← Back to ROP filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Information regarding risk factors can be found in “Management’s Discussion and Analysis of Financial Condition and Results of Operations – Information About Forward-Looking Statements,” in Part I, Item 2 of this Quarterly Report and in Part I, Item 1A of our 2025 Annual Report on Form 10-K. We are providing the following information regarding changes that have occurred to the previously disclosed risk factors in our 2025 Annual Report on Form 10-K. Except for such additional information, there have been no other material changes during the six months ended June 30, 2026 to the risk factors reported in our 2025 Annual Report on Form 10-K.
We rely on information and technology, including third-party cloud computing platforms and other third-party business partners, for many of our business operations which could fail and cause disruption to our business operations.
Our business operations are dependent upon information technology networks and systems to securely transmit, process, and store information and to communicate among our locations around the world and with clients, suppliers, and business partners. A shutdown of, or inability to access, one or more of our facilities, a power outage, or a failure of one or more of our information technology, telecommunications, or other systems could significantly impair our ability to perform such functions on a timely basis. Our compliance, cybersecurity and data privacy programs, cybersecurity technology, and risk management cannot eliminate all system risk. Credential compromise and identity-based attacks represent risks, and while we deploy identity threat protection and multi-factor authentication across our enterprise systems, determined attackers may still gain unauthorized access through sophisticated credential theft, session hijacking, social engineering, or privilege escalation techniques. Cybersecurity incidents including ransomware attacks, insider threats, system disruptions, and configuration errors could result in the misappropriation or corruption of data and assets, or disruptions to our business strategy, results of operations, and financial condition, and may require notification to customers and regulators with associated investigation, remediation, and monitoring obligations. These disruptions may include, but are not limited to, interruptions to business operations, loss of intellectual property, release of confidential or other sensitive information, alteration or corruption of data or systems, costs related to remediation or the payment of ransom, litigation (including individual claims, consumer class actions, or commercial litigation), administrative, civil, or criminal investigations or actions, regulatory intervention and sanctions or fines, investigation and remediation costs, and prolonged negative publicity. While we have experienced disruptions, and our Vertafore business was previously subject to litigation regarding the exposure of data which was dismissed, to date, management has not identified any material impact on the Company from these disruptions.
We rely on business partners such as third-party data centers and cloud platforms, such as Amazon Web Services, Google Cloud Platform, Microsoft Azure, and Oracle Cloud to host certain enterprise and customer systems. Our software development and business operations rely on open-source components, third-party software libraries, and vendor dependencies that could contain undisclosed vulnerabilities, be subject to supply chain attacks, or become unavailable, potentially affecting our products, hosted services, and internal systems. Our software development lifecycle and deployment infrastructure, including source code repositories, continuous integration and continuous deployment (“CI/CD”) systems, build pipelines, code-signing processes, developer tools (including AI coding tools), automated testing environments, and other software development infrastructure, may be targeted by threat actors seeking to compromise software integrity, gain unauthorized access to credentials or cloud environments, introduce malicious code, exfiltrate sensitive information, or disrupt operations. Because these systems often integrate with third-party platforms, open-source components, cloud-based development tools, and trusted vendor ecosystems, vulnerabilities or compromises affecting software suppliers, developer environments, automated workflows, or software supply chains could propagate across internal systems, hosted services, or customer-facing products before detection. We have limited ability to monitor these third parties’ security measures or the full impact of the systemic risk, and concentration with a limited number of providers increases our exposure to outages and pricing changes. If any third-party system or cloud platform that we use is unavailable to us for any reason, our customers may experience service interruptions, which could significantly impact our operations, reputation, business, and financial results. Failure of our systems or those of our third-party service providers, may result in interruptions in our service and loss of data or processing capabilities, all of which may cause a loss in customers, refunds to be sought with respect to product fees, and/or material harm to our reputation and operating results. While certain of our businesses have experienced temporary disruptions, management has not identified any material impact on the Company from such disruptions to date.
28
Global cybersecurity threats are rapidly evolving and attacks to identities, networks, platforms, systems, and endpoints can range from uncoordinated individual attempts to sophisticated and targeted measures known as advanced persistent threats, directed at the Company, its businesses, its customers, and/or its third-party service providers, including, but not limited to, cloud providers and providers of network management services. These may include such things as unauthorized access, phishing attacks, denial of service, insider threats, data exfiltration and extortion, introduction of malware or ransomware, and other disruptive problems caused by threat actors. Threat actors are increasingly targeting trusted software providers, managed service providers, cloud platforms, software repositories, identity providers, developer tools, and other third-party technology ecosystems used by enterprises to develop, host, authenticate, and deploy software and services. Threat actors are also increasingly using AI to automate cyberattacks, enhance phishing and business email compromise campaigns, create convincing synthetic media, accelerate malware development, identify software vulnerabilities, and evade traditional security controls. As these capabilities continue to evolve, they may increase the frequency, sophistication, and effectiveness of attacks directed at the Company, its customers, and its third-party service providers. We face emerging risks from AI-powered attacks, including deepfakes used to impersonate employees or customers, AI-assisted social engineering and hacking activity, prompt injection attempts against AI systems, and data poisoning targeting machine learning models. These sophisticated attack techniques may bypass traditional security controls. Additionally, zero-day vulnerabilities, which are previously unknown security flaws with no available patches, pose risks that cannot be fully mitigated through our standard vulnerability management processes, requiring rapid detection and response capabilities to minimize potential damage. While we have experienced and expect to continue to experience these types of cybersecurity threats and incidents, management has not identified any cybersecurity incidents that have been material to the Company to date. We seek to deploy measures to protect, detect, respond, and recover from cybersecurity threats and incidents, including identity and access controls, employee training, data protection, vulnerability management, incident response, secure product development, continuous monitoring of our networks, platforms, endpoints, systems, and software development environments, and maintenance of ransomware resilient backup and recovery capabilities. Our customers are increasingly requiring cybersecurity protections and mandating cybersecurity standards in our products and services, and we may incur additional costs to comply with such demands. Despite these efforts, we can make no assurances that we will be able to mitigate, detect, prevent, timely and adequately respond, or fully recover from the negative effects of cybersecurity incidents, and such cybersecurity incidents, depending on their nature and scope, could potentially result in the misappropriation, destruction, corruption, or unavailability of critical data and confidential or proprietary information (our own or that of third parties) and the disruption of business operations. The potential consequences of a material cybersecurity incident include financial loss, reputational damage, damage to our IT systems, data loss, litigation, theft of intellectual property, regulatory fines, customer attrition, diminution in the value of our investments in research and development, and increased cybersecurity protection and remediation costs, which may not be fully covered by insurance and could adversely affect our competitiveness and results of operations. Any imposition of liability, particularly liability that is not covered by insurance or is in excess of insurance coverage, could materially harm our operating results and financial condition.
Our increasing use of artificial intelligence technologies presents operational, intellectual property, and competitive risks that could adversely affect our business, reputation, financial condition, and results of operations.
We are increasingly incorporating AI solutions into our platforms, offerings, services, and operations, and we expect that AI will continue to become a more integral part of our business and the markets in which we operate over time. Our competitors, AI companies, or other third parties may incorporate AI into their products or operations in a manner that could impair our ability to compete effectively and adversely affect our results of operations. The rapid pace of AI advancement may make it difficult to maintain competitive advantages, and AI capabilities could become commoditized, reducing our ability to significantly differentiate our offerings. Additionally, we may face challenges in protecting and enforcing rights in AI-generated or AI-assisted innovations, as intellectual property protections for AI-created materials remain uncertain in many jurisdictions. Competitors may be able to reverse-engineer or replicate our AI capabilities, and questions regarding ownership or authorship of AI-generated content or inventions could create legal uncertainties. Generative AI technologies, including certain AI-enabled features incorporated into our solutions, may produce output that appears correct but is or is alleged to be inaccurate, incomplete, or misleading, or that incorporates protected material without explicit authorization. If we use AI or offer AI-enabled solutions in a manner that is alleged to be deficient, inaccurate, incomplete, misleading, violative of third-party intellectual property, biased, or otherwise flawed, our business, reputation, financial condition, and results of operations may be adversely affected.
29
The use of AI tools by our employees, contractors, and other authorized users also presents operational, cybersecurity, intellectual property, confidentiality, and data governance risks. Unauthorized or inadvertent use of third-party AI platforms, AI coding assistants, or other AI-enabled development tools, including the submission of proprietary source code, confidential information, customer information, trade secrets, or other sensitive data to AI systems that are outside our controlled environments or are not approved for such use, could result in the unintended disclosure, retention, or use of such information, impair our ability to protect intellectual property, create contractual or legal obligations, or otherwise adversely affect our business, reputation, financial condition, and results of operations. We have experienced, and expect to continue to experience, instances of unauthorized or inadvertent use of AI technologies by personnel, however, such instances have not been material to the Company to date. While we maintain policies, technical controls, monitoring, and employee training governing the use of AI technologies, these measures may not prevent all unauthorized or inadvertent disclosures or misuse of sensitive information. In addition, unauthorized use of AI tools outside our approved governance framework (Shadow AI) may reduce the effectiveness of our information security, data governance, intellectual property protection, and records management controls.
We rely on third-party AI platforms and services, including proprietary and open-source large language models and other AI technologies provided by companies such as OpenAI, Anthropic, Google, and Microsoft. These providers may change their terms of service, increase pricing and/or change pricing models, discontinue services, experience outages, decline to provide certain indemnities, or make changes to their AI models that adversely affect our products or operations. As AI becomes more central to our offerings, our exposure to pricing changes from these providers increases, and we may not be able to pass such cost increases on to our customers. We have limited control over, and visibility into, the development, training data, model architecture, security, governance, availability, pricing, licensing terms, APIs, data handling practices, and future updates of these third-party AI systems. These providers may, among other things, modify model capabilities, acceptable use policies, safety features, commercial terms, or the manner in which their AI technologies are made available, which could require us to modify our products or operations, incur additional costs, discontinue certain functionality, or otherwise adversely affect our business. Any disruption in access to these services could have a significant impact on our business. The use of AI applications may result in cybersecurity incidents that implicate the personal data of end users of such applications. Any such cybersecurity incidents related to our use of AI applications could adversely affect our reputation and results of operations. AI also presents emerging ethical issues, and if our use of AI becomes controversial, we may experience brand, reputational, or competitive harm, or legal liability.
We depend on our ability to develop new products and software, and any failure to develop or market new products and software could adversely affect our business.
The future success of our business will depend, in part, on our ability to design and manufacture new competitive products, including the development of software, and to enhance existing product and software offerings, including through the development and deployment of AI. This product development may require substantial internal investment. There can be no assurance that unforeseen problems will not occur with respect to the development, performance, or market acceptance of new technologies, products, or software or that we will otherwise be able to successfully develop and market new products and software. Failure of our product or software offerings to gain market acceptance or our failure to successfully develop and market new products and software could reduce our margins, which would have an adverse effect on our business, financial condition, and results of operations.
Additionally, as we continue to increasingly build AI into many of our offerings, we face more competition as AI technologies are increasingly integrated into the markets in which we compete. New AI offerings may disrupt our offerings or transform workforce needs and may negatively impact demand for our offerings, or our competitors may be able to incorporate AI into their offerings more efficiently or successfully than we are able to. Even if our products are more effective than the products that our competitors offer, potential customers might select competitive products in lieu of purchasing our products. Failure to compete successfully against our competitors could negatively impact our future sales and harm our business.
30