← Back to WST filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Other than the risk factor listed below, there have been no material changes to the risk factors disclosed in Part I, Item 1A of our 2025 Annual Report.
Unauthorized access to our or our customers’ information and systems could negatively impact our business.
Our systems and networks, as well as those of our customers, suppliers, service providers, and banks, have been, or may in the future become the target of cyberattacks or information security breaches which, in turn, could result in the unauthorized release and misuse of confidential or proprietary information about our company, our employees or our customers, as well as disrupt our operations or damage our facilities or those of third parties. Attacks on information systems and networks are increasing in their frequency, levels of persistence, sophistication, and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals, including state-sponsored organizations, with a wide range of motives and expertise.
For example, in May 2026, we experienced a material cybersecurity attack in which certain data was exfiltrated by an unauthorized party and certain systems were encrypted. Upon initial detection of an intrusion, we promptly activated our incident response protocols (including proactively taking systems offline globally for containment purposes), notified law enforcement, and engaged external cyber-forensic experts. The incident and our response temporarily disrupted our global operations. We have taken steps intended to mitigate the risk of dissemination of the exfiltrated data. This incident has been contained and our operations have fully recovered.
Techniques used to gain unauthorized access to or to acquire data and systems, disable or degrade service, or sabotage systems, are constantly evolving (including through the use of artificial intelligence), and we are unable to anticipate all techniques or comprehensively avoid unauthorized access, acquisition of, or other adverse impacts to our data or our systems or the networks and systems of third parties upon which we rely. We may not discover all such incidents or activities or be able to respond or otherwise address them promptly, in sufficient respects or at all.
44
Table of Contents
Additionally, our systems are subject to regulations to preserve the privacy of certain data held on those systems. We maintain an extensive network of technical security controls, policy enforcement mechanisms and monitoring systems, in order to address these threats. While these measures are designed to prevent, detect and respond to unauthorized activity in our systems, certain types of attacks could result in financial or information losses and/or reputational harm. If we cannot comply with regulations or prevent the unauthorized access, release and/or corruption of our or our customers’ confidential, classified or personally identifiable information, our reputation could be damaged, and/or we could face financial losses.
An adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to incur additional costs to modify or enhance our systems, or to try to prevent or remediate any such attacks. Modifying or enhancing our systems may result in unanticipated or prolonged disruption events, which could have a material adverse effect on our business and/or results of operations.
The costs of mitigating data security risks could be significant and are likely to increase in the future. Although we carry cybersecurity insurance, there can be no assurance that our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy limits, or that applicable insurance will be available to us in the future on economically reasonable terms or at all.