← Back to FLOC filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
In addition to the other information set forth in this Quarterly Report (including the risk factor set forth below), you should carefully consider the factors discussed under Part I, Item 1A. Risk Factors in our Annual Report and Part II, Item 1A. Risk Factors in our Quarterly Report on Form 10-Q for the three months ended March 31, 2026. These factors could materially adversely affect our business, financial condition, liquidity, results of operations and capital position, and could cause our actual results to differ materially from our historical results or the results contemplated by any forward-looking statements contained in this Quarterly Report. Except as set forth below, there have been no material changes in the risks affecting the Company since the filing of our Annual Report.
We are subject to information technology, cybersecurity and privacy risks, and have experienced cybersecurity incidents.
We depend on various information technologies and other products and services to store and process business information and otherwise support our business activities. We also manufacture and sell hardware and software to provide monitoring, controls and optimization of customers’ critical assets in oil and natural gas production and distribution. In addition, certain of our customer offerings include digital components, such as remote monitoring of certain customer operations. We also provide services to maintain these systems. Additionally, our operations rely upon partners, suppliers and other third-party providers of information technology and other products and services. If any of these information technologies, products or services are damaged, cease to properly function, are breached due to employee error, malfeasance, system errors, or other vulnerabilities, or are subject to cybersecurity attacks, such as those involving unauthorized access, malicious software and/or other intrusions, we and our partners, suppliers or other third parties could experience: (i) production downtimes; (ii) operational delays; (iii) the compromising of confidential, proprietary or otherwise protected information, including personal and customer data; (iv) destruction, corruption, or theft of data; (v) security breaches; (vi) other manipulation, disruption, misappropriation or improper use of our systems or networks; (vii) hydrocarbon pollution from loss of containment; (viii) financial losses from remedial actions; (ix) loss of business or potential liability; (x) adverse media coverage; and (xi) legal claims or legal proceedings, including regulatory investigations and actions, and/or damage to our reputation. Increased risks of such attacks and disruptions also exist as a result of geopolitical conflicts, such as the continuing conflict between Russia and Ukraine and the Middle East.
During the second quarter of 2026, we experienced a cybersecurity incident in which a threat actor gained unauthorized access to certain Company systems, resulting in the exfiltration of certain internal business data. We promptly detected the incident, took steps to contain the unauthorized access, restored access for all systems, and engaged outside cybersecurity experts and legal counsel to assist with our response. Our systems and business operations were not materially disrupted, and, the incident did not materially affect, and is not reasonably likely to materially affect, our business, financial condition, results of operations or cash flows.
We expect such cybersecurity threats targeting our systems and those of our third-party solutions to continue, and the Company’s and our customers’, partners’, vendors’ and other third- parties’ systems, networks, products and services remain potentially vulnerable to known or unknown cybersecurity threats and attacks. While we do not believe any
62
prior cybersecurity incident has been material to date, we attempt to mitigate these risks through employee training, technical security controls, incident response procedures and the maintenance of backup and protective systems. However, these measures may not be effective against all threats, and a successful breach or attack involving the Company's information technology systems or those of third parties on which we rely could have a material adverse effect on our business, results of operations, financial condition and cash flows
While we currently maintain cybersecurity insurance, such insurance may not be sufficient in type or amount to cover us against claims related to cybersecurity breaches or attacks, failures or other data security-related incidents, and we cannot be certain that cyber insurance will continue to be available to us on economically reasonable terms, or at all, or that an insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could materially and adversely affect our results of operations, cash flows, and financial condition.