Because the techniques used to obtain unauthorized access, or to sabotage systems, change frequently and generally are not recognized until launched against a target, we may be unable to anticipate or detect these techniques or to implement adequate preventative measures. Additionally, we expect threat actors to continue to increase in sophistication, including through the use of increasingly advanced AI tools, which may accelerate the identification and exploitation of vulnerabilities, enable evasion of security controls, and reduce the time between discovery and attempted exploitation. The pace at which vulnerabilities can be identified and weaponized may outstrip our ability, and that of our third-party providers, to test and deploy patches or other mitigating measures across complex systems. Any unauthorized access could negatively impact our customers' products, result in a loss of confidence by our customers, damage our reputation, disrupt our business, result in a misappropriation of our assets (including cash), lead to legal liability and negatively impact our future sales. Additionally, such actions could result in significant costs associated with loss of our intellectual property, impairment of our ability to conduct our operations, rebuilding our network and systems, prosecuting and defending litigation, responding to regulatory inquiries or actions, paying damages or taking other remedial steps. In addition, we may incur significant costs designed to prevent or mitigate the damage related to cybersecurity incidents. For instance, we may retain additional employees or consultants, implement new policies and procedures, and install information technology to detect and prevent identity theft, data breaches, or system disruptions. We would incur any such costs with the intent that proactively preventing a cybersecurity incident ultimately helps to mitigate potential cybersecurity liability. As previously disclosed, on September 14, 2020, the Company detected a ransomware attack impacting certain of our operational and information technology systems that we do not believe had a material impact on the Company's business, operations or financial condition.
The costs to address the foregoing security problems and security vulnerabilities before or after a cyber-incident could be significant. Our remediation efforts may not be successful and could result in interruptions, delays, a cessation of service, and a loss of existing or potential customers, impeding our sales, manufacturing, distribution, and other critical functions.
We depend upon internal production and on outside single or limited-source suppliers for many of our key components and raw materials, including cutting-edge optics and materials. Any interruption in the supply or availability of these key components and raw materials could adversely affect our results of operations.
We rely exclusively on our own production capabilities to manufacture certain of our key components, such as semiconductor diodes, specialty optical fibers and optical components. We do not have redundant production lines for some of our components, such as our diodes and some other components, which are made at a single manufacturing facility. These are not readily available from other sources at our current costs and may not be available at all. If our manufacturing activities were obstructed or hampered significantly, it could take a considerable length of time and capital investment, or it could increase our costs, to resume manufacturing or find alternative sources of supply. Many of the tools and equipment we use are custom-designed, and it could take a significant period of time to repair or replace them. Our primary manufacturing facilities are located in the United States and Germany, and we have added production in Italy and Poland. Despite our efforts to mitigate the impact of any flood, fire, natural disaster, political unrest, act of terrorism, war, trade sanctions, outbreak of disease or other similar event, our business could be adversely affected to the extent that we do not have redundant production capabilities if any of our major manufacturing facilities or equipment should become inoperable, inaccessible, damaged or destroyed.
We purchase certain raw materials used to manufacture our products and other components, such as semiconductor wafer substrates, diode packages, modulators, micro-optics, bulk optics and high power beam delivery products, from single or limited-source suppliers. We typically purchase our components and materials through purchase orders or agreed-upon terms and conditions and we do not have guaranteed supply arrangements with many of these suppliers. These suppliers are relatively small private companies that may discontinue their operations at any time and may be particularly susceptible to prevailing economic conditions. Some of our suppliers are also our competitors. Some of our suppliers may not be able to meet our requirements due to global demand for their components. As a result, we have experienced and may in the future experience longer lead times or delays in fulfillment of our orders. Furthermore, other than our current suppliers, there are a limited number of entities from whom we could obtain these supplies. We do not anticipate that we would be able to purchase these components or raw materials that we require in a short period of time or at the same cost from other sources in commercial quantities or that have our required performance specifications.
We are also transitioning certain activities that we have historically performed internally to outside suppliers. These transitions may result in qualification or implementation delays, supply interruptions, quality or yield issues, higher-than-anticipated costs, or reduced control over production processes, technical know-how or intellectual property. We may incur costs to complete these transitions, maintain duplicative capabilities during the transition period or address excess internal capacity, and we may not realize the anticipated cost savings or operational benefits. Outside suppliers may also be unable to meet our quality, cost, capacity, delivery or other requirements. If we are unable to manage these transitions effectively, our operations, customer relationships and financial results could be adversely affected.
33
Table of Contents
Any interruption or delay in the supply of any of these components or materials, or in outsourced manufacturing activities, or the inability to obtain these components, materials or services from alternate sources at acceptable prices and within a reasonable amount of time, could adversely affect our business. If our suppliers face financial or other difficulties, if our suppliers do not maintain sufficient inventory or capacity on hand, fail to meet our requirements, or if there are significant changes in demand for the components, materials or services we obtain from them, they could limit the availability of these components, materials or services to us, which in turn could adversely affect our business.