← Back to JCI filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Except as set forth herein, there have been no material changes to the disclosure regarding risk factors presented in Part I, Item 1A, of the Company’s Annual Report on Form 10-K for the year ended September 30, 2025.
Cybersecurity incidents impacting our IT systems and digital products could disrupt business operations, result in the loss of critical and confidential information, and materially and adversely affect our reputation and results of operations.
We rely upon the capacity, reliability and security of our IT and data security infrastructure, and our ability to expand and continually update this infrastructure in response to the changing needs of our business. Also, the implementation of new systems, integration of existing systems and supporting our older systems all increase risks of security breaches. If we experience a problem with the functioning of an important IT system as a result of increased burdens placed on our IT infrastructure or a security breach of our IT systems, the resulting disruptions could have a material adverse effect on our business, reputation and financial results.
Global cybersecurity threats and incidents can range from uncoordinated individual attempts to gain unauthorized access to IT systems to sophisticated and targeted measures known as advanced persistent threats directed at the company and its products, customers and/or third-party service providers, including cloud providers. Moreover, AI and machine learning technologies continue to develop rapidly, and it is impossible to predict the future risks and market disruptions that may arise from such developments. Threat actors are already leveraging such technologies to develop new hacking tools and attack vectors, exploit vulnerabilities, obscure their activities, and increase the difficulty of threat attribution. For example, powerful new AI tools are finding previously undetected vulnerabilities in short time spans and creating exposures to zero-day attacks, all of which significantly diminish the window for us and our third-party service providers to detect, respond to and protect our IT and data security infrastructure. In addition, the vendors we use to support our business and operations have experienced, and will likely continue to experience, these types of threats and incidents, which add to the risks to our IT systems (including our cloud services providers’ systems), internal networks, our customers’ systems and the information stored and processed on such networks and systems. Despite our efforts to deploy countermeasures to deter, prevent, detect, respond to and mitigate cybersecurity threats, we have experienced, and will likely continue to experience, cybersecurity incidents and attacks. Such incidents have remained, and could in the future remain, undetected for an extended period of time, and the losses arising from such incidents could exceed our available insurance coverage for such matters.
Any future cybersecurity incidents or attacks, depending on their nature and scope, may result in the incurrence of significant costs, reputational damage, exposure to legal claims, enforcement actions, audits, investigations and fines levied by governmental organizations, misappropriation, destruction, corruption or unavailability of critical data and confidential or proprietary information (our own or that of third parties), the theft of intellectual property and the diminution in the value of our investment in research, development and engineering, and the disruption of business operations.
44
Our customers, including the U.S. government, are increasingly requiring cybersecurity protections and mandating cybersecurity standards in our products, and we may incur additional costs to comply with such demands. Moreover, an increasing number of our products, services and technologies, including our OpenBlue software platform, are delivered with digital capabilities and accompanying interconnected device networks, which include sensors, data, building management systems and advanced computing and analytics capabilities. If we are unable to manage the lifecycle cybersecurity risk in development, deployment and operation of our digital platforms and services, they could become susceptible to cybersecurity incidents and lead to third-party claims that our product failures have caused damage to our customers. This risk is enhanced by the increasingly connected nature of our products and the role they play in managing building systems.
Data privacy, identity protection and information security compliance may require significant resources and presents certain risks.
We collect, store, have access to and otherwise process certain confidential or sensitive data, including proprietary business information, customer data, personal data or other information that is subject to privacy and security laws, regulations and/or customer-imposed controls. Despite our efforts, our business, data and our products have been and will in the future be vulnerable to security incidents, theft, misplaced or lost data, programming errors, or errors that could potentially lead to the compromise or further compromise of such data, improper use of our products, systems, software solutions or networks, unauthorized access, use, disclosure, modification or destruction of information, defective products, production downtimes and operational disruptions. During September 2023, we experienced a cybersecurity event where certain data, primarily employee, job applicant and personal information and other related data, was impacted. The Company has taken appropriate actions to notify individuals and regulatory authorities.
The actual or perceived risk of theft, loss, fraudulent use or misuse of customer, employee or other data as a result of the foregoing or any other cybersecurity incident, as well as non-compliance with applicable industry standards or our contractual or other legal obligations or privacy and information security policies regarding such data, could result in litigation and/or regulatory activity and associated fines, damages, costs, awards, or settlements.
Such an event could lead customers to select the products and services of our competitors, harm our reputation and credibility, cause unfavorable publicity or otherwise adversely affect certain existing and potential customers’ perception of the security and reliability of our services, all of which could result in lost sales. In addition, we have and may in the future be required to make certain third-party notifications to individuals and regulators.
We operate in an environment in which there are different and potentially conflicting data privacy laws in effect in the various U.S. states and foreign jurisdictions in which we operate and we must understand and comply with each law and standard in each of these jurisdictions while ensuring the data is secured. For example, proposed regulations restricting the use of biometric security technology could impact the products and solutions offered by our security business. Government enforcement actions can be costly and interrupt the regular operation of our business, and violations of data privacy laws can result in fines, reputational damage and civil lawsuits, any of which may adversely affect our business, reputation and financial results.
Some of our contracts do not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our data privacy and security obligations. While we maintain general liability insurance coverage and coverage for errors or omissions, such coverage might not be adequate or otherwise protect us from liabilities or damages with respect to such claims. The successful assertion of one or more large claims against us that exceeds our available insurance coverage, or results in adverse changes to our insurance policies could have an adverse effect on our business and financial results.
We are incorporating artificial intelligence technologies into our products, services and processes. These technologies may present business, compliance and reputational risks.
Recent technological advances in AI and machine-learning technology both present opportunities and pose risks to us. If we fail to keep pace with rapidly evolving technological developments in AI, our competitive position and business results may suffer. The introduction of these technologies, particularly generative AI, into internal processes and/or new and existing offerings may result in new or expanded risks and liabilities, including due to enhanced governmental or regulatory scrutiny, litigation, compliance issues, ethical concerns, confidentiality or security risks, as well as other factors that could adversely affect our business, reputation, and financial results. In addition, our personnel could, unbeknownst to us, improperly utilize AI and machine learning technology while carrying out their responsibilities. The use of AI in the development of our products and services could also cause loss or theft of intellectual property, as well as subject us to risks related to intellectual property
45
infringement or misappropriation, data privacy and cybersecurity. The use of AI can lead to unintended consequences, including generating content that appears correct but is factually inaccurate, misleading or otherwise flawed, or that results in unintended biases and discriminatory outcomes, which could harm our stakeholders, our reputation and our business, and expose us to risks related to inaccuracies or errors in the output of such technologies. We also face risks of competitive disadvantage if our competitors more effectively use AI to drive internal efficiencies or create new or enhanced products or services that we are unable to compete against on cost, quality or other attributes. Furthermore, the emergence of increasingly sophisticated AI and machine learning technology has prompted lawmakers around the world to consider the regulation of such technology, including in jurisdictions in which we operate. Such regulations may impose obligations on companies like ours, and the costs of monitoring and responding to such regulations, as well as the consequences of non-compliance, could have a material adverse effect on our business, operations and financial condition.